mirror of
https://github.com/toeverything/AFFiNE.git
synced 2026-02-12 04:18:54 +00:00
Compare commits
137 Commits
v2026.2.10
...
v0.12.0
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
df17001284 | ||
|
|
e400abf1f4 | ||
|
|
640aa00148 | ||
|
|
5ae8f029f7 | ||
|
|
a26e0b3ec9 | ||
|
|
f492b6711b | ||
|
|
81aae61394 | ||
|
|
e08f58beea | ||
|
|
4560819f76 | ||
|
|
193c197a54 | ||
|
|
449c0a38a7 | ||
|
|
8d141e5a81 | ||
|
|
e04911315f | ||
|
|
75d58679b6 | ||
|
|
2e6386e4cf | ||
|
|
f345a61df0 | ||
|
|
a6420fcd76 | ||
|
|
fec406f7e8 | ||
|
|
769398591b | ||
|
|
e01569fff7 | ||
|
|
6bde2de783 | ||
|
|
3513ced6cb | ||
|
|
8dc9addc40 | ||
|
|
9d9f89ef2e | ||
|
|
6cfe5d4566 | ||
|
|
6032b432f8 | ||
|
|
5823787ded | ||
|
|
b3f272ba70 | ||
|
|
a5df5a7c8a | ||
|
|
90de90403a | ||
|
|
4d4e4fc4e2 | ||
|
|
aa73e532d3 | ||
|
|
31faa93c71 | ||
|
|
def60f4c61 | ||
|
|
d15ec0ff77 | ||
|
|
d2acd0385a | ||
|
|
1effb2f25f | ||
|
|
9189d26332 | ||
|
|
79a8be7799 | ||
|
|
1a643cc70c | ||
|
|
9321be3ff5 | ||
|
|
24dc3f95ff | ||
|
|
4257b5f3a4 | ||
|
|
ea17e86032 | ||
|
|
48cd8999bd | ||
|
|
cdf1d9002e | ||
|
|
79b39f14d2 | ||
|
|
619420cfd1 | ||
|
|
739e914b5f | ||
|
|
5e9739eb3a | ||
|
|
0a89b7f528 | ||
|
|
0a0ee37ac2 | ||
|
|
a143379161 | ||
|
|
8e7dedfe82 | ||
|
|
d25a8547d0 | ||
|
|
4d16229fea | ||
|
|
99371be7e8 | ||
|
|
34ed8dd7a5 | ||
|
|
39b7b671b1 | ||
|
|
207b56d5af | ||
|
|
9e94e7195b | ||
|
|
de951c8779 | ||
|
|
fd37026ca5 | ||
|
|
4fd5812a89 | ||
|
|
d01e987ecc | ||
|
|
d87c218c0b | ||
|
|
a5bf5cc244 | ||
|
|
16bcd6e76b | ||
|
|
2e2ace8472 | ||
|
|
37cff8fe8d | ||
|
|
70ab3b4916 | ||
|
|
f42ba54578 | ||
|
|
a67c8181fc | ||
|
|
613efbded9 | ||
|
|
549419d102 | ||
|
|
21c42f8771 | ||
|
|
9012adda7a | ||
|
|
fb442e9055 | ||
|
|
a231474dd2 | ||
|
|
833b42000b | ||
|
|
7690c48710 | ||
|
|
579828a700 | ||
|
|
746db2ccfc | ||
|
|
eff344a9c1 | ||
|
|
c89ebab596 | ||
|
|
62f4421b7c | ||
|
|
42383dbd29 | ||
|
|
120e7397ba | ||
|
|
24123ad01c | ||
|
|
ad50320391 | ||
|
|
eb21a60dda | ||
|
|
c0e3be2d40 | ||
|
|
09d3b72358 | ||
|
|
246e16c6c0 | ||
|
|
dc279d062b | ||
|
|
47d5f9e1c2 | ||
|
|
a226eb8d5f | ||
|
|
908c4e1a6f | ||
|
|
1d0bcc80a0 | ||
|
|
50010bd824 | ||
|
|
c0ede1326d | ||
|
|
89197bacef | ||
|
|
f97d323ab5 | ||
|
|
2acb219dcc | ||
|
|
992ed89a89 | ||
|
|
d272d7922d | ||
|
|
c1cd1713b9 | ||
|
|
b20e91bee0 | ||
|
|
9a4e5ec8c3 | ||
|
|
2019838ae7 | ||
|
|
30ff25f400 | ||
|
|
e766208c18 | ||
|
|
8742f28148 | ||
|
|
cd291bb60e | ||
|
|
62c0efcfd1 | ||
|
|
87248b3337 | ||
|
|
00c940f7df | ||
|
|
931b459fbd | ||
|
|
51e71f4a0a | ||
|
|
9b631f2328 | ||
|
|
01f481a9b6 | ||
|
|
0177ab5c87 | ||
|
|
4db35d341c | ||
|
|
3c4a803c97 | ||
|
|
05154dc7ca | ||
|
|
c90b477f60 | ||
|
|
6f18ddbe85 | ||
|
|
dde779a71d | ||
|
|
bd9f66fbc7 | ||
|
|
92f1f40bfa | ||
|
|
48dc1049b3 | ||
|
|
9add530370 | ||
|
|
b77460d871 | ||
|
|
42db41776b | ||
|
|
075439c74f | ||
|
|
fc6c553ece | ||
|
|
59cb3d5df1 |
@@ -1,21 +1,2 @@
|
|||||||
[target.x86_64-pc-windows-msvc]
|
[target.x86_64-pc-windows-msvc]
|
||||||
rustflags = ["-C", "target-feature=+crt-static"]
|
rustflags = ["-C", "target-feature=+crt-static"]
|
||||||
[target.aarch64-pc-windows-msvc]
|
|
||||||
rustflags = ["-C", "target-feature=+crt-static"]
|
|
||||||
[target.'cfg(target_os = "linux")']
|
|
||||||
rustflags = ["-C", "link-args=-Wl,--warn-unresolved-symbols"]
|
|
||||||
[target.'cfg(target_os = "macos")']
|
|
||||||
rustflags = [
|
|
||||||
"-C",
|
|
||||||
"link-args=-Wl,-undefined,dynamic_lookup,-no_fixup_chains",
|
|
||||||
"-C",
|
|
||||||
"link-args=-all_load",
|
|
||||||
"-C",
|
|
||||||
"link-args=-weak_framework ScreenCaptureKit",
|
|
||||||
]
|
|
||||||
# https://sourceware.org/bugzilla/show_bug.cgi?id=21032
|
|
||||||
# https://sourceware.org/bugzilla/show_bug.cgi?id=21031
|
|
||||||
# https://github.com/rust-lang/rust/issues/134820
|
|
||||||
# pthread_key_create() destructors and segfault after a DSO unloading
|
|
||||||
[target.'cfg(all(target_env = "gnu", not(target_os = "windows")))']
|
|
||||||
rustflags = ["-C", "link-args=-Wl,-z,nodelete"]
|
|
||||||
|
|||||||
9
.devcontainer/Dockerfile
Normal file
9
.devcontainer/Dockerfile
Normal file
@@ -0,0 +1,9 @@
|
|||||||
|
FROM mcr.microsoft.com/devcontainers/base:bookworm
|
||||||
|
|
||||||
|
# Install Homebrew For Linux
|
||||||
|
RUN /bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)" && \
|
||||||
|
eval "$(/home/linuxbrew/.linuxbrew/bin/brew shellenv)" && \
|
||||||
|
echo "eval \"\$($(brew --prefix)/bin/brew shellenv)\"" >> /home/vscode/.zshrc && \
|
||||||
|
echo "eval \"\$($(brew --prefix)/bin/brew shellenv)\"" >> /home/vscode/.bashrc && \
|
||||||
|
# Install Graphite
|
||||||
|
brew install withgraphite/tap/graphite && gt --version
|
||||||
@@ -1,11 +1,12 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
# This is a script used by the devcontainer to build the project
|
# This is a script used by the devcontainer to build the project
|
||||||
|
|
||||||
|
#Enable yarn
|
||||||
|
corepack enable
|
||||||
|
corepack prepare yarn@stable --activate
|
||||||
|
|
||||||
# install dependencies
|
# install dependencies
|
||||||
yarn install
|
yarn install
|
||||||
|
|
||||||
# Build Server Dependencies
|
|
||||||
yarn affine @affine/server-native build
|
|
||||||
|
|
||||||
# Create database
|
# Create database
|
||||||
yarn affine @affine/server prisma migrate reset -f
|
yarn workspace @affine/server prisma db push
|
||||||
@@ -1,16 +1,12 @@
|
|||||||
// For format details, see https://aka.ms/devcontainer.json.
|
// For format details, see https://aka.ms/devcontainer.json.
|
||||||
{
|
{
|
||||||
"name": "AFFiNE Dev Container",
|
"name": "Debian",
|
||||||
"dockerComposeFile": "docker-compose.yml",
|
"dockerComposeFile": "docker-compose.yml",
|
||||||
"service": "app",
|
"service": "app",
|
||||||
"workspaceFolder": "/workspaces/${localWorkspaceFolderBasename}",
|
"workspaceFolder": "/workspaces/${localWorkspaceFolderBasename}",
|
||||||
"containerEnv": {
|
|
||||||
"COREPACK_ENABLE_DOWNLOAD_PROMPT": "0"
|
|
||||||
},
|
|
||||||
"features": {
|
"features": {
|
||||||
"ghcr.io/devcontainers/features/node:1": {
|
"ghcr.io/devcontainers/features/node:1": {
|
||||||
"version": "lts",
|
"version": "18"
|
||||||
"installYarnUsingApt": false
|
|
||||||
},
|
},
|
||||||
"ghcr.io/devcontainers/features/rust:1": {}
|
"ghcr.io/devcontainers/features/rust:1": {}
|
||||||
},
|
},
|
||||||
@@ -20,7 +16,7 @@
|
|||||||
"extensions": [
|
"extensions": [
|
||||||
"ms-playwright.playwright",
|
"ms-playwright.playwright",
|
||||||
"esbenp.prettier-vscode",
|
"esbenp.prettier-vscode",
|
||||||
"dbaeumer.vscode-eslint"
|
"streetsidesoftware.code-spell-checker"
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -2,20 +2,18 @@ version: '3.8'
|
|||||||
|
|
||||||
services:
|
services:
|
||||||
app:
|
app:
|
||||||
security_opt:
|
build:
|
||||||
- no-new-privileges:true
|
context: .
|
||||||
image: mcr.microsoft.com/devcontainers/base:bookworm
|
dockerfile: Dockerfile
|
||||||
volumes:
|
volumes:
|
||||||
- ../..:/workspaces:cached
|
- ../..:/workspaces:cached
|
||||||
command: sleep infinity
|
command: sleep infinity
|
||||||
network_mode: service:db
|
network_mode: service:db
|
||||||
environment:
|
environment:
|
||||||
DATABASE_URL: postgresql://affine:affine@db:5432/affine
|
DATABASE_URL: postgresql://affine:affine@db:5432/affine
|
||||||
REDIS_SERVER_HOST: redis
|
|
||||||
AFFINE_INDEXER_SEARCH_ENDPOINT: http://indexer:9308
|
|
||||||
|
|
||||||
db:
|
db:
|
||||||
image: pgvector/pgvector:pg16
|
image: postgres:latest
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
volumes:
|
volumes:
|
||||||
- postgres-data:/var/lib/postgresql/data
|
- postgres-data:/var/lib/postgresql/data
|
||||||
@@ -23,22 +21,6 @@ services:
|
|||||||
POSTGRES_PASSWORD: affine
|
POSTGRES_PASSWORD: affine
|
||||||
POSTGRES_USER: affine
|
POSTGRES_USER: affine
|
||||||
POSTGRES_DB: affine
|
POSTGRES_DB: affine
|
||||||
redis:
|
|
||||||
image: redis
|
|
||||||
|
|
||||||
indexer:
|
|
||||||
image: manticoresearch/manticore:${MANTICORE_VERSION:-10.1.0}
|
|
||||||
ulimits:
|
|
||||||
nproc: 65535
|
|
||||||
nofile:
|
|
||||||
soft: 65535
|
|
||||||
hard: 65535
|
|
||||||
memlock:
|
|
||||||
soft: -1
|
|
||||||
hard: -1
|
|
||||||
volumes:
|
|
||||||
- manticoresearch_data:/var/lib/manticore
|
|
||||||
|
|
||||||
volumes:
|
volumes:
|
||||||
postgres-data:
|
postgres-data:
|
||||||
manticoresearch_data:
|
|
||||||
|
|||||||
@@ -1,9 +1,7 @@
|
|||||||
set -e
|
|
||||||
|
|
||||||
npm install -g @withgraphite/graphite-cli@stable
|
|
||||||
|
|
||||||
if [ -v GRAPHITE_TOKEN ];then
|
if [ -v GRAPHITE_TOKEN ];then
|
||||||
gt auth --token $GRAPHITE_TOKEN
|
gt auth --token $GRAPHITE_TOKEN
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
git fetch
|
||||||
|
git branch canary -t origin/canary
|
||||||
gt init --trunk canary
|
gt init --trunk canary
|
||||||
|
|||||||
@@ -1,15 +0,0 @@
|
|||||||
# postgres major version
|
|
||||||
DB_VERSION=16
|
|
||||||
# database credentials
|
|
||||||
DB_PASSWORD=affine
|
|
||||||
DB_USERNAME=affine
|
|
||||||
DB_DATABASE_NAME=affine
|
|
||||||
|
|
||||||
# elasticsearch env
|
|
||||||
# ELASTIC_VERSION=9.0.1
|
|
||||||
# enable for arm64, e.g.: macOS M1+
|
|
||||||
# ELASTIC_VERSION_ARM64=-arm64
|
|
||||||
# ELASTIC_PLATFORM=linux/arm64
|
|
||||||
|
|
||||||
# manticoresearch
|
|
||||||
MANTICORE_VERSION=10.1.0
|
|
||||||
6
.docker/dev/.gitignore
vendored
6
.docker/dev/.gitignore
vendored
@@ -1,6 +0,0 @@
|
|||||||
postgres
|
|
||||||
.env
|
|
||||||
compose.yml
|
|
||||||
certs/*
|
|
||||||
!certs/.gitkeep
|
|
||||||
nginx/conf.d/*
|
|
||||||
@@ -1,21 +0,0 @@
|
|||||||
# Dev containers
|
|
||||||
|
|
||||||
## Develop with domain
|
|
||||||
|
|
||||||
> MacOs only, OrbStack only
|
|
||||||
|
|
||||||
### 1. Generate and install Root CA
|
|
||||||
|
|
||||||
```bash
|
|
||||||
# the root ca file will be located at `./.docker/dev/certs/ca`
|
|
||||||
yarn affine cert --install
|
|
||||||
```
|
|
||||||
|
|
||||||
### 2. Generate domain certs
|
|
||||||
|
|
||||||
```bash
|
|
||||||
# certificates will be located at `./.docker/dev/certs/${domain}`
|
|
||||||
yarn affine cert --domain affine.localhost
|
|
||||||
```
|
|
||||||
|
|
||||||
### 3. Enable nginx service in compose.yml
|
|
||||||
@@ -1,99 +0,0 @@
|
|||||||
name: affine_dev_services
|
|
||||||
services:
|
|
||||||
postgres:
|
|
||||||
env_file:
|
|
||||||
- .env
|
|
||||||
image: pgvector/pgvector:pg${DB_VERSION:-16}
|
|
||||||
ports:
|
|
||||||
- 5432:5432
|
|
||||||
environment:
|
|
||||||
POSTGRES_PASSWORD: ${DB_PASSWORD}
|
|
||||||
POSTGRES_USER: ${DB_USERNAME}
|
|
||||||
POSTGRES_DB: ${DB_DATABASE_NAME}
|
|
||||||
volumes:
|
|
||||||
- postgres_data:/var/lib/postgresql/data
|
|
||||||
|
|
||||||
redis:
|
|
||||||
image: redis:latest
|
|
||||||
ports:
|
|
||||||
- 6379:6379
|
|
||||||
|
|
||||||
# https://mailpit.axllent.org/docs/install/docker/
|
|
||||||
mailpit:
|
|
||||||
image: axllent/mailpit:latest
|
|
||||||
ports:
|
|
||||||
- 1025:1025
|
|
||||||
- 8025:8025
|
|
||||||
environment:
|
|
||||||
MP_MAX_MESSAGES: 5000
|
|
||||||
MP_DATABASE: /data/mailpit.db
|
|
||||||
MP_SMTP_AUTH_ACCEPT_ANY: 1
|
|
||||||
MP_SMTP_AUTH_ALLOW_INSECURE: 1
|
|
||||||
volumes:
|
|
||||||
- mailpit_data:/data
|
|
||||||
|
|
||||||
# https://manual.manticoresearch.com/Starting_the_server/Docker
|
|
||||||
manticoresearch:
|
|
||||||
image: manticoresearch/manticore:${MANTICORE_VERSION:-10.1.0}
|
|
||||||
ports:
|
|
||||||
- 9308:9308
|
|
||||||
ulimits:
|
|
||||||
nproc: 65535
|
|
||||||
nofile:
|
|
||||||
soft: 65535
|
|
||||||
hard: 65535
|
|
||||||
memlock:
|
|
||||||
soft: -1
|
|
||||||
hard: -1
|
|
||||||
volumes:
|
|
||||||
- manticoresearch_data:/var/lib/manticore
|
|
||||||
|
|
||||||
# elasticsearch:
|
|
||||||
# image: docker.elastic.co/elasticsearch/elasticsearch:${ELASTIC_VERSION:-9.0.1}${ELASTIC_VERSION_ARM64}
|
|
||||||
# platform: ${ELASTIC_PLATFORM}
|
|
||||||
# labels:
|
|
||||||
# co.elastic.logs/module: elasticsearch
|
|
||||||
# volumes:
|
|
||||||
# - elasticsearch_data:/usr/share/elasticsearch/data
|
|
||||||
# ports:
|
|
||||||
# - ${ES_PORT:-9200}:9200
|
|
||||||
# environment:
|
|
||||||
# - node.name=es01
|
|
||||||
# - cluster.name=affine-dev
|
|
||||||
# - discovery.type=single-node
|
|
||||||
# - bootstrap.memory_lock=true
|
|
||||||
# - xpack.security.enabled=false
|
|
||||||
# - xpack.security.http.ssl.enabled=false
|
|
||||||
# - xpack.security.transport.ssl.enabled=false
|
|
||||||
# - xpack.license.self_generated.type=basic
|
|
||||||
# mem_limit: ${ES_MEM_LIMIT:-1073741824}
|
|
||||||
# ulimits:
|
|
||||||
# memlock:
|
|
||||||
# soft: -1
|
|
||||||
# hard: -1
|
|
||||||
# healthcheck:
|
|
||||||
# test:
|
|
||||||
# [
|
|
||||||
# "CMD-SHELL",
|
|
||||||
# "curl -s http://localhost:9200 | grep -q 'affine-dev'",
|
|
||||||
# ]
|
|
||||||
# interval: 10s
|
|
||||||
# timeout: 10s
|
|
||||||
# retries: 120
|
|
||||||
|
|
||||||
# nginx:
|
|
||||||
# image: nginx:alpine
|
|
||||||
# volumes:
|
|
||||||
# - ./nginx/nginx.conf:/etc/nginx/nginx.conf:ro
|
|
||||||
# - ./nginx/conf.d:/etc/nginx/conf.d:ro
|
|
||||||
# - ./certs:/etc/nginx/certs:ro
|
|
||||||
# network_mode: host
|
|
||||||
|
|
||||||
networks:
|
|
||||||
dev:
|
|
||||||
|
|
||||||
volumes:
|
|
||||||
postgres_data:
|
|
||||||
manticoresearch_data:
|
|
||||||
mailpit_data:
|
|
||||||
elasticsearch_data:
|
|
||||||
@@ -1,28 +0,0 @@
|
|||||||
user nginx;
|
|
||||||
worker_processes auto;
|
|
||||||
|
|
||||||
error_log /var/log/nginx/error.log;
|
|
||||||
pid /var/run/nginx.pid;
|
|
||||||
|
|
||||||
events {
|
|
||||||
worker_connections 1024;
|
|
||||||
}
|
|
||||||
|
|
||||||
http {
|
|
||||||
include mime.types;
|
|
||||||
default_type application/octet-stream;
|
|
||||||
|
|
||||||
log_format main '$remote_addr - $remote_user [$time_local] "$request" '
|
|
||||||
'$status $body_bytes_sent "$http_referer" '
|
|
||||||
'"$http_user_agent" "$http_x_forwarded_for"';
|
|
||||||
access_log /var/log/nginx/access.log main;
|
|
||||||
|
|
||||||
sendfile on;
|
|
||||||
keepalive_timeout 65;
|
|
||||||
types_hash_max_size 2048;
|
|
||||||
client_max_body_size 512M;
|
|
||||||
server_names_hash_bucket_size 128;
|
|
||||||
ssi on;
|
|
||||||
gzip on;
|
|
||||||
include "/etc/nginx/conf.d/*";
|
|
||||||
}
|
|
||||||
@@ -1,27 +0,0 @@
|
|||||||
server {
|
|
||||||
listen 80;
|
|
||||||
server_name DEV_DOMAIN;
|
|
||||||
|
|
||||||
location / {
|
|
||||||
return 301 https://$host$request_uri;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
server {
|
|
||||||
listen 443 ssl;
|
|
||||||
http2 on;
|
|
||||||
ssl_certificate /etc/nginx/certs/$host/crt;
|
|
||||||
ssl_certificate_key /etc/nginx/certs/$host/key;
|
|
||||||
server_name DEV_DOMAIN;
|
|
||||||
|
|
||||||
location / {
|
|
||||||
proxy_pass http://localhost:8080;
|
|
||||||
proxy_set_header Host $host;
|
|
||||||
proxy_set_header X-Real-IP $remote_addr;
|
|
||||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
||||||
proxy_set_header X-Forwarded-Proto $scheme;
|
|
||||||
proxy_set_header Upgrade $http_upgrade;
|
|
||||||
proxy_set_header Connection "upgrade";
|
|
||||||
resolver 127.0.0.1;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,25 +0,0 @@
|
|||||||
[req]
|
|
||||||
distinguished_name = req_distinguished_name
|
|
||||||
req_extensions = v3_req
|
|
||||||
|
|
||||||
[req_distinguished_name]
|
|
||||||
countryName = Country Name (2 letter code)
|
|
||||||
countryName_default = US
|
|
||||||
stateOrProvinceName = State or Province Name (full name)
|
|
||||||
stateOrProvinceName_default = MN
|
|
||||||
localityName = Locality Name (eg, city)
|
|
||||||
localityName_default = Minneapolis
|
|
||||||
organizationalUnitName = Organizational Unit Name (eg, section)
|
|
||||||
organizationalUnitName_default = Domain Control Validated
|
|
||||||
commonName = Internet Widgits Ltd
|
|
||||||
commonName_max = 64
|
|
||||||
|
|
||||||
[ v3_req ]
|
|
||||||
# Extensions to add to a certificate request
|
|
||||||
basicConstraints = CA:FALSE
|
|
||||||
keyUsage = nonRepudiation, digitalSignature, keyEncipherment
|
|
||||||
subjectAltName = @alt_names
|
|
||||||
|
|
||||||
[alt_names]
|
|
||||||
DNS.1 = DEV_DOMAIN
|
|
||||||
DNS.2 = *.DEV_DOMAIN
|
|
||||||
@@ -1,23 +0,0 @@
|
|||||||
# select a revision to deploy, available values: stable, beta, canary
|
|
||||||
AFFINE_REVISION=stable
|
|
||||||
|
|
||||||
# set the port for the server container it will expose the server on
|
|
||||||
PORT=3010
|
|
||||||
|
|
||||||
# set the host for the server for outgoing links
|
|
||||||
# AFFINE_SERVER_HTTPS=true
|
|
||||||
# AFFINE_SERVER_HOST=affine.yourdomain.com
|
|
||||||
# or
|
|
||||||
# AFFINE_SERVER_EXTERNAL_URL=https://affine.yourdomain.com
|
|
||||||
|
|
||||||
# position of the database data to persist
|
|
||||||
DB_DATA_LOCATION=~/.affine/self-host/postgres/pgdata
|
|
||||||
# position of the upload data(images, files, etc.) to persist
|
|
||||||
UPLOAD_LOCATION=~/.affine/self-host/storage
|
|
||||||
# position of the configuration files to persist
|
|
||||||
CONFIG_LOCATION=~/.affine/self-host/config
|
|
||||||
|
|
||||||
# database credentials
|
|
||||||
DB_USERNAME=affine
|
|
||||||
DB_PASSWORD=
|
|
||||||
DB_DATABASE=affine
|
|
||||||
1
.docker/selfhost/.gitignore
vendored
1
.docker/selfhost/.gitignore
vendored
@@ -1 +0,0 @@
|
|||||||
.env
|
|
||||||
@@ -1,76 +0,0 @@
|
|||||||
name: affine
|
|
||||||
services:
|
|
||||||
affine:
|
|
||||||
image: ghcr.io/toeverything/affine:${AFFINE_REVISION:-stable}
|
|
||||||
container_name: affine_server
|
|
||||||
ports:
|
|
||||||
- '${PORT:-3010}:3010'
|
|
||||||
depends_on:
|
|
||||||
redis:
|
|
||||||
condition: service_healthy
|
|
||||||
postgres:
|
|
||||||
condition: service_healthy
|
|
||||||
affine_migration:
|
|
||||||
condition: service_completed_successfully
|
|
||||||
volumes:
|
|
||||||
# custom configurations
|
|
||||||
- ${UPLOAD_LOCATION}:/root/.affine/storage
|
|
||||||
- ${CONFIG_LOCATION}:/root/.affine/config
|
|
||||||
env_file:
|
|
||||||
- .env
|
|
||||||
environment:
|
|
||||||
- REDIS_SERVER_HOST=redis
|
|
||||||
- DATABASE_URL=postgresql://${DB_USERNAME}:${DB_PASSWORD}@postgres:5432/${DB_DATABASE:-affine}
|
|
||||||
- AFFINE_INDEXER_ENABLED=false
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
affine_migration:
|
|
||||||
image: ghcr.io/toeverything/affine:${AFFINE_REVISION:-stable}
|
|
||||||
container_name: affine_migration_job
|
|
||||||
volumes:
|
|
||||||
# custom configurations
|
|
||||||
- ${UPLOAD_LOCATION}:/root/.affine/storage
|
|
||||||
- ${CONFIG_LOCATION}:/root/.affine/config
|
|
||||||
command: ['sh', '-c', 'node ./scripts/self-host-predeploy.js']
|
|
||||||
env_file:
|
|
||||||
- .env
|
|
||||||
environment:
|
|
||||||
- REDIS_SERVER_HOST=redis
|
|
||||||
- DATABASE_URL=postgresql://${DB_USERNAME}:${DB_PASSWORD}@postgres:5432/${DB_DATABASE:-affine}
|
|
||||||
- AFFINE_INDEXER_ENABLED=false
|
|
||||||
depends_on:
|
|
||||||
postgres:
|
|
||||||
condition: service_healthy
|
|
||||||
redis:
|
|
||||||
condition: service_healthy
|
|
||||||
|
|
||||||
redis:
|
|
||||||
image: redis
|
|
||||||
container_name: affine_redis
|
|
||||||
healthcheck:
|
|
||||||
test: ['CMD', 'redis-cli', '--raw', 'incr', 'ping']
|
|
||||||
interval: 10s
|
|
||||||
timeout: 5s
|
|
||||||
retries: 5
|
|
||||||
restart: unless-stopped
|
|
||||||
|
|
||||||
postgres:
|
|
||||||
image: pgvector/pgvector:pg16
|
|
||||||
container_name: affine_postgres
|
|
||||||
volumes:
|
|
||||||
- ${DB_DATA_LOCATION}:/var/lib/postgresql/data
|
|
||||||
environment:
|
|
||||||
POSTGRES_USER: ${DB_USERNAME}
|
|
||||||
POSTGRES_PASSWORD: ${DB_PASSWORD}
|
|
||||||
POSTGRES_DB: ${DB_DATABASE:-affine}
|
|
||||||
POSTGRES_INITDB_ARGS: '--data-checksums'
|
|
||||||
# you better set a password for you database
|
|
||||||
# or you may add 'POSTGRES_HOST_AUTH_METHOD=trust' to ignore postgres security policy
|
|
||||||
POSTGRES_HOST_AUTH_METHOD: trust
|
|
||||||
healthcheck:
|
|
||||||
test:
|
|
||||||
['CMD', 'pg_isready', '-U', "${DB_USERNAME}", '-d', "${DB_DATABASE:-affine}"]
|
|
||||||
interval: 10s
|
|
||||||
timeout: 5s
|
|
||||||
retries: 5
|
|
||||||
restart: unless-stopped
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
{
|
|
||||||
"$schema": "https://github.com/toeverything/affine/releases/latest/download/config.schema.json",
|
|
||||||
"server": {
|
|
||||||
"name": "AFFiNE Self Hosted Server"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -1,26 +0,0 @@
|
|||||||
.git
|
|
||||||
.github/**/*.md
|
|
||||||
.gitignore
|
|
||||||
|
|
||||||
# Local dependency/build artifacts
|
|
||||||
/node_modules
|
|
||||||
/target
|
|
||||||
|
|
||||||
# Yarn v4 artifacts (not needed for image packaging)
|
|
||||||
/.yarn/cache
|
|
||||||
/.yarn/unplugged
|
|
||||||
/.yarn/install-state.gz
|
|
||||||
/.pnp.*
|
|
||||||
|
|
||||||
# Test artifacts
|
|
||||||
/test-results
|
|
||||||
/playwright-report
|
|
||||||
/coverage
|
|
||||||
/.coverage
|
|
||||||
|
|
||||||
# OS noise
|
|
||||||
.DS_Store
|
|
||||||
|
|
||||||
# Sourcemaps (keep server sourcemap for backend stacktraces)
|
|
||||||
**/*.map
|
|
||||||
!packages/backend/server/dist/main.js.map
|
|
||||||
@@ -1,8 +1,6 @@
|
|||||||
# Editor configuration, see http://editorconfig.org
|
# Editor configuration, see http://editorconfig.org
|
||||||
root = true
|
root = true
|
||||||
|
|
||||||
[*.rs]
|
|
||||||
max_line_length = 120
|
|
||||||
[*]
|
[*]
|
||||||
charset = utf-8
|
charset = utf-8
|
||||||
indent_style = space
|
indent_style = space
|
||||||
|
|||||||
14
.env.template
Normal file
14
.env.template
Normal file
@@ -0,0 +1,14 @@
|
|||||||
|
ENABLE_PLUGIN=
|
||||||
|
ENABLE_TEST_PROPERTIES=
|
||||||
|
ENABLE_BC_PROVIDER=
|
||||||
|
CHANGELOG_URL=
|
||||||
|
ENABLE_PRELOADING=
|
||||||
|
ENABLE_NEW_SETTING_MODAL=
|
||||||
|
ENABLE_SQLITE_PROVIDER=
|
||||||
|
ENABLE_NEW_SETTING_UNSTABLE_API=
|
||||||
|
ENABLE_NOTIFICATION_CENTER=
|
||||||
|
ENABLE_CLOUD=
|
||||||
|
ENABLE_MOVE_DATABASE=
|
||||||
|
SHOULD_REPORT_TRACE=
|
||||||
|
TRACE_REPORT_ENDPOINT=
|
||||||
|
CAPTCHA_SITE_KEY=
|
||||||
15
.eslintignore
Normal file
15
.eslintignore
Normal file
@@ -0,0 +1,15 @@
|
|||||||
|
node_modules
|
||||||
|
dist
|
||||||
|
.next
|
||||||
|
out
|
||||||
|
storybook-static
|
||||||
|
affine-out
|
||||||
|
_next
|
||||||
|
lib
|
||||||
|
.eslintrc.js
|
||||||
|
e2e-dist-*
|
||||||
|
static
|
||||||
|
web-static
|
||||||
|
public
|
||||||
|
packages/frontend/i18n/src/i18n-generated.ts
|
||||||
|
packages/frontend/templates/edgeless-templates.gen.ts
|
||||||
311
.eslintrc.js
Normal file
311
.eslintrc.js
Normal file
@@ -0,0 +1,311 @@
|
|||||||
|
const { resolve } = require('node:path');
|
||||||
|
|
||||||
|
const createPattern = packageName => [
|
||||||
|
{
|
||||||
|
group: ['**/dist', '**/dist/**'],
|
||||||
|
message: 'Do not import from dist',
|
||||||
|
allowTypeImports: false,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
group: ['**/src', '**/src/**'],
|
||||||
|
message: 'Do not import from src',
|
||||||
|
allowTypeImports: false,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
group: [`@affine/${packageName}`],
|
||||||
|
message: 'Do not import package itself',
|
||||||
|
allowTypeImports: false,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
group: [`@toeverything/${packageName}`],
|
||||||
|
message: 'Do not import package itself',
|
||||||
|
allowTypeImports: false,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
group: ['@blocksuite/store'],
|
||||||
|
message: "Import from '@blocksuite/global/utils'",
|
||||||
|
importNames: ['assertExists', 'assertEquals'],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
group: ['react-router-dom'],
|
||||||
|
message: 'Use `useNavigateHelper` instead',
|
||||||
|
importNames: ['useNavigate'],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
group: ['next-auth/react'],
|
||||||
|
message: "Import hooks from 'use-current-user.tsx'",
|
||||||
|
// useSession is type unsafe
|
||||||
|
importNames: ['useSession'],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
group: ['next-auth/react'],
|
||||||
|
message: "Import hooks from 'cloud-utils.ts'",
|
||||||
|
importNames: ['signIn', 'signOut'],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
group: ['yjs'],
|
||||||
|
message: 'Do not use this API because it has a bug',
|
||||||
|
importNames: ['mergeUpdates'],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
group: ['@affine/env/constant'],
|
||||||
|
message:
|
||||||
|
'Do not import from @affine/env/constant. Use `environment.isDesktop` instead',
|
||||||
|
importNames: ['isDesktop'],
|
||||||
|
},
|
||||||
|
];
|
||||||
|
|
||||||
|
const allPackages = [
|
||||||
|
'packages/backend/server',
|
||||||
|
'packages/frontend/component',
|
||||||
|
'packages/frontend/core',
|
||||||
|
'packages/frontend/electron',
|
||||||
|
'packages/frontend/graphql',
|
||||||
|
'packages/frontend/i18n',
|
||||||
|
'packages/frontend/native',
|
||||||
|
'packages/frontend/templates',
|
||||||
|
'packages/frontend/workspace',
|
||||||
|
'packages/common/debug',
|
||||||
|
'packages/common/env',
|
||||||
|
'packages/common/infra',
|
||||||
|
'packages/common/theme',
|
||||||
|
'packages/common/y-indexeddb',
|
||||||
|
'tools/cli',
|
||||||
|
'tests/storybook',
|
||||||
|
];
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @type {import('eslint').Linter.Config}
|
||||||
|
*/
|
||||||
|
const config = {
|
||||||
|
root: true,
|
||||||
|
settings: {
|
||||||
|
react: {
|
||||||
|
version: 'detect',
|
||||||
|
},
|
||||||
|
next: {
|
||||||
|
rootDir: 'packages/frontend/core',
|
||||||
|
},
|
||||||
|
},
|
||||||
|
extends: [
|
||||||
|
'eslint:recommended',
|
||||||
|
'plugin:react-hooks/recommended',
|
||||||
|
'plugin:react/recommended',
|
||||||
|
'plugin:react/jsx-runtime',
|
||||||
|
'plugin:@typescript-eslint/recommended',
|
||||||
|
'prettier',
|
||||||
|
],
|
||||||
|
parser: '@typescript-eslint/parser',
|
||||||
|
parserOptions: {
|
||||||
|
ecmaFeatures: {
|
||||||
|
globalReturn: false,
|
||||||
|
impliedStrict: true,
|
||||||
|
jsx: true,
|
||||||
|
},
|
||||||
|
ecmaVersion: 'latest',
|
||||||
|
sourceType: 'module',
|
||||||
|
project: resolve(__dirname, './tsconfig.eslint.json'),
|
||||||
|
},
|
||||||
|
plugins: [
|
||||||
|
'react',
|
||||||
|
'@typescript-eslint',
|
||||||
|
'simple-import-sort',
|
||||||
|
'sonarjs',
|
||||||
|
'i',
|
||||||
|
'unused-imports',
|
||||||
|
'unicorn',
|
||||||
|
],
|
||||||
|
rules: {
|
||||||
|
'array-callback-return': 'error',
|
||||||
|
'no-undef': 'off',
|
||||||
|
'no-empty': 'off',
|
||||||
|
'no-func-assign': 'off',
|
||||||
|
'no-cond-assign': 'off',
|
||||||
|
'no-constant-binary-expression': 'error',
|
||||||
|
'no-constructor-return': 'error',
|
||||||
|
'no-self-compare': 'error',
|
||||||
|
eqeqeq: ['error', 'always', { null: 'ignore' }],
|
||||||
|
'react/prop-types': 'off',
|
||||||
|
'react/jsx-no-useless-fragment': 'error',
|
||||||
|
'@typescript-eslint/consistent-type-imports': 'error',
|
||||||
|
'@typescript-eslint/no-non-null-assertion': 'error',
|
||||||
|
'@typescript-eslint/no-explicit-any': 'off',
|
||||||
|
'@typescript-eslint/no-empty-function': 'off',
|
||||||
|
'@typescript-eslint/await-thenable': 'error',
|
||||||
|
'@typescript-eslint/require-array-sort-compare': 'error',
|
||||||
|
'@typescript-eslint/unified-signatures': 'error',
|
||||||
|
'@typescript-eslint/prefer-for-of': 'error',
|
||||||
|
'@typescript-eslint/no-unused-vars': [
|
||||||
|
'error',
|
||||||
|
{
|
||||||
|
varsIgnorePattern: '^_',
|
||||||
|
argsIgnorePattern: '^_',
|
||||||
|
caughtErrorsIgnorePattern: '^_',
|
||||||
|
},
|
||||||
|
],
|
||||||
|
'unused-imports/no-unused-imports': 'error',
|
||||||
|
'simple-import-sort/imports': 'error',
|
||||||
|
'simple-import-sort/exports': 'error',
|
||||||
|
'@typescript-eslint/ban-ts-comment': [
|
||||||
|
'error',
|
||||||
|
{
|
||||||
|
'ts-expect-error': 'allow-with-description',
|
||||||
|
'ts-ignore': true,
|
||||||
|
'ts-nocheck': true,
|
||||||
|
'ts-check': false,
|
||||||
|
},
|
||||||
|
],
|
||||||
|
'@typescript-eslint/no-restricted-imports': [
|
||||||
|
'error',
|
||||||
|
{
|
||||||
|
patterns: [
|
||||||
|
{
|
||||||
|
group: ['**/dist'],
|
||||||
|
message: "Don't import from dist",
|
||||||
|
allowTypeImports: false,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
group: ['**/src'],
|
||||||
|
message: "Don't import from src",
|
||||||
|
allowTypeImports: false,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
group: ['@blocksuite/store'],
|
||||||
|
message: "Import from '@blocksuite/global/utils'",
|
||||||
|
importNames: ['assertExists', 'assertEquals'],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
group: ['react-router-dom'],
|
||||||
|
message: 'Use `useNavigateHelper` instead',
|
||||||
|
importNames: ['useNavigate'],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
group: ['next-auth/react'],
|
||||||
|
message: "Import hooks from 'use-current-user.tsx'",
|
||||||
|
// useSession is type unsafe
|
||||||
|
importNames: ['useSession'],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
group: ['next-auth/react'],
|
||||||
|
message: "Import hooks from 'cloud-utils.ts'",
|
||||||
|
importNames: ['signIn', 'signOut'],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
group: ['yjs'],
|
||||||
|
message: 'Do not use this API because it has a bug',
|
||||||
|
importNames: ['mergeUpdates'],
|
||||||
|
},
|
||||||
|
],
|
||||||
|
},
|
||||||
|
],
|
||||||
|
'unicorn/filename-case': [
|
||||||
|
'error',
|
||||||
|
{
|
||||||
|
case: 'kebabCase',
|
||||||
|
ignore: ['^\\[[a-zA-Z0-9-_]+\\]\\.tsx$'],
|
||||||
|
},
|
||||||
|
],
|
||||||
|
'unicorn/no-unnecessary-await': 'error',
|
||||||
|
'unicorn/no-useless-fallback-in-spread': 'error',
|
||||||
|
'unicorn/prefer-dom-node-dataset': 'error',
|
||||||
|
'unicorn/prefer-dom-node-append': 'error',
|
||||||
|
'unicorn/prefer-dom-node-remove': 'error',
|
||||||
|
'unicorn/prefer-array-some': 'error',
|
||||||
|
'unicorn/prefer-date-now': 'error',
|
||||||
|
'unicorn/prefer-blob-reading-methods': 'error',
|
||||||
|
'unicorn/no-typeof-undefined': 'error',
|
||||||
|
'unicorn/no-useless-promise-resolve-reject': 'error',
|
||||||
|
'unicorn/no-new-array': 'error',
|
||||||
|
'unicorn/new-for-builtins': 'error',
|
||||||
|
'unicorn/prefer-node-protocol': 'error',
|
||||||
|
'sonarjs/no-all-duplicated-branches': 'error',
|
||||||
|
'sonarjs/no-element-overwrite': 'error',
|
||||||
|
'sonarjs/no-empty-collection': 'error',
|
||||||
|
'sonarjs/no-extra-arguments': 'error',
|
||||||
|
'sonarjs/no-identical-conditions': 'error',
|
||||||
|
'sonarjs/no-identical-expressions': 'error',
|
||||||
|
'sonarjs/no-ignored-return': 'error',
|
||||||
|
'sonarjs/no-one-iteration-loop': 'error',
|
||||||
|
'sonarjs/no-use-of-empty-return-value': 'error',
|
||||||
|
'sonarjs/non-existent-operator': 'error',
|
||||||
|
'sonarjs/no-collapsible-if': 'error',
|
||||||
|
'sonarjs/no-same-line-conditional': 'error',
|
||||||
|
'sonarjs/no-duplicated-branches': 'error',
|
||||||
|
'sonarjs/no-collection-size-mischeck': 'error',
|
||||||
|
'sonarjs/no-useless-catch': 'error',
|
||||||
|
'sonarjs/no-identical-functions': 'error',
|
||||||
|
},
|
||||||
|
overrides: [
|
||||||
|
{
|
||||||
|
files: 'packages/backend/server/**/*.ts',
|
||||||
|
rules: {
|
||||||
|
'@typescript-eslint/consistent-type-imports': 0,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
files: '*.cjs',
|
||||||
|
rules: {
|
||||||
|
'@typescript-eslint/no-var-requires': 0,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
...allPackages.map(pkg => ({
|
||||||
|
files: [`${pkg}/src/**/*.ts`, `${pkg}/src/**/*.tsx`],
|
||||||
|
parserOptions: {
|
||||||
|
project: resolve(__dirname, './tsconfig.eslint.json'),
|
||||||
|
},
|
||||||
|
rules: {
|
||||||
|
'@typescript-eslint/no-restricted-imports': [
|
||||||
|
'error',
|
||||||
|
{
|
||||||
|
patterns: createPattern(pkg),
|
||||||
|
},
|
||||||
|
],
|
||||||
|
'@typescript-eslint/no-floating-promises': [
|
||||||
|
'error',
|
||||||
|
{
|
||||||
|
ignoreVoid: false,
|
||||||
|
ignoreIIFE: false,
|
||||||
|
},
|
||||||
|
],
|
||||||
|
'@typescript-eslint/no-misused-promises': ['error'],
|
||||||
|
'@typescript-eslint/prefer-readonly': 'error',
|
||||||
|
'i/no-extraneous-dependencies': ['error'],
|
||||||
|
'react-hooks/exhaustive-deps': [
|
||||||
|
'warn',
|
||||||
|
{
|
||||||
|
additionalHooks: 'useAsyncCallback',
|
||||||
|
},
|
||||||
|
],
|
||||||
|
},
|
||||||
|
})),
|
||||||
|
{
|
||||||
|
files: [
|
||||||
|
'**/__tests__/**/*',
|
||||||
|
'**/*.stories.tsx',
|
||||||
|
'**/*.spec.ts',
|
||||||
|
'**/tests/**/*',
|
||||||
|
'scripts/**/*',
|
||||||
|
'**/benchmark/**/*',
|
||||||
|
'**/__debug__/**/*',
|
||||||
|
'**/e2e/**/*',
|
||||||
|
],
|
||||||
|
rules: {
|
||||||
|
'@typescript-eslint/no-non-null-assertion': 0,
|
||||||
|
'@typescript-eslint/ban-ts-comment': [
|
||||||
|
'error',
|
||||||
|
{
|
||||||
|
'ts-expect-error': false,
|
||||||
|
'ts-ignore': true,
|
||||||
|
'ts-nocheck': true,
|
||||||
|
'ts-check': false,
|
||||||
|
},
|
||||||
|
],
|
||||||
|
'@typescript-eslint/no-floating-promises': 0,
|
||||||
|
'@typescript-eslint/no-misused-promises': 0,
|
||||||
|
'@typescript-eslint/no-restricted-imports': 0,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
],
|
||||||
|
};
|
||||||
|
|
||||||
|
module.exports = config;
|
||||||
2
.github/CODEOWNERS
vendored
2
.github/CODEOWNERS
vendored
@@ -1,2 +0,0 @@
|
|||||||
/blocksuite/ @toeverything/blocksuite-core
|
|
||||||
/packages/frontend/core/src/blocksuite @toeverything/blocksuite-core
|
|
||||||
|
|||||||
41
.github/ISSUE_TEMPLATE/BUG-REPORT.yml
vendored
41
.github/ISSUE_TEMPLATE/BUG-REPORT.yml
vendored
@@ -1,14 +1,12 @@
|
|||||||
name: Bug Report
|
name: Bug Report
|
||||||
description: File a bug report
|
description: File a bug report
|
||||||
title: '[Bug]: '
|
title: "\u200b"
|
||||||
labels: ['bug']
|
labels: ['bug']
|
||||||
body:
|
body:
|
||||||
- type: markdown
|
- type: markdown
|
||||||
attributes:
|
attributes:
|
||||||
value: |
|
value: |
|
||||||
Thanks for taking the time to fill out this bug report!
|
Thanks for taking the time to fill out this bug report!
|
||||||
Check out this [link](https://github.com/toeverything/AFFiNE/blob/canary/docs/issue-triaging.md)
|
|
||||||
to learn how we manage issues and when your issue will be processed.
|
|
||||||
- type: textarea
|
- type: textarea
|
||||||
id: what-happened
|
id: what-happened
|
||||||
attributes:
|
attributes:
|
||||||
@@ -18,26 +16,20 @@ body:
|
|||||||
validations:
|
validations:
|
||||||
required: true
|
required: true
|
||||||
- type: dropdown
|
- type: dropdown
|
||||||
id: distribution
|
id: version
|
||||||
attributes:
|
attributes:
|
||||||
label: Distribution version
|
label: Distribution version
|
||||||
description: What distribution of AFFiNE are you using?
|
description: What version of AFFiNE are you using?
|
||||||
options:
|
options:
|
||||||
- macOS x64 (Intel)
|
- macOS x64 (Intel)
|
||||||
- macOS ARM 64 (Apple Silicon)
|
- macOS ARM 64 (Apple Silicon)
|
||||||
- Windows x64
|
- Windows x64
|
||||||
- Linux
|
- Linux
|
||||||
- Web (https://app.affine.pro)
|
- Web (app.affine.pro)
|
||||||
- Beta Web (https://insider.affine.pro)
|
- Web (affine.fail)
|
||||||
- Canary Web (https://affine.fail)
|
- Web (insider.affine.pro)
|
||||||
validations:
|
validations:
|
||||||
required: true
|
required: true
|
||||||
- type: input
|
|
||||||
id: version
|
|
||||||
attributes:
|
|
||||||
label: App Version
|
|
||||||
description: What version of AFFiNE are you using?
|
|
||||||
placeholder: (You can find AFFiNE version in [About AFFiNE] setting panel)
|
|
||||||
- type: dropdown
|
- type: dropdown
|
||||||
id: browsers
|
id: browsers
|
||||||
attributes:
|
attributes:
|
||||||
@@ -49,19 +41,6 @@ body:
|
|||||||
- Firefox
|
- Firefox
|
||||||
- Safari
|
- Safari
|
||||||
- Other
|
- Other
|
||||||
- type: checkboxes
|
|
||||||
id: selfhost
|
|
||||||
attributes:
|
|
||||||
label: Are you self-hosting?
|
|
||||||
description: >
|
|
||||||
If you are self-hosting, please check the box and provide information about your setup.
|
|
||||||
options:
|
|
||||||
- label: 'Yes'
|
|
||||||
- type: input
|
|
||||||
id: selfhost-version
|
|
||||||
attributes:
|
|
||||||
label: Self-hosting Version
|
|
||||||
description: What version of AFFiNE are you selfhosting?
|
|
||||||
- type: textarea
|
- type: textarea
|
||||||
id: logs
|
id: logs
|
||||||
attributes:
|
attributes:
|
||||||
@@ -76,9 +55,9 @@ body:
|
|||||||
Tip: You can attach images here
|
Tip: You can attach images here
|
||||||
- type: checkboxes
|
- type: checkboxes
|
||||||
attributes:
|
attributes:
|
||||||
label: Is your content generated by AI?
|
label: Are you willing to submit a PR?
|
||||||
description: >
|
description: >
|
||||||
(Required) Please confirm that the content you submit was not generated by AI or only minimally edited by AI.
|
(Optional) We encourage you to submit a [Pull Request](https://github.com/toeverything/affine/pulls) (PR) to help improve AFFiNE for everyone, especially if you have a good understanding of how to implement a fix or feature.
|
||||||
If an administrator believes the post contains a large amount of AI-generated content, they may directly close the question.
|
See the AFFiNE [Contributing Guide](https://github.com/toeverything/affine/blob/canary/CONTRIBUTING.md) to get started.
|
||||||
options:
|
options:
|
||||||
- label: I confirm that the content I submitted was **not** generated by AI / **merely contained minimal** AI edits.
|
- label: Yes I'd like to help by submitting a PR!
|
||||||
|
|||||||
10
.github/ISSUE_TEMPLATE/FEATURE-REQUEST.yml
vendored
10
.github/ISSUE_TEMPLATE/FEATURE-REQUEST.yml
vendored
@@ -1,6 +1,6 @@
|
|||||||
name: Feature Request
|
name: Feature Request
|
||||||
description: Suggest a feature or improvement
|
description: Suggest a feature or improvement
|
||||||
title: '[Feature Request]: '
|
title: "\u200b"
|
||||||
labels: ['feat', 'story']
|
labels: ['feat', 'story']
|
||||||
body:
|
body:
|
||||||
- type: markdown
|
- type: markdown
|
||||||
@@ -34,11 +34,3 @@ body:
|
|||||||
See the AFFiNE [Contributing Guide](https://github.com/toeverything/affine/blob/canary/CONTRIBUTING.md) to get started.
|
See the AFFiNE [Contributing Guide](https://github.com/toeverything/affine/blob/canary/CONTRIBUTING.md) to get started.
|
||||||
options:
|
options:
|
||||||
- label: Yes I'd like to help by submitting a PR!
|
- label: Yes I'd like to help by submitting a PR!
|
||||||
- type: checkboxes
|
|
||||||
attributes:
|
|
||||||
label: Is your content generated by AI?
|
|
||||||
description: >
|
|
||||||
(Required) Please confirm that the content you submit was not generated by AI or only minimally edited by AI.
|
|
||||||
If an administrator believes the post contains a large amount of AI-generated content, they may directly close the question.
|
|
||||||
options:
|
|
||||||
- label: I confirm that the content I submitted was **not** generated by AI / **merely contained minimal** AI edits.
|
|
||||||
|
|||||||
70
.github/actions/build-rust/action.yml
vendored
70
.github/actions/build-rust/action.yml
vendored
@@ -7,10 +7,9 @@ inputs:
|
|||||||
package:
|
package:
|
||||||
description: 'Package to build'
|
description: 'Package to build'
|
||||||
required: true
|
required: true
|
||||||
no-build:
|
nx_token:
|
||||||
description: 'Whether to skip building'
|
description: 'Nx Cloud access token'
|
||||||
required: false
|
required: false
|
||||||
default: 'false'
|
|
||||||
|
|
||||||
runs:
|
runs:
|
||||||
using: 'composite'
|
using: 'composite'
|
||||||
@@ -18,78 +17,39 @@ runs:
|
|||||||
- name: Print rustup toolchain version
|
- name: Print rustup toolchain version
|
||||||
shell: bash
|
shell: bash
|
||||||
id: rustup-version
|
id: rustup-version
|
||||||
working-directory: ${{ env.DEV_DRIVE_WORKSPACE || github.workspace }}
|
|
||||||
run: |
|
run: |
|
||||||
export RUST_TOOLCHAIN_VERSION="$(grep 'channel' rust-toolchain.toml | head -1 | awk -F '"' '{print $2}')"
|
export RUST_TOOLCHAIN_VERSION="$(grep 'channel' rust-toolchain.toml | head -1 | awk -F '"' '{print $2}')"
|
||||||
echo "Rust toolchain version: $RUST_TOOLCHAIN_VERSION"
|
echo "Rust toolchain version: $RUST_TOOLCHAIN_VERSION"
|
||||||
echo "RUST_TOOLCHAIN_VERSION=$RUST_TOOLCHAIN_VERSION" >> "$GITHUB_OUTPUT"
|
echo "RUST_TOOLCHAIN_VERSION=$RUST_TOOLCHAIN_VERSION" >> "$GITHUB_OUTPUT"
|
||||||
- name: Setup Rust
|
- name: Setup Rust
|
||||||
uses: dtolnay/rust-toolchain@stable
|
uses: dtolnay/rust-toolchain@stable
|
||||||
if: ${{ runner.os != 'Windows' }}
|
|
||||||
with:
|
with:
|
||||||
toolchain: '${{ steps.rustup-version.outputs.RUST_TOOLCHAIN_VERSION }}'
|
toolchain: '${{ steps.rustup-version.outputs.RUST_TOOLCHAIN_VERSION }}'
|
||||||
targets: ${{ inputs.target }}
|
targets: ${{ inputs.target }}
|
||||||
env:
|
env:
|
||||||
CARGO_INCREMENTAL: '1'
|
CARGO_INCREMENTAL: '1'
|
||||||
|
|
||||||
- name: Setup Rust
|
|
||||||
uses: dtolnay/rust-toolchain@stable
|
|
||||||
if: ${{ runner.os == 'Windows' }}
|
|
||||||
with:
|
|
||||||
toolchain: '${{ steps.rustup-version.outputs.RUST_TOOLCHAIN_VERSION }}'
|
|
||||||
targets: ${{ inputs.target }}
|
|
||||||
env:
|
|
||||||
CARGO_INCREMENTAL: '1'
|
|
||||||
CARGO_HOME: ${{ env.DEV_DRIVE }}/.cargo
|
|
||||||
RUSTUP_HOME: ${{ env.DEV_DRIVE }}/.rustup
|
|
||||||
|
|
||||||
- name: Set CC
|
- name: Set CC
|
||||||
if: ${{ contains(inputs.target, 'linux') && inputs.no-build != 'true' }}
|
if: ${{ contains(inputs.target, 'linux') && inputs.package != '@affine/native' }}
|
||||||
working-directory: ${{ env.DEV_DRIVE_WORKSPACE || github.workspace }}
|
|
||||||
shell: bash
|
shell: bash
|
||||||
# https://github.com/tree-sitter/tree-sitter/issues/4186
|
|
||||||
# pass -D_BSD_SOURCE to clang to fix the tree-sitter build issue
|
|
||||||
run: |
|
run: |
|
||||||
echo "CC=clang -D_BSD_SOURCE" >> "$GITHUB_ENV"
|
echo "CC=clang" >> "$GITHUB_ENV"
|
||||||
echo "TARGET_CC=clang -D_BSD_SOURCE" >> "$GITHUB_ENV"
|
echo "TARGET_CC=clang" >> "$GITHUB_ENV"
|
||||||
|
|
||||||
- name: Cache cargo
|
- name: Cache cargo
|
||||||
uses: Swatinem/rust-cache@v2
|
uses: actions/cache@v4
|
||||||
if: ${{ runner.os == 'Windows' }}
|
|
||||||
with:
|
with:
|
||||||
workspaces: ${{ env.DEV_DRIVE_WORKSPACE }}
|
path: |
|
||||||
save-if: ${{ github.ref_name == 'canary' }}
|
~/.cargo/registry/index/
|
||||||
shared-key: ${{ inputs.target }}-${{ inputs.package }}
|
~/.cargo/registry/cache/
|
||||||
env:
|
~/.cargo/git/db/
|
||||||
CARGO_HOME: ${{ env.DEV_DRIVE }}/.cargo
|
~/.napi-rs
|
||||||
RUSTUP_HOME: ${{ env.DEV_DRIVE }}/.rustup
|
target/${{ inputs.target }}
|
||||||
|
key: stable-${{ inputs.target }}-cargo-cache
|
||||||
- name: Cache cargo
|
|
||||||
uses: Swatinem/rust-cache@v2
|
|
||||||
if: ${{ runner.os != 'Windows' }}
|
|
||||||
with:
|
|
||||||
save-if: ${{ github.ref_name == 'canary' }}
|
|
||||||
shared-key: ${{ inputs.target }}-${{ inputs.package }}
|
|
||||||
|
|
||||||
- name: Build
|
- name: Build
|
||||||
shell: bash
|
shell: bash
|
||||||
if: ${{ runner.os != 'Windows' && inputs.no-build != 'true' }}
|
|
||||||
run: |
|
run: |
|
||||||
if [[ "${{ inputs.target }}" == "x86_64-unknown-linux-gnu" ]]; then
|
yarn workspace ${{ inputs.package }} nx build ${{ inputs.package }} --target ${{ inputs.target }} --use-napi-cross
|
||||||
yarn workspace ${{ inputs.package }} build --target ${{ inputs.target }}
|
|
||||||
else
|
|
||||||
yarn workspace ${{ inputs.package }} build --target ${{ inputs.target }} --use-napi-cross
|
|
||||||
fi
|
|
||||||
env:
|
env:
|
||||||
|
NX_CLOUD_ACCESS_TOKEN: ${{ inputs.nx_token }}
|
||||||
DEBUG: 'napi:*'
|
DEBUG: 'napi:*'
|
||||||
|
|
||||||
- name: Build
|
|
||||||
working-directory: ${{ env.DEV_DRIVE_WORKSPACE || github.workspace }}
|
|
||||||
shell: bash
|
|
||||||
if: ${{ runner.os == 'Windows' && inputs.no-build != 'true' }}
|
|
||||||
run: |
|
|
||||||
yarn workspace ${{ inputs.package }} build --target ${{ inputs.target }}
|
|
||||||
env:
|
|
||||||
DEBUG: 'napi:*'
|
|
||||||
CARGO_HOME: ${{ env.DEV_DRIVE }}/.cargo
|
|
||||||
RUSTUP_HOME: ${{ env.DEV_DRIVE }}/.rustup
|
|
||||||
|
|||||||
36
.github/actions/cluster-auth/action.yml
vendored
36
.github/actions/cluster-auth/action.yml
vendored
@@ -1,36 +0,0 @@
|
|||||||
name: 'Auth to Cluster'
|
|
||||||
description: 'Auth to the GCP Cluster'
|
|
||||||
inputs:
|
|
||||||
gcp-project-number:
|
|
||||||
description: 'GCP project number'
|
|
||||||
required: true
|
|
||||||
gcp-project-id:
|
|
||||||
description: 'GCP project id'
|
|
||||||
required: true
|
|
||||||
service-account:
|
|
||||||
description: 'Service account'
|
|
||||||
cluster-name:
|
|
||||||
description: 'Cluster name'
|
|
||||||
cluster-location:
|
|
||||||
description: 'Cluster location'
|
|
||||||
|
|
||||||
runs:
|
|
||||||
using: 'composite'
|
|
||||||
steps:
|
|
||||||
- id: auth
|
|
||||||
uses: google-github-actions/auth@v2
|
|
||||||
with:
|
|
||||||
workload_identity_provider: 'projects/${{ inputs.gcp-project-number }}/locations/global/workloadIdentityPools/github-actions/providers/github-actions-helm-deploy'
|
|
||||||
service_account: '${{ inputs.service-account }}'
|
|
||||||
token_format: 'access_token'
|
|
||||||
project_id: '${{ inputs.gcp-project-id }}'
|
|
||||||
|
|
||||||
- name: 'Setup gcloud cli'
|
|
||||||
uses: 'google-github-actions/setup-gcloud@v2'
|
|
||||||
with:
|
|
||||||
install_components: 'gke-gcloud-auth-plugin'
|
|
||||||
|
|
||||||
- id: get-gke-credentials
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
gcloud container clusters get-credentials ${{ inputs.cluster-name }} --region ${{ inputs.cluster-location }} --project ${{ inputs.gcp-project-id }}
|
|
||||||
25
.github/actions/copilot-test/action.yml
vendored
25
.github/actions/copilot-test/action.yml
vendored
@@ -1,25 +0,0 @@
|
|||||||
name: 'Run Copilot E2E Test'
|
|
||||||
description: 'Run Copilot E2E Test'
|
|
||||||
inputs:
|
|
||||||
script:
|
|
||||||
description: 'Script to run'
|
|
||||||
default: 'yarn affine @affine-test/affine-cloud-copilot e2e --forbid-only'
|
|
||||||
required: false
|
|
||||||
|
|
||||||
runs:
|
|
||||||
using: 'composite'
|
|
||||||
steps:
|
|
||||||
- name: Server Copilot E2E Test
|
|
||||||
shell: bash
|
|
||||||
run: ${{ inputs.script }}
|
|
||||||
env:
|
|
||||||
COPILOT: true
|
|
||||||
DEV_SERVER_URL: http://localhost:8080
|
|
||||||
|
|
||||||
- name: Upload test results
|
|
||||||
if: ${{ failure() }}
|
|
||||||
uses: actions/upload-artifact@v4
|
|
||||||
with:
|
|
||||||
name: test-results-e2e-server-copilot
|
|
||||||
path: ./test-results
|
|
||||||
if-no-files-found: ignore
|
|
||||||
29
.github/actions/deploy/action.yml
vendored
29
.github/actions/deploy/action.yml
vendored
@@ -1,6 +1,9 @@
|
|||||||
name: 'Deploy to Cluster'
|
name: 'Deploy to Cluster'
|
||||||
description: 'Deploy AFFiNE Cloud to cluster'
|
description: 'Deploy AFFiNE Cloud to cluster'
|
||||||
inputs:
|
inputs:
|
||||||
|
build-type:
|
||||||
|
description: 'Align with App build type, canary|beta|stable|internal'
|
||||||
|
default: 'canary'
|
||||||
gcp-project-number:
|
gcp-project-number:
|
||||||
description: 'GCP project number'
|
description: 'GCP project number'
|
||||||
required: true
|
required: true
|
||||||
@@ -21,15 +24,27 @@ runs:
|
|||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
echo "GIT_SHORT_HASH=$(git rev-parse --short HEAD)" >> "$GITHUB_ENV"
|
echo "GIT_SHORT_HASH=$(git rev-parse --short HEAD)" >> "$GITHUB_ENV"
|
||||||
- name: 'Auth to cluster'
|
- uses: azure/setup-helm@v3
|
||||||
uses: './.github/actions/cluster-auth'
|
- id: auth
|
||||||
|
uses: google-github-actions/auth@v2
|
||||||
with:
|
with:
|
||||||
gcp-project-number: '${{ inputs.gcp-project-number }}'
|
workload_identity_provider: 'projects/${{ inputs.gcp-project-number }}/locations/global/workloadIdentityPools/github-actions/providers/github-actions-helm-deploy'
|
||||||
gcp-project-id: '${{ inputs.gcp-project-id }}'
|
service_account: '${{ inputs.service-account }}'
|
||||||
service-account: '${{ inputs.service-account }}'
|
token_format: 'access_token'
|
||||||
cluster-name: '${{ inputs.cluster-name }}'
|
project_id: '${{ inputs.gcp-project-id }}'
|
||||||
cluster-location: '${{ inputs.cluster-location }}'
|
|
||||||
|
- name: 'Setup gcloud cli'
|
||||||
|
uses: 'google-github-actions/setup-gcloud@v2'
|
||||||
|
with:
|
||||||
|
install_components: 'gke-gcloud-auth-plugin'
|
||||||
|
|
||||||
|
- id: get-gke-credentials
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
gcloud container clusters get-credentials ${{ inputs.cluster-name }} --region ${{ inputs.cluster-location }} --project ${{ inputs.gcp-project-id }}
|
||||||
|
|
||||||
- name: Deploy
|
- name: Deploy
|
||||||
shell: bash
|
shell: bash
|
||||||
run: node ./.github/actions/deploy/deploy.mjs
|
run: node ./.github/actions/deploy/deploy.mjs
|
||||||
|
env:
|
||||||
|
BUILD_TYPE: '${{ inputs.build-type }}'
|
||||||
|
|||||||
179
.github/actions/deploy/deploy.mjs
vendored
179
.github/actions/deploy/deploy.mjs
vendored
@@ -10,48 +10,32 @@ const {
|
|||||||
DATABASE_USERNAME,
|
DATABASE_USERNAME,
|
||||||
DATABASE_PASSWORD,
|
DATABASE_PASSWORD,
|
||||||
DATABASE_NAME,
|
DATABASE_NAME,
|
||||||
GCLOUD_CONNECTION_NAME,
|
R2_ACCOUNT_ID,
|
||||||
|
R2_ACCESS_KEY_ID,
|
||||||
|
R2_SECRET_ACCESS_KEY,
|
||||||
|
ENABLE_CAPTCHA,
|
||||||
|
CAPTCHA_TURNSTILE_SECRET,
|
||||||
|
OAUTH_EMAIL_SENDER,
|
||||||
|
OAUTH_EMAIL_LOGIN,
|
||||||
|
OAUTH_EMAIL_PASSWORD,
|
||||||
|
AFFINE_GOOGLE_CLIENT_ID,
|
||||||
|
AFFINE_GOOGLE_CLIENT_SECRET,
|
||||||
CLOUD_SQL_IAM_ACCOUNT,
|
CLOUD_SQL_IAM_ACCOUNT,
|
||||||
APP_IAM_ACCOUNT,
|
GCLOUD_CONNECTION_NAME,
|
||||||
REDIS_SERVER_HOST,
|
GCLOUD_CLOUD_SQL_INTERNAL_ENDPOINT,
|
||||||
REDIS_SERVER_PASSWORD,
|
REDIS_HOST,
|
||||||
|
REDIS_PASSWORD,
|
||||||
|
STRIPE_API_KEY,
|
||||||
|
STRIPE_WEBHOOK_KEY,
|
||||||
STATIC_IP_NAME,
|
STATIC_IP_NAME,
|
||||||
AFFINE_INDEXER_SEARCH_PROVIDER,
|
|
||||||
AFFINE_INDEXER_SEARCH_ENDPOINT,
|
|
||||||
AFFINE_INDEXER_SEARCH_API_KEY,
|
|
||||||
} = process.env;
|
} = process.env;
|
||||||
|
|
||||||
|
// eslint-disable-next-line @typescript-eslint/no-non-null-assertion
|
||||||
const buildType = BUILD_TYPE || 'canary';
|
const buildType = BUILD_TYPE || 'canary';
|
||||||
|
|
||||||
const isProduction = buildType === 'stable';
|
const isProduction = buildType === 'stable';
|
||||||
const isBeta = buildType === 'beta';
|
const isBeta = buildType === 'beta';
|
||||||
const isCanary = buildType === 'canary';
|
|
||||||
const isInternal = buildType === 'internal';
|
const isInternal = buildType === 'internal';
|
||||||
const isSpotEnabled = isBeta || isCanary;
|
|
||||||
|
|
||||||
const replicaConfig = {
|
|
||||||
stable: {
|
|
||||||
front: Number(process.env.PRODUCTION_FRONT_REPLICA) || 2,
|
|
||||||
graphql: Number(process.env.PRODUCTION_GRAPHQL_REPLICA) || 2,
|
|
||||||
doc: Number(process.env.PRODUCTION_DOC_REPLICA) || 2,
|
|
||||||
},
|
|
||||||
beta: {
|
|
||||||
front: Number(process.env.BETA_FRONT_REPLICA) || 1,
|
|
||||||
graphql: Number(process.env.BETA_GRAPHQL_REPLICA) || 1,
|
|
||||||
doc: Number(process.env.BETA_DOC_REPLICA) || 1,
|
|
||||||
},
|
|
||||||
canary: { front: 1, graphql: 1, doc: 1 },
|
|
||||||
};
|
|
||||||
|
|
||||||
const cpuConfig = {
|
|
||||||
beta: { front: '1', graphql: '1', doc: '1' },
|
|
||||||
canary: { front: '500m', graphql: '1', doc: '500m' },
|
|
||||||
};
|
|
||||||
|
|
||||||
const memoryConfig = {
|
|
||||||
beta: { front: '1Gi', graphql: '1Gi', doc: '1Gi' },
|
|
||||||
canary: { front: '512Mi', graphql: '512Mi', doc: '512Mi' },
|
|
||||||
};
|
|
||||||
|
|
||||||
const createHelmCommand = ({ isDryRun }) => {
|
const createHelmCommand = ({ isDryRun }) => {
|
||||||
const flag = isDryRun ? '--dry-run' : '--atomic';
|
const flag = isDryRun ? '--dry-run' : '--atomic';
|
||||||
@@ -59,69 +43,38 @@ const createHelmCommand = ({ isDryRun }) => {
|
|||||||
const redisAndPostgres =
|
const redisAndPostgres =
|
||||||
isProduction || isBeta || isInternal
|
isProduction || isBeta || isInternal
|
||||||
? [
|
? [
|
||||||
`--set cloud-sql-proxy.enabled=true`,
|
`--set-string global.database.url=${DATABASE_URL}`,
|
||||||
`--set-string cloud-sql-proxy.database.connectionName="${GCLOUD_CONNECTION_NAME}"`,
|
|
||||||
`--set-string global.database.host=${DATABASE_URL}`,
|
|
||||||
`--set-string global.database.user=${DATABASE_USERNAME}`,
|
`--set-string global.database.user=${DATABASE_USERNAME}`,
|
||||||
`--set-string global.database.password=${DATABASE_PASSWORD}`,
|
`--set-string global.database.password=${DATABASE_PASSWORD}`,
|
||||||
`--set-string global.database.name=${DATABASE_NAME}`,
|
`--set-string global.database.name=${DATABASE_NAME}`,
|
||||||
`--set-string global.redis.host="${REDIS_SERVER_HOST}"`,
|
`--set global.database.gcloud.enabled=true`,
|
||||||
`--set-string global.redis.password="${REDIS_SERVER_PASSWORD}"`,
|
`--set-string global.database.gcloud.connectionName="${GCLOUD_CONNECTION_NAME}"`,
|
||||||
|
`--set-string global.database.gcloud.cloudSqlInternal="${GCLOUD_CLOUD_SQL_INTERNAL_ENDPOINT}"`,
|
||||||
|
`--set-string global.redis.host="${REDIS_HOST}"`,
|
||||||
|
`--set-string global.redis.password="${REDIS_PASSWORD}"`,
|
||||||
]
|
]
|
||||||
: [];
|
: [];
|
||||||
const indexerOptions = [
|
const serviceAnnotations =
|
||||||
`--set-string global.indexer.provider="${AFFINE_INDEXER_SEARCH_PROVIDER}"`,
|
|
||||||
`--set-string global.indexer.endpoint="${AFFINE_INDEXER_SEARCH_ENDPOINT}"`,
|
|
||||||
`--set-string global.indexer.apiKey="${AFFINE_INDEXER_SEARCH_API_KEY}"`,
|
|
||||||
];
|
|
||||||
const cloudSqlNodeSelector = isBeta
|
|
||||||
? `{ \\"iam.gke.io/gke-metadata-server-enabled\\": \\"true\\", \\"cloud.google.com/gke-spot\\": \\"true\\" }`
|
|
||||||
: `{ \\"iam.gke.io/gke-metadata-server-enabled\\": \\"true\\" }`;
|
|
||||||
const serviceAnnotations = [
|
|
||||||
`--set-json front.serviceAccount.annotations="{ \\"iam.gke.io/gcp-service-account\\": \\"${APP_IAM_ACCOUNT}\\" }"`,
|
|
||||||
`--set-json graphql.serviceAccount.annotations="{ \\"iam.gke.io/gcp-service-account\\": \\"${APP_IAM_ACCOUNT}\\" }"`,
|
|
||||||
`--set-json doc.serviceAccount.annotations="{ \\"iam.gke.io/gcp-service-account\\": \\"${APP_IAM_ACCOUNT}\\" }"`,
|
|
||||||
].concat(
|
|
||||||
isProduction || isBeta || isInternal
|
isProduction || isBeta || isInternal
|
||||||
? [
|
? [
|
||||||
`--set-json front.services.web.annotations="{ \\"cloud.google.com/neg\\": \\"{\\\\\\"ingress\\\\\\": true}\\" }"`,
|
`--set-json web.service.annotations=\"{ \\"cloud.google.com/neg\\": \\"{\\\\\\"ingress\\\\\\": true}\\" }\"`,
|
||||||
`--set-json front.services.sync.annotations="{ \\"cloud.google.com/neg\\": \\"{\\\\\\"ingress\\\\\\": true}\\" }"`,
|
`--set-json graphql.service.annotations=\"{ \\"cloud.google.com/neg\\": \\"{\\\\\\"ingress\\\\\\": true}\\" }\"`,
|
||||||
`--set-json front.services.renderer.annotations="{ \\"cloud.google.com/neg\\": \\"{\\\\\\"ingress\\\\\\": true}\\" }"`,
|
`--set-json sync.service.annotations=\"{ \\"cloud.google.com/neg\\": \\"{\\\\\\"ingress\\\\\\": true}\\" }\"`,
|
||||||
`--set-json graphql.service.annotations="{ \\"cloud.google.com/neg\\": \\"{\\\\\\"ingress\\\\\\": true}\\" }"`,
|
`--set-json cloud-sql-proxy.serviceAccount.annotations=\"{ \\"iam.gke.io/gcp-service-account\\": \\"${CLOUD_SQL_IAM_ACCOUNT}\\" }\"`,
|
||||||
`--set-json cloud-sql-proxy.serviceAccount.annotations="{ \\"iam.gke.io/gcp-service-account\\": \\"${CLOUD_SQL_IAM_ACCOUNT}\\" }"`,
|
`--set-json cloud-sql-proxy.nodeSelector=\"{ \\"iam.gke.io/gke-metadata-server-enabled\\": \\"true\\" }\"`,
|
||||||
`--set-json cloud-sql-proxy.nodeSelector="${cloudSqlNodeSelector}"`,
|
|
||||||
]
|
]
|
||||||
: []
|
: [];
|
||||||
);
|
const webReplicaCount = isProduction ? 3 : isBeta ? 2 : 2;
|
||||||
const spotNodeSelector = `{ \\"cloud.google.com/gke-spot\\": \\"true\\" }`;
|
const graphqlReplicaCount = isProduction
|
||||||
const spotScheduling = isSpotEnabled
|
? Number(process.env.PRODUCTION_GRAPHQL_REPLICA) || 3
|
||||||
? [
|
: isBeta
|
||||||
`--set-json front.nodeSelector="${spotNodeSelector}"`,
|
? Number(process.env.isBeta_GRAPHQL_REPLICA) || 2
|
||||||
`--set-json graphql.nodeSelector="${spotNodeSelector}"`,
|
: 2;
|
||||||
`--set-json doc.nodeSelector="${spotNodeSelector}"`,
|
const syncReplicaCount = isProduction
|
||||||
]
|
? Number(process.env.PRODUCTION_SYNC_REPLICA) || 3
|
||||||
: [];
|
: isBeta
|
||||||
|
? Number(process.env.BETA_SYNC_REPLICA) || 2
|
||||||
const cpu = cpuConfig[buildType];
|
: 2;
|
||||||
const memory = memoryConfig[buildType];
|
|
||||||
let resources = [];
|
|
||||||
if (cpu) {
|
|
||||||
resources = resources.concat([
|
|
||||||
`--set front.resources.requests.cpu="${cpu.front}"`,
|
|
||||||
`--set graphql.resources.requests.cpu="${cpu.graphql}"`,
|
|
||||||
`--set doc.resources.requests.cpu="${cpu.doc}"`,
|
|
||||||
]);
|
|
||||||
}
|
|
||||||
if (memory) {
|
|
||||||
resources = resources.concat([
|
|
||||||
`--set front.resources.requests.memory="${memory.front}"`,
|
|
||||||
`--set graphql.resources.requests.memory="${memory.graphql}"`,
|
|
||||||
`--set doc.resources.requests.memory="${memory.doc}"`,
|
|
||||||
]);
|
|
||||||
}
|
|
||||||
|
|
||||||
const replica = replicaConfig[buildType] || replicaConfig.canary;
|
|
||||||
|
|
||||||
const namespace = isProduction
|
const namespace = isProduction
|
||||||
? 'production'
|
? 'production'
|
||||||
: isBeta
|
: isBeta
|
||||||
@@ -129,38 +82,40 @@ const createHelmCommand = ({ isDryRun }) => {
|
|||||||
: isInternal
|
: isInternal
|
||||||
? 'internal'
|
? 'internal'
|
||||||
: 'dev';
|
: 'dev';
|
||||||
|
// eslint-disable-next-line @typescript-eslint/no-non-null-assertion
|
||||||
const hosts = (DEPLOY_HOST || CANARY_DEPLOY_HOST)
|
const host = DEPLOY_HOST || CANARY_DEPLOY_HOST;
|
||||||
.split(',')
|
|
||||||
.map(host => host.trim())
|
|
||||||
.filter(host => host);
|
|
||||||
const primaryHost = hosts[0] || '0.0.0.0';
|
|
||||||
const deployCommand = [
|
const deployCommand = [
|
||||||
`helm upgrade --install affine .github/helm/affine`,
|
`helm upgrade --install affine .github/helm/affine`,
|
||||||
`--namespace ${namespace}`,
|
`--namespace ${namespace}`,
|
||||||
`--set-string global.deployment.type="affine"`,
|
|
||||||
`--set-string global.deployment.platform="gcp"`,
|
|
||||||
`--set-string global.app.buildType="${buildType}"`,
|
|
||||||
`--set global.ingress.enabled=true`,
|
`--set global.ingress.enabled=true`,
|
||||||
`--set-json global.ingress.annotations="{ \\"kubernetes.io/ingress.class\\": \\"gce\\", \\"kubernetes.io/ingress.allow-http\\": \\"true\\", \\"kubernetes.io/ingress.global-static-ip-name\\": \\"${STATIC_IP_NAME}\\" }"`,
|
`--set-json global.ingress.annotations=\"{ \\"kubernetes.io/ingress.class\\": \\"gce\\", \\"kubernetes.io/ingress.allow-http\\": \\"true\\", \\"kubernetes.io/ingress.global-static-ip-name\\": \\"${STATIC_IP_NAME}\\" }\"`,
|
||||||
...hosts.map(
|
`--set-string global.ingress.host="${host}"`,
|
||||||
(host, index) => `--set global.ingress.hosts[${index}]=${host}`
|
|
||||||
),
|
|
||||||
`--set-string global.version="${APP_VERSION}"`,
|
`--set-string global.version="${APP_VERSION}"`,
|
||||||
...redisAndPostgres,
|
...redisAndPostgres,
|
||||||
...indexerOptions,
|
`--set web.replicaCount=${webReplicaCount}`,
|
||||||
`--set front.replicaCount=${replica.front}`,
|
`--set-string web.image.tag="${imageTag}"`,
|
||||||
`--set-string front.image.tag="${imageTag}"`,
|
`--set graphql.replicaCount=${graphqlReplicaCount}`,
|
||||||
`--set-string front.app.host="${primaryHost}"`,
|
|
||||||
`--set graphql.replicaCount=${replica.graphql}`,
|
|
||||||
`--set-string graphql.image.tag="${imageTag}"`,
|
`--set-string graphql.image.tag="${imageTag}"`,
|
||||||
`--set-string graphql.app.host="${primaryHost}"`,
|
`--set graphql.app.host=${host}`,
|
||||||
`--set-string doc.image.tag="${imageTag}"`,
|
`--set graphql.app.captcha.enabled=${ENABLE_CAPTCHA}`,
|
||||||
`--set-string doc.app.host="${primaryHost}"`,
|
`--set-string graphql.app.captcha.turnstile.secret="${CAPTCHA_TURNSTILE_SECRET}"`,
|
||||||
`--set doc.replicaCount=${replica.doc}`,
|
`--set graphql.app.objectStorage.r2.enabled=true`,
|
||||||
|
`--set-string graphql.app.objectStorage.r2.accountId="${R2_ACCOUNT_ID}"`,
|
||||||
|
`--set-string graphql.app.objectStorage.r2.accessKeyId="${R2_ACCESS_KEY_ID}"`,
|
||||||
|
`--set-string graphql.app.objectStorage.r2.secretAccessKey="${R2_SECRET_ACCESS_KEY}"`,
|
||||||
|
`--set-string graphql.app.oauth.email.sender="${OAUTH_EMAIL_SENDER}"`,
|
||||||
|
`--set-string graphql.app.oauth.email.login="${OAUTH_EMAIL_LOGIN}"`,
|
||||||
|
`--set-string graphql.app.oauth.email.password="${OAUTH_EMAIL_PASSWORD}"`,
|
||||||
|
`--set-string graphql.app.oauth.google.enabled=true`,
|
||||||
|
`--set-string graphql.app.oauth.google.clientId="${AFFINE_GOOGLE_CLIENT_ID}"`,
|
||||||
|
`--set-string graphql.app.oauth.google.clientSecret="${AFFINE_GOOGLE_CLIENT_SECRET}"`,
|
||||||
|
`--set-string graphql.app.payment.stripe.apiKey="${STRIPE_API_KEY}"`,
|
||||||
|
`--set-string graphql.app.payment.stripe.webhookKey="${STRIPE_WEBHOOK_KEY}"`,
|
||||||
|
`--set graphql.app.experimental.enableJwstCodec=true`,
|
||||||
|
`--set graphql.app.features.earlyAccessPreview=false`,
|
||||||
|
`--set sync.replicaCount=${syncReplicaCount}`,
|
||||||
|
`--set-string sync.image.tag="${imageTag}"`,
|
||||||
...serviceAnnotations,
|
...serviceAnnotations,
|
||||||
...spotScheduling,
|
|
||||||
...resources,
|
|
||||||
`--timeout 10m`,
|
`--timeout 10m`,
|
||||||
flag,
|
flag,
|
||||||
].join(' ');
|
].join(' ');
|
||||||
|
|||||||
22
.github/actions/download-core/action.yml
vendored
Normal file
22
.github/actions/download-core/action.yml
vendored
Normal file
@@ -0,0 +1,22 @@
|
|||||||
|
name: 'Download core artifacts'
|
||||||
|
description: 'Download core artifacts and extract to dist'
|
||||||
|
inputs:
|
||||||
|
path:
|
||||||
|
description: 'Path to extract'
|
||||||
|
required: true
|
||||||
|
|
||||||
|
runs:
|
||||||
|
using: 'composite'
|
||||||
|
steps:
|
||||||
|
- name: Download tar.gz
|
||||||
|
uses: actions/download-artifact@v4
|
||||||
|
with:
|
||||||
|
name: core
|
||||||
|
path: .
|
||||||
|
|
||||||
|
- name: Extract core artifacts
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
mkdir -p ${{ inputs.path }}
|
||||||
|
tar -xvf dist.tar.gz --directory ${{ inputs.path }}
|
||||||
|
rm dist.tar.gz
|
||||||
22
.github/actions/download-web/action.yml
vendored
22
.github/actions/download-web/action.yml
vendored
@@ -1,22 +0,0 @@
|
|||||||
name: 'Download core artifacts'
|
|
||||||
description: 'Download core artifacts and extract to dist'
|
|
||||||
inputs:
|
|
||||||
path:
|
|
||||||
description: 'Path to extract'
|
|
||||||
required: true
|
|
||||||
|
|
||||||
runs:
|
|
||||||
using: 'composite'
|
|
||||||
steps:
|
|
||||||
- name: Download tar.gz
|
|
||||||
uses: actions/download-artifact@v4
|
|
||||||
with:
|
|
||||||
name: web
|
|
||||||
path: .
|
|
||||||
|
|
||||||
- name: Extract core artifacts
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
mkdir -p ${{ inputs.path }}
|
|
||||||
tar -xvf dist.tar.gz --directory ${{ inputs.path }}
|
|
||||||
rm dist.tar.gz
|
|
||||||
41
.github/actions/prepare-release/action.yml
vendored
41
.github/actions/prepare-release/action.yml
vendored
@@ -1,41 +0,0 @@
|
|||||||
name: Prepare Release
|
|
||||||
description: 'Prepare Release'
|
|
||||||
outputs:
|
|
||||||
APP_VERSION:
|
|
||||||
description: 'App Version'
|
|
||||||
value: ${{ steps.get-version.outputs.APP_VERSION }}
|
|
||||||
GIT_SHORT_HASH:
|
|
||||||
description: 'Git Short Hash'
|
|
||||||
value: ${{ steps.get-version.outputs.GIT_SHORT_HASH }}
|
|
||||||
BUILD_TYPE:
|
|
||||||
description: 'Build Type'
|
|
||||||
value: ${{ steps.get-version.outputs.BUILD_TYPE }}
|
|
||||||
runs:
|
|
||||||
using: 'composite'
|
|
||||||
steps:
|
|
||||||
- name: Get Version
|
|
||||||
id: get-version
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
GIT_SHORT_HASH=$(git rev-parse --short HEAD)
|
|
||||||
if [ "${{ github.ref_type }}" == "tag" ]; then
|
|
||||||
APP_VERSION=$(echo "${{ github.ref_name }}" | sed 's/^v//')
|
|
||||||
else
|
|
||||||
APP_VERSION=$(date '+%Y.%-m.%-d-canary.%-H%M')
|
|
||||||
fi
|
|
||||||
if [[ "$APP_VERSION" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
|
|
||||||
BUILD_TYPE=stable
|
|
||||||
elif [[ "$APP_VERSION" =~ ^[0-9]+\.[0-9]+\.[0-9]+-beta\.[0-9]+$ ]]; then
|
|
||||||
BUILD_TYPE=beta
|
|
||||||
elif [[ "$APP_VERSION" =~ ^[0-9]+\.[0-9]+\.[0-9]+-canary\.[0-9a-f]+$ ]]; then
|
|
||||||
BUILD_TYPE=canary
|
|
||||||
else
|
|
||||||
echo "Error: unsupported version string: $APP_VERSION" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
echo $APP_VERSION
|
|
||||||
echo $GIT_SHORT_HASH
|
|
||||||
echo $BUILD_TYPE
|
|
||||||
echo "APP_VERSION=$APP_VERSION" >> "$GITHUB_OUTPUT"
|
|
||||||
echo "GIT_SHORT_HASH=$GIT_SHORT_HASH" >> "$GITHUB_OUTPUT"
|
|
||||||
echo "BUILD_TYPE=$BUILD_TYPE" >> "$GITHUB_OUTPUT"
|
|
||||||
30
.github/actions/server-test-env/action.yml
vendored
30
.github/actions/server-test-env/action.yml
vendored
@@ -1,30 +0,0 @@
|
|||||||
name: 'Prepare Server Test Environment'
|
|
||||||
description: 'Prepare Server Test Environment'
|
|
||||||
|
|
||||||
runs:
|
|
||||||
using: 'composite'
|
|
||||||
steps:
|
|
||||||
- name: Initialize database
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
psql -h localhost -U postgres -c "CREATE DATABASE affine;"
|
|
||||||
psql -h localhost -U postgres -c "CREATE USER affine WITH PASSWORD 'affine';"
|
|
||||||
psql -h localhost -U postgres -c "ALTER USER affine WITH SUPERUSER;"
|
|
||||||
env:
|
|
||||||
PGPASSWORD: affine
|
|
||||||
|
|
||||||
- name: Run init-db script
|
|
||||||
shell: bash
|
|
||||||
env:
|
|
||||||
NODE_ENV: test
|
|
||||||
run: |
|
|
||||||
yarn affine @affine/server prisma generate
|
|
||||||
yarn affine @affine/server prisma migrate deploy
|
|
||||||
yarn affine @affine/server data-migration run
|
|
||||||
|
|
||||||
- name: Import config
|
|
||||||
shell: bash
|
|
||||||
env:
|
|
||||||
DEFAULT_CONFIG: '{}'
|
|
||||||
run: |
|
|
||||||
printf '%s\n' "${SERVER_CONFIG:-$DEFAULT_CONFIG}" > ./packages/backend/server/config.json
|
|
||||||
82
.github/actions/setup-node/action.yml
vendored
82
.github/actions/setup-node/action.yml
vendored
@@ -13,18 +13,10 @@ inputs:
|
|||||||
description: 'Run the install step for Playwright.'
|
description: 'Run the install step for Playwright.'
|
||||||
required: false
|
required: false
|
||||||
default: 'false'
|
default: 'false'
|
||||||
playwright-platform:
|
|
||||||
description: 'The platform to install Playwright for.'
|
|
||||||
required: false
|
|
||||||
default: 'chromium,webkit'
|
|
||||||
electron-install:
|
electron-install:
|
||||||
description: 'Download the Electron binary'
|
description: 'Download the Electron binary'
|
||||||
required: false
|
required: false
|
||||||
default: 'true'
|
default: 'true'
|
||||||
corepack-install:
|
|
||||||
description: 'Install CorePack'
|
|
||||||
required: false
|
|
||||||
default: 'false'
|
|
||||||
hard-link-nm:
|
hard-link-nm:
|
||||||
description: 'set nmMode to hardlinks-local in .yarnrc.yml'
|
description: 'set nmMode to hardlinks-local in .yarnrc.yml'
|
||||||
required: false
|
required: false
|
||||||
@@ -39,19 +31,10 @@ inputs:
|
|||||||
full-cache:
|
full-cache:
|
||||||
description: 'Full installation cache'
|
description: 'Full installation cache'
|
||||||
required: false
|
required: false
|
||||||
|
|
||||||
runs:
|
runs:
|
||||||
using: 'composite'
|
using: 'composite'
|
||||||
steps:
|
steps:
|
||||||
- name: Output workspace path
|
|
||||||
id: workspace-path
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
if [ -n "${{ env.DEV_DRIVE_WORKSPACE }}" ]; then
|
|
||||||
echo "workspace_path=${{ env.DEV_DRIVE_WORKSPACE }}" >> $GITHUB_OUTPUT
|
|
||||||
else
|
|
||||||
echo "workspace_path=${{ github.workspace }}" >> $GITHUB_OUTPUT
|
|
||||||
fi
|
|
||||||
|
|
||||||
- name: Setup Node.js
|
- name: Setup Node.js
|
||||||
uses: actions/setup-node@v4
|
uses: actions/setup-node@v4
|
||||||
with:
|
with:
|
||||||
@@ -59,37 +42,24 @@ runs:
|
|||||||
registry-url: https://npm.pkg.github.com
|
registry-url: https://npm.pkg.github.com
|
||||||
scope: '@toeverything'
|
scope: '@toeverything'
|
||||||
|
|
||||||
- uses: kenchan0130/actions-system-info@master
|
|
||||||
id: system-info
|
|
||||||
|
|
||||||
- name: Init CorePack
|
|
||||||
if: ${{ inputs.corepack-install == 'true' }}
|
|
||||||
shell: bash
|
|
||||||
working-directory: ${{ steps.workspace-path.outputs.workspace_path }}
|
|
||||||
run: corepack enable
|
|
||||||
|
|
||||||
- name: Set nmMode
|
- name: Set nmMode
|
||||||
if: ${{ inputs.hard-link-nm == 'false' }}
|
if: ${{ inputs.hard-link-nm == 'false' }}
|
||||||
shell: bash
|
shell: bash
|
||||||
working-directory: ${{ steps.workspace-path.outputs.workspace_path }}
|
|
||||||
run: yarn config set nmMode classic
|
run: yarn config set nmMode classic
|
||||||
|
|
||||||
- name: Set nmHoistingLimits
|
- name: Set nmHoistingLimits
|
||||||
if: ${{ inputs.nmHoistingLimits }}
|
if: ${{ inputs.nmHoistingLimits }}
|
||||||
shell: bash
|
shell: bash
|
||||||
working-directory: ${{ steps.workspace-path.outputs.workspace_path }}
|
|
||||||
run: yarn config set nmHoistingLimits ${{ inputs.nmHoistingLimits }}
|
run: yarn config set nmHoistingLimits ${{ inputs.nmHoistingLimits }}
|
||||||
|
|
||||||
- name: Set enableScripts
|
- name: Set enableScripts
|
||||||
if: ${{ inputs.enableScripts == 'false' }}
|
if: ${{ inputs.enableScripts == 'false' }}
|
||||||
shell: bash
|
shell: bash
|
||||||
working-directory: ${{ steps.workspace-path.outputs.workspace_path }}
|
|
||||||
run: yarn config set enableScripts false
|
run: yarn config set enableScripts false
|
||||||
|
|
||||||
- name: Set yarn global cache path
|
- name: Set yarn global cache path
|
||||||
shell: bash
|
shell: bash
|
||||||
id: yarn-cache
|
id: yarn-cache
|
||||||
working-directory: ${{ steps.workspace-path.outputs.workspace_path }}
|
|
||||||
run: node -e "const p = $(yarn config cacheFolder --json).effective; console.log('yarn_global_cache=' + p)" >> $GITHUB_OUTPUT
|
run: node -e "const p = $(yarn config cacheFolder --json).effective; console.log('yarn_global_cache=' + p)" >> $GITHUB_OUTPUT
|
||||||
|
|
||||||
- name: Cache non-full yarn cache on Linux
|
- name: Cache non-full yarn cache on Linux
|
||||||
@@ -97,9 +67,9 @@ runs:
|
|||||||
if: ${{ inputs.full-cache != 'true' && runner.os == 'Linux' }}
|
if: ${{ inputs.full-cache != 'true' && runner.os == 'Linux' }}
|
||||||
with:
|
with:
|
||||||
path: |
|
path: |
|
||||||
${{ steps.workspace-path.outputs.workspace_path }}/node_modules
|
node_modules
|
||||||
${{ steps.yarn-cache.outputs.yarn_global_cache }}
|
${{ steps.yarn-cache.outputs.yarn_global_cache }}
|
||||||
key: node_modules-cache-${{ github.job }}-${{ runner.os }}-${{ runner.arch }}-${{ steps.system-info.outputs.name }}-${{ steps.system-info.outputs.release }}-${{ steps.system-info.outputs.version }}
|
key: node_modules-cache-${{ github.job }}-${{ runner.os }}
|
||||||
|
|
||||||
# The network performance on macOS is very poor
|
# The network performance on macOS is very poor
|
||||||
# and the decompression performance on Windows is very terrible
|
# and the decompression performance on Windows is very terrible
|
||||||
@@ -110,7 +80,7 @@ runs:
|
|||||||
with:
|
with:
|
||||||
path: |
|
path: |
|
||||||
${{ steps.yarn-cache.outputs.yarn_global_cache }}
|
${{ steps.yarn-cache.outputs.yarn_global_cache }}
|
||||||
key: node_modules-cache-${{ github.job }}-${{ runner.os }}-${{ runner.arch }}-${{ steps.system-info.outputs.name }}-${{ steps.system-info.outputs.release }}-${{ steps.system-info.outputs.version }}
|
key: node_modules-cache-${{ github.job }}-${{ runner.os }}
|
||||||
|
|
||||||
- name: Cache full yarn cache on Linux
|
- name: Cache full yarn cache on Linux
|
||||||
uses: actions/cache@v4
|
uses: actions/cache@v4
|
||||||
@@ -119,7 +89,7 @@ runs:
|
|||||||
path: |
|
path: |
|
||||||
node_modules
|
node_modules
|
||||||
${{ steps.yarn-cache.outputs.yarn_global_cache }}
|
${{ steps.yarn-cache.outputs.yarn_global_cache }}
|
||||||
key: node_modules-cache-full-${{ runner.os }}-${{ runner.arch }}-${{ steps.system-info.outputs.name }}-${{ steps.system-info.outputs.release }}-${{ steps.system-info.outputs.version }}
|
key: node_modules-cache-full-${{ runner.os }}
|
||||||
|
|
||||||
- name: Cache full yarn cache on non-Linux
|
- name: Cache full yarn cache on non-Linux
|
||||||
uses: actions/cache@v4
|
uses: actions/cache@v4
|
||||||
@@ -127,12 +97,23 @@ runs:
|
|||||||
with:
|
with:
|
||||||
path: |
|
path: |
|
||||||
${{ steps.yarn-cache.outputs.yarn_global_cache }}
|
${{ steps.yarn-cache.outputs.yarn_global_cache }}
|
||||||
key: node_modules-cache-full-${{ runner.os }}-${{ runner.arch }}-${{ steps.system-info.outputs.name }}-${{ steps.system-info.outputs.release }}-${{ steps.system-info.outputs.version }}
|
key: node_modules-cache-full-${{ runner.os }}
|
||||||
|
|
||||||
- name: yarn install
|
- name: yarn install
|
||||||
if: ${{ inputs.package-install == 'true' }}
|
if: ${{ inputs.package-install == 'true' }}
|
||||||
|
continue-on-error: true
|
||||||
|
shell: bash
|
||||||
|
run: yarn ${{ inputs.extra-flags }}
|
||||||
|
env:
|
||||||
|
HUSKY: '0'
|
||||||
|
PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD: '1'
|
||||||
|
ELECTRON_SKIP_BINARY_DOWNLOAD: '1'
|
||||||
|
SENTRYCLI_SKIP_DOWNLOAD: '1'
|
||||||
|
DEBUG: '*'
|
||||||
|
|
||||||
|
- name: yarn install (try again)
|
||||||
|
if: ${{ steps.install.outcome == 'failure' }}
|
||||||
shell: bash
|
shell: bash
|
||||||
working-directory: ${{ steps.workspace-path.outputs.workspace_path }}
|
|
||||||
run: yarn ${{ inputs.extra-flags }}
|
run: yarn ${{ inputs.extra-flags }}
|
||||||
env:
|
env:
|
||||||
HUSKY: '0'
|
HUSKY: '0'
|
||||||
@@ -145,7 +126,6 @@ runs:
|
|||||||
id: playwright-version
|
id: playwright-version
|
||||||
if: ${{ inputs.playwright-install == 'true' }}
|
if: ${{ inputs.playwright-install == 'true' }}
|
||||||
shell: bash
|
shell: bash
|
||||||
working-directory: ${{ steps.workspace-path.outputs.workspace_path }}
|
|
||||||
run: echo "version=$(yarn why --json @playwright/test | grep -h 'workspace:.' | jq --raw-output '.children[].locator' | sed -e 's/@playwright\/test@.*://' | head -n 1)" >> $GITHUB_OUTPUT
|
run: echo "version=$(yarn why --json @playwright/test | grep -h 'workspace:.' | jq --raw-output '.children[].locator' | sed -e 's/@playwright\/test@.*://' | head -n 1)" >> $GITHUB_OUTPUT
|
||||||
|
|
||||||
# Attempt to restore the correct Playwright browser binaries based on the
|
# Attempt to restore the correct Playwright browser binaries based on the
|
||||||
@@ -158,8 +138,8 @@ runs:
|
|||||||
id: playwright-cache
|
id: playwright-cache
|
||||||
if: ${{ inputs.playwright-install == 'true' }}
|
if: ${{ inputs.playwright-install == 'true' }}
|
||||||
with:
|
with:
|
||||||
path: ${{ steps.workspace-path.outputs.workspace_path }}/node_modules/.cache/ms-playwright
|
path: ${{ github.workspace }}/node_modules/.cache/ms-playwright
|
||||||
key: '${{ runner.os }}-${{ runner.arch }}-${{ steps.system-info.outputs.name }}-${{ steps.system-info.outputs.release }}-${{ steps.system-info.outputs.version }}-playwright-${{ steps.playwright-version.outputs.version }}'
|
key: '${{ runner.os }}-playwright-${{ steps.playwright-version.outputs.version }}'
|
||||||
# As a fallback, if the Playwright version has changed, try use the
|
# As a fallback, if the Playwright version has changed, try use the
|
||||||
# most recently cached version. There's a good chance that at least one
|
# most recently cached version. There's a good chance that at least one
|
||||||
# of the browser binary versions haven't been updated, so Playwright can
|
# of the browser binary versions haven't been updated, so Playwright can
|
||||||
@@ -169,22 +149,20 @@ runs:
|
|||||||
# date cache, but still let Playwright decide if it needs to download
|
# date cache, but still let Playwright decide if it needs to download
|
||||||
# new binaries or not.
|
# new binaries or not.
|
||||||
restore-keys: |
|
restore-keys: |
|
||||||
${{ runner.os }}-${{ runner.arch }}-${{ steps.system-info.outputs.name }}-${{ steps.system-info.outputs.release }}-${{ steps.system-info.outputs.version }}-playwright-
|
${{ runner.os }}-playwright-
|
||||||
|
|
||||||
# If the Playwright browser binaries weren't able to be restored, we tell
|
# If the Playwright browser binaries weren't able to be restored, we tell
|
||||||
# playwright to install everything for us.
|
# playwright to install everything for us.
|
||||||
- name: Install Playwright's dependencies
|
- name: Install Playwright's dependencies
|
||||||
shell: bash
|
shell: bash
|
||||||
if: inputs.playwright-install == 'true'
|
if: inputs.playwright-install == 'true'
|
||||||
run: yarn playwright install --with-deps $(echo "${{ inputs.playwright-platform }}" | tr ',' ' ')
|
run: yarn playwright install --with-deps chromium
|
||||||
working-directory: ${{ steps.workspace-path.outputs.workspace_path }}
|
|
||||||
env:
|
env:
|
||||||
PLAYWRIGHT_BROWSERS_PATH: ${{ steps.workspace-path.outputs.workspace_path }}/node_modules/.cache/ms-playwright
|
PLAYWRIGHT_BROWSERS_PATH: ${{ github.workspace }}/node_modules/.cache/ms-playwright
|
||||||
|
|
||||||
- name: Get installed Electron version
|
- name: Get installed Electron version
|
||||||
id: electron-version
|
id: electron-version
|
||||||
if: ${{ inputs.electron-install == 'true' }}
|
if: ${{ inputs.electron-install == 'true' }}
|
||||||
working-directory: ${{ steps.workspace-path.outputs.workspace_path }}
|
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
echo "version=$(yarn why --json electron | grep -h 'workspace:.' | jq --raw-output '.children[].locator' | sed -e 's/@playwright\/test@.*://' | head -n 1)" >> $GITHUB_OUTPUT
|
echo "version=$(yarn why --json electron | grep -h 'workspace:.' | jq --raw-output '.children[].locator' | sed -e 's/@playwright\/test@.*://' | head -n 1)" >> $GITHUB_OUTPUT
|
||||||
@@ -193,20 +171,14 @@ runs:
|
|||||||
id: electron-cache
|
id: electron-cache
|
||||||
if: ${{ inputs.electron-install == 'true' }}
|
if: ${{ inputs.electron-install == 'true' }}
|
||||||
with:
|
with:
|
||||||
path: ${{ steps.workspace-path.outputs.workspace_path }}/node_modules/.cache/electron
|
path: 'node_modules/.cache/electron'
|
||||||
key: '${{ runner.os }}-${{ runner.arch }}-${{ steps.system-info.outputs.name }}-${{ steps.system-info.outputs.release }}-${{ steps.system-info.outputs.version }}-electron-${{ steps.electron-version.outputs.version }}'
|
key: '${{ runner.os }}-electron-${{ steps.electron-version.outputs.version }}'
|
||||||
restore-keys: |
|
restore-keys: |
|
||||||
${{ runner.os }}-${{ runner.arch }}-${{ steps.system-info.outputs.name }}-${{ steps.system-info.outputs.release }}-${{ steps.system-info.outputs.version }}-electron-
|
${{ runner.os }}-electron-
|
||||||
|
|
||||||
- name: Install Electron binary
|
- name: Install Electron binary
|
||||||
shell: bash
|
shell: bash
|
||||||
if: inputs.electron-install == 'true'
|
if: inputs.electron-install == 'true'
|
||||||
run: node ./node_modules/electron/install.js
|
run: node ./node_modules/electron/install.js
|
||||||
working-directory: ${{ steps.workspace-path.outputs.workspace_path }}
|
|
||||||
env:
|
env:
|
||||||
electron_config_cache: ${{ steps.workspace-path.outputs.workspace_path }}/node_modules/.cache/electron
|
electron_config_cache: ./node_modules/.cache/electron
|
||||||
|
|
||||||
- name: Write PLAYWRIGHT_BROWSERS_PATH env
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
echo "PLAYWRIGHT_BROWSERS_PATH=${{ steps.workspace-path.outputs.workspace_path }}/node_modules/.cache/ms-playwright" >> $GITHUB_ENV
|
|
||||||
|
|||||||
26
.github/actions/setup-version/action.yml
vendored
26
.github/actions/setup-version/action.yml
vendored
@@ -1,18 +1,24 @@
|
|||||||
name: Setup Version
|
name: Setup Version
|
||||||
description: 'Setup Version'
|
description: 'Setup Version'
|
||||||
inputs:
|
outputs:
|
||||||
app-version:
|
APP_VERSION:
|
||||||
description: 'App Version'
|
description: 'App Version'
|
||||||
required: true
|
value: ${{ steps.version.outputs.APP_VERSION }}
|
||||||
ios-app-version:
|
|
||||||
description: 'iOS App Store Version (Optional, use App version if empty)'
|
|
||||||
required: false
|
|
||||||
type: string
|
|
||||||
runs:
|
runs:
|
||||||
using: 'composite'
|
using: 'composite'
|
||||||
steps:
|
steps:
|
||||||
- name: 'Write Version'
|
- name: 'Write Version'
|
||||||
|
id: version
|
||||||
shell: bash
|
shell: bash
|
||||||
env:
|
run: |
|
||||||
IOS_APP_VERSION: ${{ inputs.ios-app-version }}
|
if [ "${{ github.ref_type }}" == "tag" ]; then
|
||||||
run: ./scripts/set-version.sh ${{ inputs.app-version }}
|
APP_VERSION=$(echo "${{ github.ref_name }}" | sed 's/^v//')
|
||||||
|
else
|
||||||
|
PACKAGE_VERSION=$(node -p "require('./package.json').version")
|
||||||
|
TIME_VERSION=$(date +%Y%m%d%H%M)
|
||||||
|
GIT_SHORT_HASH=$(git rev-parse --short HEAD)
|
||||||
|
APP_VERSION=$PACKAGE_VERSION-nightly-$TIME_VERSION-$GIT_SHORT_HASH
|
||||||
|
fi
|
||||||
|
echo $APP_VERSION
|
||||||
|
echo "APP_VERSION=$APP_VERSION" >> "$GITHUB_OUTPUT"
|
||||||
|
./scripts/set-version.sh $APP_VERSION
|
||||||
|
|||||||
11
.github/deployment/front/Dockerfile
vendored
Normal file
11
.github/deployment/front/Dockerfile
vendored
Normal file
@@ -0,0 +1,11 @@
|
|||||||
|
FROM openresty/openresty:1.21.4.3-0-buster
|
||||||
|
WORKDIR /app
|
||||||
|
COPY ./packages/frontend/core/dist ./dist
|
||||||
|
COPY ./.github/deployment/front/nginx.conf /usr/local/openresty/nginx/conf/nginx.conf
|
||||||
|
COPY ./.github/deployment/front/affine.nginx.conf /etc/nginx/conf.d/affine.nginx.conf
|
||||||
|
|
||||||
|
RUN mkdir -p /var/log/nginx && \
|
||||||
|
rm /etc/nginx/conf.d/default.conf
|
||||||
|
|
||||||
|
EXPOSE 8080
|
||||||
|
CMD ["/usr/local/openresty/bin/openresty", "-g", "daemon off;"]
|
||||||
13
.github/deployment/front/affine.nginx.conf
vendored
Normal file
13
.github/deployment/front/affine.nginx.conf
vendored
Normal file
@@ -0,0 +1,13 @@
|
|||||||
|
server {
|
||||||
|
listen 8080;
|
||||||
|
root /app/dist;
|
||||||
|
|
||||||
|
location / {
|
||||||
|
try_files $uri $uri/ /index.html;
|
||||||
|
}
|
||||||
|
|
||||||
|
error_page 404 /404.html;
|
||||||
|
location = /404.html {
|
||||||
|
internal;
|
||||||
|
}
|
||||||
|
}
|
||||||
14
.github/deployment/front/nginx.conf
vendored
Normal file
14
.github/deployment/front/nginx.conf
vendored
Normal file
@@ -0,0 +1,14 @@
|
|||||||
|
worker_processes 4;
|
||||||
|
error_log /var/log/nginx/error.log warn;
|
||||||
|
pcre_jit on;
|
||||||
|
events {
|
||||||
|
worker_connections 1024;
|
||||||
|
}
|
||||||
|
http {
|
||||||
|
include mime.types;
|
||||||
|
log_format main '$remote_addr [$time_local] "$request" '
|
||||||
|
'$status $body_bytes_sent "$http_referer" '
|
||||||
|
'"$http_user_agent" "$http_x_forwarded_for"';
|
||||||
|
access_log /var/log/nginx/access.log main;
|
||||||
|
include /etc/nginx/conf.d/*.conf;
|
||||||
|
}
|
||||||
32
.github/deployment/node/Dockerfile
vendored
32
.github/deployment/node/Dockerfile
vendored
@@ -1,35 +1,11 @@
|
|||||||
# syntax=docker/dockerfile:1.7
|
FROM node:18-bookworm-slim
|
||||||
|
|
||||||
FROM node:22-bookworm-slim AS assets
|
|
||||||
WORKDIR /app
|
|
||||||
|
|
||||||
COPY ./packages/backend/server /app
|
COPY ./packages/backend/server /app
|
||||||
COPY ./packages/frontend/apps/web/dist /app/static
|
COPY ./packages/frontend/core/dist /app/static
|
||||||
COPY ./packages/frontend/admin/dist /app/static/admin
|
|
||||||
COPY ./packages/frontend/apps/mobile/dist /app/static/mobile
|
|
||||||
|
|
||||||
# Keep server sourcemap for stacktraces, but don't ship frontend/node_modules sourcemaps.
|
|
||||||
ARG TARGETARCH
|
|
||||||
ARG TARGETVARIANT
|
|
||||||
# Needed for Prisma engine resolution (and potential engine download during cleanup).
|
|
||||||
RUN apt-get update && \
|
|
||||||
apt-get install -y --no-install-recommends openssl ca-certificates && \
|
|
||||||
rm -rf /var/lib/apt/lists/*
|
|
||||||
|
|
||||||
RUN AFFINE_DOCKER_CLEAN=1 TARGETARCH="${TARGETARCH}" TARGETVARIANT="${TARGETVARIANT}" node ./scripts/docker-clean.mjs
|
|
||||||
|
|
||||||
FROM node:22-bookworm-slim
|
|
||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
|
|
||||||
COPY --from=assets /app /app
|
|
||||||
|
|
||||||
RUN apt-get update && \
|
RUN apt-get update && \
|
||||||
apt-get install -y --no-install-recommends openssl libjemalloc2 && \
|
apt-get install -y --no-install-recommends openssl && \
|
||||||
rm -rf /var/lib/apt/lists/*
|
rm -rf /var/lib/apt/lists/*
|
||||||
|
|
||||||
# Enable jemalloc by preloading the library
|
CMD ["node", "--es-module-specifier-resolution=node", "./dist/index.js"]
|
||||||
ENV LD_PRELOAD=libjemalloc.so.2
|
|
||||||
|
|
||||||
EXPOSE 3010
|
|
||||||
|
|
||||||
CMD ["node", "./dist/main.js"]
|
|
||||||
|
|||||||
61
.github/deployment/self-host/compose.yaml
vendored
Normal file
61
.github/deployment/self-host/compose.yaml
vendored
Normal file
@@ -0,0 +1,61 @@
|
|||||||
|
services:
|
||||||
|
affine:
|
||||||
|
image: ghcr.io/toeverything/affine-graphql:beta
|
||||||
|
container_name: affine_selfhosted
|
||||||
|
command:
|
||||||
|
['sh', '-c', 'node ./scripts/self-host-predeploy && node ./dist/index.js']
|
||||||
|
ports:
|
||||||
|
- '3010:3010'
|
||||||
|
- '5555:5555'
|
||||||
|
depends_on:
|
||||||
|
redis:
|
||||||
|
condition: service_healthy
|
||||||
|
postgres:
|
||||||
|
condition: service_healthy
|
||||||
|
volumes:
|
||||||
|
# custom configurations
|
||||||
|
- ~/.affine/self-host/config:/root/.affine/config
|
||||||
|
# blob storage
|
||||||
|
- ~/.affine/self-host/storage:/root/.affine/storage
|
||||||
|
logging:
|
||||||
|
driver: 'json-file'
|
||||||
|
options:
|
||||||
|
max-size: '1000m'
|
||||||
|
restart: unless-stopped
|
||||||
|
environment:
|
||||||
|
- NODE_OPTIONS=--es-module-specifier-resolution node
|
||||||
|
- AFFINE_CONFIG_PATH=/root/.affine/config
|
||||||
|
- REDIS_SERVER_HOST=redis
|
||||||
|
- DATABASE_URL=postgres://affine:affine@postgres:5432/affine
|
||||||
|
- DISABLE_TELEMETRY=true
|
||||||
|
- NODE_ENV=production
|
||||||
|
- SERVER_FLAVOR=selfhosted
|
||||||
|
- AFFINE_ADMIN_EMAIL=${AFFINE_ADMIN_EMAIL}
|
||||||
|
- AFFINE_ADMIN_PASSWORD=${AFFINE_ADMIN_PASSWORD}
|
||||||
|
redis:
|
||||||
|
image: redis
|
||||||
|
container_name: affine_redis
|
||||||
|
restart: unless-stopped
|
||||||
|
volumes:
|
||||||
|
- ~/.affine/self-host/redis:/data
|
||||||
|
healthcheck:
|
||||||
|
test: ['CMD', 'redis-cli', '--raw', 'incr', 'ping']
|
||||||
|
interval: 10s
|
||||||
|
timeout: 5s
|
||||||
|
retries: 5
|
||||||
|
postgres:
|
||||||
|
image: postgres
|
||||||
|
container_name: affine_postgres
|
||||||
|
restart: unless-stopped
|
||||||
|
volumes:
|
||||||
|
- ~/.affine/self-host/postgres:/var/lib/postgresql/data
|
||||||
|
healthcheck:
|
||||||
|
test: ['CMD-SHELL', 'pg_isready -U affine']
|
||||||
|
interval: 10s
|
||||||
|
timeout: 5s
|
||||||
|
retries: 5
|
||||||
|
environment:
|
||||||
|
POSTGRES_USER: affine
|
||||||
|
POSTGRES_PASSWORD: affine
|
||||||
|
POSTGRES_DB: affine
|
||||||
|
PGDATA: /var/lib/postgresql/data/pgdata
|
||||||
2
.github/helm/affine/Chart.yaml
vendored
2
.github/helm/affine/Chart.yaml
vendored
@@ -3,4 +3,4 @@ name: affine
|
|||||||
description: AFFiNE cloud chart
|
description: AFFiNE cloud chart
|
||||||
type: application
|
type: application
|
||||||
version: 0.0.0
|
version: 0.0.0
|
||||||
appVersion: "0.26.1"
|
appVersion: "0.12.0"
|
||||||
|
|||||||
11
.github/helm/affine/charts/doc/Chart.yaml
vendored
11
.github/helm/affine/charts/doc/Chart.yaml
vendored
@@ -1,11 +0,0 @@
|
|||||||
apiVersion: v2
|
|
||||||
name: doc
|
|
||||||
description: AFFiNE doc server
|
|
||||||
type: application
|
|
||||||
version: 0.0.0
|
|
||||||
appVersion: "0.26.1"
|
|
||||||
dependencies:
|
|
||||||
- name: gcloud-sql-proxy
|
|
||||||
version: 0.0.0
|
|
||||||
repository: "file://../gcloud-sql-proxy"
|
|
||||||
condition: .global.database.gcloud.enabled
|
|
||||||
@@ -1,16 +0,0 @@
|
|||||||
1. Get the application URL by running these commands:
|
|
||||||
{{- if contains "NodePort" .Values.service.type }}
|
|
||||||
export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "doc.fullname" . }})
|
|
||||||
export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}")
|
|
||||||
echo http://$NODE_IP:$NODE_PORT
|
|
||||||
{{- else if contains "LoadBalancer" .Values.service.type }}
|
|
||||||
NOTE: It may take a few minutes for the LoadBalancer IP to be available.
|
|
||||||
You can watch the status of by running 'kubectl get --namespace {{ .Release.Namespace }} svc -w {{ include "doc.fullname" . }}'
|
|
||||||
export SERVICE_IP=$(kubectl get svc --namespace {{ .Release.Namespace }} {{ include "doc.fullname" . }} --template "{{"{{ range (index .status.loadBalancer.ingress 0) }}{{.}}{{ end }}"}}")
|
|
||||||
echo http://$SERVICE_IP:{{ .Values.service.port }}
|
|
||||||
{{- else if contains "ClusterIP" .Values.service.type }}
|
|
||||||
export POD_NAME=$(kubectl get pods --namespace {{ .Release.Namespace }} -l "app.kubernetes.io/name={{ include "doc.name" . }},app.kubernetes.io/instance={{ .Release.Name }}" -o jsonpath="{.items[0].metadata.name}")
|
|
||||||
export CONTAINER_PORT=$(kubectl get pod --namespace {{ .Release.Namespace }} $POD_NAME -o jsonpath="{.spec.containers[0].ports[0].containerPort}")
|
|
||||||
echo "Visit http://127.0.0.1:8080 to use your application"
|
|
||||||
kubectl --namespace {{ .Release.Namespace }} port-forward $POD_NAME 8080:$CONTAINER_PORT
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,63 +0,0 @@
|
|||||||
{{/*
|
|
||||||
Expand the name of the chart.
|
|
||||||
*/}}
|
|
||||||
{{- define "doc.name" -}}
|
|
||||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create a default fully qualified app name.
|
|
||||||
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
|
||||||
If release name contains chart name it will be used as a full name.
|
|
||||||
*/}}
|
|
||||||
{{- define "doc.fullname" -}}
|
|
||||||
{{- if .Values.fullnameOverride }}
|
|
||||||
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
|
||||||
{{- else }}
|
|
||||||
{{- $name := default .Chart.Name .Values.nameOverride }}
|
|
||||||
{{- if contains $name .Release.Name }}
|
|
||||||
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
|
|
||||||
{{- else }}
|
|
||||||
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create chart name and version as used by the chart label.
|
|
||||||
*/}}
|
|
||||||
{{- define "doc.chart" -}}
|
|
||||||
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Common labels
|
|
||||||
*/}}
|
|
||||||
{{- define "doc.labels" -}}
|
|
||||||
helm.sh/chart: {{ include "doc.chart" . }}
|
|
||||||
{{ include "doc.selectorLabels" . }}
|
|
||||||
{{- if .Chart.AppVersion }}
|
|
||||||
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
|
||||||
{{- end }}
|
|
||||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
||||||
monitoring: enabled
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Selector labels
|
|
||||||
*/}}
|
|
||||||
{{- define "doc.selectorLabels" -}}
|
|
||||||
app.kubernetes.io/name: {{ include "doc.name" . }}
|
|
||||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the name of the service account to use
|
|
||||||
*/}}
|
|
||||||
{{- define "doc.serviceAccountName" -}}
|
|
||||||
{{- if .Values.serviceAccount.create }}
|
|
||||||
{{- default (include "doc.fullname" .) .Values.global.docService.name }}
|
|
||||||
{{- else }}
|
|
||||||
{{- default "default" .Values.global.docService.name }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,118 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: {{ include "doc.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "doc.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
replicas: {{ .Values.replicaCount }}
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
{{- include "doc.selectorLabels" . | nindent 6 }}
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
{{- with .Values.podAnnotations }}
|
|
||||||
annotations:
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
labels:
|
|
||||||
{{- include "doc.selectorLabels" . | nindent 8 }}
|
|
||||||
spec:
|
|
||||||
{{- with .Values.imagePullSecrets }}
|
|
||||||
imagePullSecrets:
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
serviceAccountName: {{ include "doc.serviceAccountName" . }}
|
|
||||||
containers:
|
|
||||||
- name: {{ .Chart.Name }}
|
|
||||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
|
|
||||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
|
||||||
env:
|
|
||||||
- name: AFFINE_PRIVATE_KEY
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: "{{ .Values.global.secret.secretName }}"
|
|
||||||
key: key
|
|
||||||
- name: NODE_ENV
|
|
||||||
value: "{{ .Values.env }}"
|
|
||||||
- name: NODE_OPTIONS
|
|
||||||
value: "--max-old-space-size=4096"
|
|
||||||
- name: NO_COLOR
|
|
||||||
value: "1"
|
|
||||||
- name: DEPLOYMENT_TYPE
|
|
||||||
value: "{{ .Values.global.deployment.type }}"
|
|
||||||
- name: DEPLOYMENT_PLATFORM
|
|
||||||
value: "{{ .Values.global.deployment.platform }}"
|
|
||||||
- name: SERVER_FLAVOR
|
|
||||||
value: "doc"
|
|
||||||
- name: AFFINE_ENV
|
|
||||||
value: "{{ .Release.Namespace }}"
|
|
||||||
- name: DATABASE_PASSWORD
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: pg-postgresql
|
|
||||||
key: postgres-password
|
|
||||||
- name: DATABASE_URL
|
|
||||||
value: postgres://{{ .Values.global.database.user }}:$(DATABASE_PASSWORD)@{{ .Values.global.database.host }}:{{ .Values.global.database.port }}/{{ .Values.global.database.name }}
|
|
||||||
- name: REDIS_SERVER_ENABLED
|
|
||||||
value: "true"
|
|
||||||
- name: REDIS_SERVER_HOST
|
|
||||||
value: "{{ .Values.global.redis.host }}"
|
|
||||||
- name: REDIS_SERVER_PORT
|
|
||||||
value: "{{ .Values.global.redis.port }}"
|
|
||||||
- name: REDIS_SERVER_USER
|
|
||||||
value: "{{ .Values.global.redis.username }}"
|
|
||||||
- name: REDIS_SERVER_PASSWORD
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: redis
|
|
||||||
key: redis-password
|
|
||||||
- name: REDIS_SERVER_DATABASE
|
|
||||||
value: "{{ .Values.global.redis.database }}"
|
|
||||||
- name: AFFINE_INDEXER_SEARCH_PROVIDER
|
|
||||||
value: "{{ .Values.global.indexer.provider }}"
|
|
||||||
- name: AFFINE_INDEXER_SEARCH_ENDPOINT
|
|
||||||
value: "{{ .Values.global.indexer.endpoint }}"
|
|
||||||
- name: AFFINE_INDEXER_SEARCH_API_KEY
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: indexer
|
|
||||||
key: indexer-apiKey
|
|
||||||
- name: AFFINE_SERVER_PORT
|
|
||||||
value: "{{ .Values.global.docService.port }}"
|
|
||||||
- name: AFFINE_SERVER_SUB_PATH
|
|
||||||
value: "{{ .Values.app.path }}"
|
|
||||||
- name: AFFINE_SERVER_HOST
|
|
||||||
value: "{{ .Values.app.host }}"
|
|
||||||
- name: AFFINE_SERVER_HTTPS
|
|
||||||
value: "{{ .Values.app.https }}"
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
containerPort: {{ .Values.global.docService.port }}
|
|
||||||
protocol: TCP
|
|
||||||
livenessProbe:
|
|
||||||
httpGet:
|
|
||||||
path: /info
|
|
||||||
port: http
|
|
||||||
initialDelaySeconds: {{ .Values.probe.initialDelaySeconds }}
|
|
||||||
timeoutSeconds: {{ .Values.probe.timeoutSeconds }}
|
|
||||||
readinessProbe:
|
|
||||||
httpGet:
|
|
||||||
path: /info
|
|
||||||
port: http
|
|
||||||
initialDelaySeconds: {{ .Values.probe.initialDelaySeconds }}
|
|
||||||
timeoutSeconds: {{ .Values.probe.timeoutSeconds }}
|
|
||||||
resources:
|
|
||||||
{{- toYaml .Values.resources | nindent 12 }}
|
|
||||||
{{- with .Values.nodeSelector }}
|
|
||||||
nodeSelector:
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- with .Values.affinity }}
|
|
||||||
affinity:
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- with .Values.tolerations }}
|
|
||||||
tolerations:
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: {{ include "doc.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "doc.labels" . | nindent 4 }}
|
|
||||||
{{- with .Values.service.annotations }}
|
|
||||||
annotations:
|
|
||||||
{{- toYaml . | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
|
||||||
type: {{ .Values.service.type }}
|
|
||||||
ports:
|
|
||||||
- port: {{ .Values.global.docService.port }}
|
|
||||||
targetPort: http
|
|
||||||
protocol: TCP
|
|
||||||
name: http
|
|
||||||
selector:
|
|
||||||
{{- include "doc.selectorLabels" . | nindent 4 }}
|
|
||||||
@@ -1,12 +0,0 @@
|
|||||||
{{- if .Values.serviceAccount.create -}}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: {{ include "doc.serviceAccountName" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "doc.labels" . | nindent 4 }}
|
|
||||||
{{- with .Values.serviceAccount.annotations }}
|
|
||||||
annotations:
|
|
||||||
{{- toYaml . | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Pod
|
|
||||||
metadata:
|
|
||||||
name: "{{ include "doc.fullname" . }}-test-connection"
|
|
||||||
labels:
|
|
||||||
{{- include "doc.labels" . | nindent 4 }}
|
|
||||||
annotations:
|
|
||||||
"helm.sh/hook": test
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: wget
|
|
||||||
image: busybox
|
|
||||||
command: ['wget']
|
|
||||||
args: ['{{ include "doc.fullname" . }}:{{ .Values.global.docService.port }}']
|
|
||||||
restartPolicy: Never
|
|
||||||
46
.github/helm/affine/charts/doc/values.yaml
vendored
46
.github/helm/affine/charts/doc/values.yaml
vendored
@@ -1,46 +0,0 @@
|
|||||||
replicaCount: 1
|
|
||||||
image:
|
|
||||||
repository: ghcr.io/toeverything/affine
|
|
||||||
pullPolicy: IfNotPresent
|
|
||||||
tag: ''
|
|
||||||
|
|
||||||
imagePullSecrets: []
|
|
||||||
nameOverride: ''
|
|
||||||
fullnameOverride: ''
|
|
||||||
# map to NODE_ENV environment variable
|
|
||||||
env: 'production'
|
|
||||||
app:
|
|
||||||
# AFFINE_SERVER_SUB_PATH
|
|
||||||
path: ''
|
|
||||||
# AFFINE_SERVER_HOST
|
|
||||||
host: '0.0.0.0'
|
|
||||||
https: true
|
|
||||||
copilot:
|
|
||||||
enabled: false
|
|
||||||
secretName: copilot
|
|
||||||
openai:
|
|
||||||
key: ''
|
|
||||||
serviceAccount:
|
|
||||||
create: true
|
|
||||||
annotations: {}
|
|
||||||
|
|
||||||
podAnnotations: {}
|
|
||||||
|
|
||||||
podSecurityContext:
|
|
||||||
fsGroup: 2000
|
|
||||||
|
|
||||||
resources:
|
|
||||||
limits:
|
|
||||||
cpu: '1'
|
|
||||||
memory: 4Gi
|
|
||||||
requests:
|
|
||||||
cpu: '1'
|
|
||||||
memory: 2Gi
|
|
||||||
|
|
||||||
probe:
|
|
||||||
initialDelaySeconds: 20
|
|
||||||
timeoutSeconds: 5
|
|
||||||
|
|
||||||
nodeSelector: {}
|
|
||||||
tolerations: []
|
|
||||||
affinity: {}
|
|
||||||
11
.github/helm/affine/charts/front/Chart.yaml
vendored
11
.github/helm/affine/charts/front/Chart.yaml
vendored
@@ -1,11 +0,0 @@
|
|||||||
apiVersion: v2
|
|
||||||
name: front
|
|
||||||
description: AFFiNE front server
|
|
||||||
type: application
|
|
||||||
version: 0.0.0
|
|
||||||
appVersion: "0.26.1"
|
|
||||||
dependencies:
|
|
||||||
- name: gcloud-sql-proxy
|
|
||||||
version: 0.0.0
|
|
||||||
repository: "file://../gcloud-sql-proxy"
|
|
||||||
condition: .global.database.gcloud.enabled
|
|
||||||
@@ -1,16 +0,0 @@
|
|||||||
1. Get the application URL by running these commands:
|
|
||||||
{{- if contains "NodePort" .Values.services.sync.type }}
|
|
||||||
export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ .Values.services.sync.name }})
|
|
||||||
export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}")
|
|
||||||
echo http://$NODE_IP:$NODE_PORT
|
|
||||||
{{- else if contains "LoadBalancer" .Values.services.sync.type }}
|
|
||||||
NOTE: It may take a few minutes for the LoadBalancer IP to be available.
|
|
||||||
You can watch the status of by running 'kubectl get --namespace {{ .Release.Namespace }} svc -w {{ .Values.services.sync.name }}'
|
|
||||||
export SERVICE_IP=$(kubectl get svc --namespace {{ .Release.Namespace }} {{ .Values.services.sync.name }} --template "{{"{{ range (index .status.loadBalancer.ingress 0) }}{{.}}{{ end }}"}}")
|
|
||||||
echo http://$SERVICE_IP:{{ .Values.services.sync.port }}
|
|
||||||
{{- else if contains "ClusterIP" .Values.services.sync.type }}
|
|
||||||
export POD_NAME=$(kubectl get pods --namespace {{ .Release.Namespace }} -l "app.kubernetes.io/name={{ include "front.name" . }},app.kubernetes.io/instance={{ .Release.Name }}" -o jsonpath="{.items[0].metadata.name}")
|
|
||||||
export CONTAINER_PORT=$(kubectl get pod --namespace {{ .Release.Namespace }} $POD_NAME -o jsonpath="{.spec.containers[0].ports[0].containerPort}")
|
|
||||||
echo "Visit http://127.0.0.1:8080 to use your application"
|
|
||||||
kubectl --namespace {{ .Release.Namespace }} port-forward $POD_NAME 8080:$CONTAINER_PORT
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,63 +0,0 @@
|
|||||||
{{/*
|
|
||||||
Expand the name of the chart.
|
|
||||||
*/}}
|
|
||||||
{{- define "front.name" -}}
|
|
||||||
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create a default fully qualified app name.
|
|
||||||
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
|
||||||
If release name contains chart name it will be used as a full name.
|
|
||||||
*/}}
|
|
||||||
{{- define "front.fullname" -}}
|
|
||||||
{{- if .Values.fullnameOverride }}
|
|
||||||
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
|
||||||
{{- else }}
|
|
||||||
{{- $name := default .Chart.Name .Values.nameOverride }}
|
|
||||||
{{- if contains $name .Release.Name }}
|
|
||||||
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
|
|
||||||
{{- else }}
|
|
||||||
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create chart name and version as used by the chart label.
|
|
||||||
*/}}
|
|
||||||
{{- define "front.chart" -}}
|
|
||||||
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Common labels
|
|
||||||
*/}}
|
|
||||||
{{- define "front.labels" -}}
|
|
||||||
helm.sh/chart: {{ include "front.chart" . }}
|
|
||||||
{{ include "front.selectorLabels" . }}
|
|
||||||
{{- if .Chart.AppVersion }}
|
|
||||||
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
|
||||||
{{- end }}
|
|
||||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
||||||
monitoring: enabled
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Selector labels
|
|
||||||
*/}}
|
|
||||||
{{- define "front.selectorLabels" -}}
|
|
||||||
app.kubernetes.io/name: {{ include "front.name" . }}
|
|
||||||
app.kubernetes.io/instance: {{ .Release.Name }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the name of the service account to use
|
|
||||||
*/}}
|
|
||||||
{{- define "front.serviceAccountName" -}}
|
|
||||||
{{- if .Values.serviceAccount.create }}
|
|
||||||
{{- default (include "front.fullname" .) .Values.serviceAccount.name }}
|
|
||||||
{{- else }}
|
|
||||||
{{- default "default" .Values.serviceAccount.name }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,120 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: {{ include "front.fullname" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "front.labels" . | nindent 4 }}
|
|
||||||
spec:
|
|
||||||
replicas: {{ .Values.replicaCount }}
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
{{- include "front.selectorLabels" . | nindent 6 }}
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
{{- with .Values.podAnnotations }}
|
|
||||||
annotations:
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
labels:
|
|
||||||
{{- include "front.selectorLabels" . | nindent 8 }}
|
|
||||||
spec:
|
|
||||||
{{- with .Values.imagePullSecrets }}
|
|
||||||
imagePullSecrets:
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
serviceAccountName: {{ include "front.serviceAccountName" . }}
|
|
||||||
securityContext:
|
|
||||||
{{- toYaml .Values.podSecurityContext | nindent 8 }}
|
|
||||||
containers:
|
|
||||||
- name: {{ .Chart.Name }}
|
|
||||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
|
|
||||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
|
||||||
env:
|
|
||||||
- name: AFFINE_PRIVATE_KEY
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: "{{ .Values.global.secret.secretName }}"
|
|
||||||
key: key
|
|
||||||
- name: NODE_ENV
|
|
||||||
value: "{{ .Values.env }}"
|
|
||||||
- name: NODE_OPTIONS
|
|
||||||
value: "{{ .Values.nodeOptions }}"
|
|
||||||
- name: NO_COLOR
|
|
||||||
value: "1"
|
|
||||||
- name: DEPLOYMENT_TYPE
|
|
||||||
value: "{{ .Values.global.deployment.type }}"
|
|
||||||
- name: DEPLOYMENT_PLATFORM
|
|
||||||
value: "{{ .Values.global.deployment.platform }}"
|
|
||||||
- name: SERVER_FLAVOR
|
|
||||||
value: "front"
|
|
||||||
- name: AFFINE_ENV
|
|
||||||
value: "{{ .Release.Namespace }}"
|
|
||||||
- name: DATABASE_PASSWORD
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: pg-postgresql
|
|
||||||
key: postgres-password
|
|
||||||
- name: DATABASE_URL
|
|
||||||
value: postgres://{{ .Values.global.database.user }}:$(DATABASE_PASSWORD)@{{ .Values.global.database.host }}:{{ .Values.global.database.port }}/{{ .Values.global.database.name }}
|
|
||||||
- name: REDIS_SERVER_ENABLED
|
|
||||||
value: "true"
|
|
||||||
- name: REDIS_SERVER_HOST
|
|
||||||
value: "{{ .Values.global.redis.host }}"
|
|
||||||
- name: REDIS_SERVER_PORT
|
|
||||||
value: "{{ .Values.global.redis.port }}"
|
|
||||||
- name: REDIS_SERVER_USER
|
|
||||||
value: "{{ .Values.global.redis.username }}"
|
|
||||||
- name: REDIS_SERVER_PASSWORD
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: redis
|
|
||||||
key: redis-password
|
|
||||||
- name: REDIS_SERVER_DATABASE
|
|
||||||
value: "{{ .Values.global.redis.database }}"
|
|
||||||
- name: AFFINE_INDEXER_SEARCH_PROVIDER
|
|
||||||
value: "{{ .Values.global.indexer.provider }}"
|
|
||||||
- name: AFFINE_INDEXER_SEARCH_ENDPOINT
|
|
||||||
value: "{{ .Values.global.indexer.endpoint }}"
|
|
||||||
- name: AFFINE_INDEXER_SEARCH_API_KEY
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: indexer
|
|
||||||
key: indexer-apiKey
|
|
||||||
- name: AFFINE_SERVER_PORT
|
|
||||||
value: "{{ .Values.app.port }}"
|
|
||||||
- name: AFFINE_SERVER_SUB_PATH
|
|
||||||
value: "{{ .Values.app.path }}"
|
|
||||||
- name: AFFINE_SERVER_HOST
|
|
||||||
value: "{{ .Values.app.host }}"
|
|
||||||
- name: AFFINE_SERVER_HTTPS
|
|
||||||
value: "{{ .Values.app.https }}"
|
|
||||||
- name: DOC_SERVICE_ENDPOINT
|
|
||||||
value: "http://{{ .Values.global.docService.name }}:{{ .Values.global.docService.port }}"
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
containerPort: {{ .Values.app.port }}
|
|
||||||
protocol: TCP
|
|
||||||
livenessProbe:
|
|
||||||
httpGet:
|
|
||||||
path: /info
|
|
||||||
port: http
|
|
||||||
initialDelaySeconds: {{ .Values.probe.initialDelaySeconds }}
|
|
||||||
readinessProbe:
|
|
||||||
httpGet:
|
|
||||||
path: /info
|
|
||||||
port: http
|
|
||||||
initialDelaySeconds: {{ .Values.probe.initialDelaySeconds }}
|
|
||||||
resources:
|
|
||||||
{{- toYaml .Values.resources | nindent 12 }}
|
|
||||||
{{- with .Values.nodeSelector }}
|
|
||||||
nodeSelector:
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- with .Values.affinity }}
|
|
||||||
affinity:
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- with .Values.tolerations }}
|
|
||||||
tolerations:
|
|
||||||
{{- toYaml . | nindent 8 }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: {{ .Values.services.renderer.name }}
|
|
||||||
labels:
|
|
||||||
{{- include "front.labels" . | nindent 4 }}
|
|
||||||
{{- with .Values.services.renderer.annotations }}
|
|
||||||
annotations:
|
|
||||||
{{- toYaml . | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
|
||||||
type: {{ .Values.services.renderer.type }}
|
|
||||||
ports:
|
|
||||||
- port: {{ .Values.services.renderer.port }}
|
|
||||||
targetPort: http
|
|
||||||
protocol: TCP
|
|
||||||
name: http
|
|
||||||
selector:
|
|
||||||
{{- include "front.selectorLabels" . | nindent 4 }}
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: {{ .Values.services.sync.name }}
|
|
||||||
labels:
|
|
||||||
{{- include "front.labels" . | nindent 4 }}
|
|
||||||
{{- with .Values.services.sync.annotations }}
|
|
||||||
annotations:
|
|
||||||
{{- toYaml . | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
|
||||||
type: {{ .Values.services.sync.type }}
|
|
||||||
ports:
|
|
||||||
- port: {{ .Values.services.sync.port }}
|
|
||||||
targetPort: http
|
|
||||||
protocol: TCP
|
|
||||||
name: http
|
|
||||||
selector:
|
|
||||||
{{- include "front.selectorLabels" . | nindent 4 }}
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: {{ .Values.services.web.name }}
|
|
||||||
labels:
|
|
||||||
{{- include "front.labels" . | nindent 4 }}
|
|
||||||
{{- with .Values.services.web.annotations }}
|
|
||||||
annotations:
|
|
||||||
{{- toYaml . | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
|
||||||
type: {{ .Values.services.web.type }}
|
|
||||||
ports:
|
|
||||||
- port: {{ .Values.services.web.port }}
|
|
||||||
targetPort: http
|
|
||||||
protocol: TCP
|
|
||||||
name: http
|
|
||||||
selector:
|
|
||||||
{{- include "front.selectorLabels" . | nindent 4 }}
|
|
||||||
@@ -1,12 +0,0 @@
|
|||||||
{{- if .Values.serviceAccount.create -}}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: {{ include "front.serviceAccountName" . }}
|
|
||||||
labels:
|
|
||||||
{{- include "front.labels" . | nindent 4 }}
|
|
||||||
{{- with .Values.serviceAccount.annotations }}
|
|
||||||
annotations:
|
|
||||||
{{- toYaml . | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Pod
|
|
||||||
metadata:
|
|
||||||
name: "{{ include "front.fullname" . }}-test-connection"
|
|
||||||
labels:
|
|
||||||
{{- include "front.labels" . | nindent 4 }}
|
|
||||||
annotations:
|
|
||||||
"helm.sh/hook": test
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: wget
|
|
||||||
image: busybox
|
|
||||||
command: ['wget']
|
|
||||||
args: ['{{ .Values.services.sync.name }}:{{ .Values.services.sync.port }}']
|
|
||||||
restartPolicy: Never
|
|
||||||
63
.github/helm/affine/charts/front/values.yaml
vendored
63
.github/helm/affine/charts/front/values.yaml
vendored
@@ -1,63 +0,0 @@
|
|||||||
replicaCount: 1
|
|
||||||
image:
|
|
||||||
repository: ghcr.io/toeverything/affine
|
|
||||||
pullPolicy: IfNotPresent
|
|
||||||
tag: ''
|
|
||||||
|
|
||||||
imagePullSecrets: []
|
|
||||||
nameOverride: ''
|
|
||||||
fullnameOverride: ''
|
|
||||||
# map to NODE_ENV environment variable
|
|
||||||
env: 'production'
|
|
||||||
nodeOptions: '--max-old-space-size=3072'
|
|
||||||
app:
|
|
||||||
# AFFINE_SERVER_PORT
|
|
||||||
port: 3010
|
|
||||||
# AFFINE_SERVER_SUB_PATH
|
|
||||||
path: ''
|
|
||||||
# AFFINE_SERVER_HOST
|
|
||||||
host: '0.0.0.0'
|
|
||||||
https: true
|
|
||||||
serviceAccount:
|
|
||||||
create: true
|
|
||||||
annotations: {}
|
|
||||||
name: 'affine-front'
|
|
||||||
|
|
||||||
podAnnotations: {}
|
|
||||||
|
|
||||||
podSecurityContext:
|
|
||||||
fsGroup: 2000
|
|
||||||
|
|
||||||
resources:
|
|
||||||
limits:
|
|
||||||
cpu: '1'
|
|
||||||
memory: 2Gi
|
|
||||||
requests:
|
|
||||||
cpu: '1'
|
|
||||||
memory: 2Gi
|
|
||||||
|
|
||||||
probe:
|
|
||||||
initialDelaySeconds: 20
|
|
||||||
|
|
||||||
services:
|
|
||||||
sync:
|
|
||||||
name: affine-sync
|
|
||||||
type: ClusterIP
|
|
||||||
port: 3010
|
|
||||||
annotations:
|
|
||||||
cloud.google.com/backend-config: '{"default": "affine-api-backendconfig"}'
|
|
||||||
renderer:
|
|
||||||
name: affine-renderer
|
|
||||||
type: ClusterIP
|
|
||||||
port: 3000
|
|
||||||
annotations:
|
|
||||||
cloud.google.com/backend-config: '{"default": "affine-api-backendconfig"}'
|
|
||||||
web:
|
|
||||||
name: affine-web
|
|
||||||
type: ClusterIP
|
|
||||||
port: 8080
|
|
||||||
annotations: {}
|
|
||||||
|
|
||||||
nodeSelector: {}
|
|
||||||
tolerations: []
|
|
||||||
affinity: {}
|
|
||||||
@@ -1,4 +1,4 @@
|
|||||||
{{- if .Values.enabled -}}
|
{{- if .Values.global.database.gcloud.enabled -}}
|
||||||
1. Get the application URL by running these commands:
|
1. Get the application URL by running these commands:
|
||||||
{{- if contains "NodePort" .Values.service.type }}
|
{{- if contains "NodePort" .Values.service.type }}
|
||||||
export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "gcloud-sql-proxy.fullname" . }})
|
export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "gcloud-sql-proxy.fullname" . }})
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
{{- if .Values.enabled -}}
|
{{- if .Values.global.database.gcloud.enabled -}}
|
||||||
apiVersion: apps/v1
|
apiVersion: apps/v1
|
||||||
kind: Deployment
|
kind: Deployment
|
||||||
metadata:
|
metadata:
|
||||||
@@ -42,7 +42,7 @@ spec:
|
|||||||
- "0.0.0.0"
|
- "0.0.0.0"
|
||||||
- "--structured-logs"
|
- "--structured-logs"
|
||||||
- "--auto-iam-authn"
|
- "--auto-iam-authn"
|
||||||
- "{{ .Values.database.connectionName }}"
|
- "{{ .Values.global.database.gcloud.connectionName }}"
|
||||||
env:
|
env:
|
||||||
# Enable HTTP healthchecks on port 9801. This enables /liveness,
|
# Enable HTTP healthchecks on port 9801. This enables /liveness,
|
||||||
# /readiness and /startup health check endpoints. Allow connections
|
# /readiness and /startup health check endpoints. Allow connections
|
||||||
@@ -56,7 +56,7 @@ spec:
|
|||||||
value: 0.0.0.0
|
value: 0.0.0.0
|
||||||
ports:
|
ports:
|
||||||
- name: cloud-sql-proxy
|
- name: cloud-sql-proxy
|
||||||
containerPort: {{ .Values.service.port }}
|
containerPort: {{ .Values.global.database.gcloud.proxyPort }}
|
||||||
protocol: TCP
|
protocol: TCP
|
||||||
- containerPort: 9801
|
- containerPort: 9801
|
||||||
protocol: TCP
|
protocol: TCP
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
{{- if .Values.enabled -}}
|
{{- if .Values.global.database.gcloud.enabled -}}
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: Service
|
kind: Service
|
||||||
metadata:
|
metadata:
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
{{- if .Values.enabled -}}
|
{{- if .Values.global.database.gcloud.enabled -}}
|
||||||
{{- if .Values.serviceAccount.create -}}
|
{{- if .Values.serviceAccount.create -}}
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: ServiceAccount
|
kind: ServiceAccount
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
{{- if .Values.enabled -}}
|
{{- if .Values.global.database.gcloud.enabled -}}
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: Pod
|
kind: Pod
|
||||||
metadata:
|
metadata:
|
||||||
|
|||||||
@@ -1,7 +1,4 @@
|
|||||||
replicaCount: 2
|
replicaCount: 3
|
||||||
enabled: false
|
|
||||||
database:
|
|
||||||
connectionName: ""
|
|
||||||
|
|
||||||
image:
|
image:
|
||||||
# the tag is defined as chart appVersion.
|
# the tag is defined as chart appVersion.
|
||||||
@@ -33,11 +30,8 @@ service:
|
|||||||
|
|
||||||
resources:
|
resources:
|
||||||
limits:
|
limits:
|
||||||
memory: "1Gi"
|
memory: "4Gi"
|
||||||
cpu: "1"
|
cpu: "2"
|
||||||
requests:
|
|
||||||
memory: "512Mi"
|
|
||||||
cpu: "100m"
|
|
||||||
|
|
||||||
volumes: []
|
volumes: []
|
||||||
volumeMounts: []
|
volumeMounts: []
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ name: graphql
|
|||||||
description: AFFiNE GraphQL server
|
description: AFFiNE GraphQL server
|
||||||
type: application
|
type: application
|
||||||
version: 0.0.0
|
version: 0.0.0
|
||||||
appVersion: "0.26.1"
|
appVersion: "0.12.0"
|
||||||
dependencies:
|
dependencies:
|
||||||
- name: gcloud-sql-proxy
|
- name: gcloud-sql-proxy
|
||||||
version: 0.0.0
|
version: 0.0.0
|
||||||
|
|||||||
@@ -61,3 +61,18 @@ Create the name of the service account to use
|
|||||||
{{- default "default" .Values.serviceAccount.name }}
|
{{- default "default" .Values.serviceAccount.name }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|
||||||
|
{{- define "jwt.key" -}}
|
||||||
|
{{- $secret := lookup "v1" "Secret" .Release.Namespace .Values.app.jwt.secretName -}}
|
||||||
|
{{- if and $secret $secret.data.private -}}
|
||||||
|
{{/*
|
||||||
|
Reusing existing secret data
|
||||||
|
*/}}
|
||||||
|
key: {{ $secret.data.private }}
|
||||||
|
{{- else -}}
|
||||||
|
{{/*
|
||||||
|
Generate new data
|
||||||
|
*/}}
|
||||||
|
key: {{ genPrivateKey "ecdsa" | b64enc }}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end -}}
|
||||||
|
|||||||
9
.github/helm/affine/charts/graphql/templates/captcha-secret.yaml
vendored
Normal file
9
.github/helm/affine/charts/graphql/templates/captcha-secret.yaml
vendored
Normal file
@@ -0,0 +1,9 @@
|
|||||||
|
{{- if .Values.app.captcha.enabled -}}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: "{{ .Values.app.captcha.secretName }}"
|
||||||
|
type: Opaque
|
||||||
|
data:
|
||||||
|
turnstileSecret: {{ .Values.app.captcha.turnstile.secret | b64enc }}
|
||||||
|
{{- end }}
|
||||||
@@ -28,32 +28,32 @@ spec:
|
|||||||
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
|
||||||
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
env:
|
env:
|
||||||
- name: AFFINE_PRIVATE_KEY
|
- name: AUTH_PRIVATE_KEY
|
||||||
valueFrom:
|
valueFrom:
|
||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
name: "{{ .Values.global.secret.secretName }}"
|
name: "{{ .Values.app.jwt.secretName }}"
|
||||||
key: key
|
key: key
|
||||||
- name: NODE_ENV
|
- name: NODE_ENV
|
||||||
value: "{{ .Values.env }}"
|
value: "{{ .Values.env }}"
|
||||||
- name: NODE_OPTIONS
|
- name: NODE_OPTIONS
|
||||||
value: "--max-old-space-size=2048"
|
value: "--max-old-space-size=4096"
|
||||||
- name: NO_COLOR
|
- name: NO_COLOR
|
||||||
value: "1"
|
value: "1"
|
||||||
- name: DEPLOYMENT_TYPE
|
|
||||||
value: "{{ .Values.global.deployment.type }}"
|
|
||||||
- name: DEPLOYMENT_PLATFORM
|
|
||||||
value: "{{ .Values.global.deployment.platform }}"
|
|
||||||
- name: SERVER_FLAVOR
|
- name: SERVER_FLAVOR
|
||||||
value: "graphql"
|
value: "graphql"
|
||||||
- name: AFFINE_ENV
|
- name: AFFINE_ENV
|
||||||
value: "{{ .Release.Namespace }}"
|
value: "{{ .Release.Namespace }}"
|
||||||
|
- name: NEXTAUTH_URL
|
||||||
|
value: "{{ .Values.global.ingress.host }}"
|
||||||
- name: DATABASE_PASSWORD
|
- name: DATABASE_PASSWORD
|
||||||
valueFrom:
|
valueFrom:
|
||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
name: pg-postgresql
|
name: pg-postgresql
|
||||||
key: postgres-password
|
key: postgres-password
|
||||||
- name: DATABASE_URL
|
- name: DATABASE_URL
|
||||||
value: postgres://{{ .Values.global.database.user }}:$(DATABASE_PASSWORD)@{{ .Values.global.database.host }}:{{ .Values.global.database.port }}/{{ .Values.global.database.name }}
|
value: postgres://{{ .Values.global.database.user }}:$(DATABASE_PASSWORD)@{{ .Values.global.database.url }}:{{ .Values.global.database.port }}/{{ .Values.global.database.name }}
|
||||||
|
- name: REDIS_SERVER_ENABLED
|
||||||
|
value: "true"
|
||||||
- name: REDIS_SERVER_HOST
|
- name: REDIS_SERVER_HOST
|
||||||
value: "{{ .Values.global.redis.host }}"
|
value: "{{ .Values.global.redis.host }}"
|
||||||
- name: REDIS_SERVER_PORT
|
- name: REDIS_SERVER_PORT
|
||||||
@@ -67,15 +67,6 @@ spec:
|
|||||||
key: redis-password
|
key: redis-password
|
||||||
- name: REDIS_SERVER_DATABASE
|
- name: REDIS_SERVER_DATABASE
|
||||||
value: "{{ .Values.global.redis.database }}"
|
value: "{{ .Values.global.redis.database }}"
|
||||||
- name: AFFINE_INDEXER_SEARCH_PROVIDER
|
|
||||||
value: "{{ .Values.global.indexer.provider }}"
|
|
||||||
- name: AFFINE_INDEXER_SEARCH_ENDPOINT
|
|
||||||
value: "{{ .Values.global.indexer.endpoint }}"
|
|
||||||
- name: AFFINE_INDEXER_SEARCH_API_KEY
|
|
||||||
valueFrom:
|
|
||||||
secretKeyRef:
|
|
||||||
name: indexer
|
|
||||||
key: indexer-apiKey
|
|
||||||
- name: AFFINE_SERVER_PORT
|
- name: AFFINE_SERVER_PORT
|
||||||
value: "{{ .Values.service.port }}"
|
value: "{{ .Values.service.port }}"
|
||||||
- name: AFFINE_SERVER_SUB_PATH
|
- name: AFFINE_SERVER_SUB_PATH
|
||||||
@@ -84,20 +75,115 @@ spec:
|
|||||||
value: "{{ .Values.app.host }}"
|
value: "{{ .Values.app.host }}"
|
||||||
- name: AFFINE_SERVER_HTTPS
|
- name: AFFINE_SERVER_HTTPS
|
||||||
value: "{{ .Values.app.https }}"
|
value: "{{ .Values.app.https }}"
|
||||||
- name: DOC_SERVICE_ENDPOINT
|
- name: ENABLE_R2_OBJECT_STORAGE
|
||||||
value: "http://{{ .Values.global.docService.name }}:{{ .Values.global.docService.port }}"
|
value: "{{ .Values.app.objectStorage.r2.enabled }}"
|
||||||
|
- name: ENABLE_CAPTCHA
|
||||||
|
value: "{{ .Values.app.captcha.enabled }}"
|
||||||
|
- name: FEATURES_EARLY_ACCESS_PREVIEW
|
||||||
|
value: "{{ .Values.app.features.earlyAccessPreview }}"
|
||||||
|
- name: OAUTH_EMAIL_SENDER
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: "{{ .Values.app.oauth.email.secretName }}"
|
||||||
|
key: sender
|
||||||
|
- name: OAUTH_EMAIL_LOGIN
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: "{{ .Values.app.oauth.email.secretName }}"
|
||||||
|
key: login
|
||||||
|
- name: OAUTH_EMAIL_SERVER
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: "{{ .Values.app.oauth.email.secretName }}"
|
||||||
|
key: server
|
||||||
|
- name: OAUTH_EMAIL_PORT
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: "{{ .Values.app.oauth.email.secretName }}"
|
||||||
|
key: port
|
||||||
|
- name: OAUTH_EMAIL_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: "{{ .Values.app.oauth.email.secretName }}"
|
||||||
|
key: password
|
||||||
|
- name: STRIPE_API_KEY
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: "{{ .Values.app.payment.stripe.secretName }}"
|
||||||
|
key: stripeAPIKey
|
||||||
|
- name: STRIPE_WEBHOOK_KEY
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: "{{ .Values.app.payment.stripe.secretName }}"
|
||||||
|
key: stripeWebhookKey
|
||||||
|
- name: DOC_MERGE_INTERVAL
|
||||||
|
value: "{{ .Values.app.doc.mergeInterval }}"
|
||||||
|
{{ if .Values.app.experimental.enableJwstCodec }}
|
||||||
|
- name: DOC_MERGE_USE_JWST_CODEC
|
||||||
|
value: "true"
|
||||||
|
{{ end }}
|
||||||
|
{{ if .Values.app.objectStorage.r2.enabled }}
|
||||||
|
- name: R2_OBJECT_STORAGE_ACCOUNT_ID
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: "{{ .Values.app.objectStorage.r2.secretName }}"
|
||||||
|
key: accountId
|
||||||
|
- name: R2_OBJECT_STORAGE_ACCESS_KEY_ID
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: "{{ .Values.app.objectStorage.r2.secretName }}"
|
||||||
|
key: accessKeyId
|
||||||
|
- name: R2_OBJECT_STORAGE_SECRET_ACCESS_KEY
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: "{{ .Values.app.objectStorage.r2.secretName }}"
|
||||||
|
key: secretAccessKey
|
||||||
|
{{ end }}
|
||||||
|
{{ if .Values.app.captcha.enabled }}
|
||||||
|
- name: CAPTCHA_TURNSTILE_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: "{{ .Values.app.captcha.secretName }}"
|
||||||
|
key: turnstileSecret
|
||||||
|
{{ end }}
|
||||||
|
{{ if .Values.app.oauth.google.enabled }}
|
||||||
|
- name: OAUTH_GOOGLE_ENABLED
|
||||||
|
value: "true"
|
||||||
|
- name: OAUTH_GOOGLE_CLIENT_ID
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: "{{ .Values.app.oauth.google.secretName }}"
|
||||||
|
key: clientId
|
||||||
|
- name: OAUTH_GOOGLE_CLIENT_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: "{{ .Values.app.oauth.google.secretName }}"
|
||||||
|
key: clientSecret
|
||||||
|
{{ end }}
|
||||||
|
{{ if .Values.app.oauth.github.enabled }}
|
||||||
|
- name: OAUTH_GITHUB_CLIENT_ID
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: "{{ .Values.app.oauth.github.secretName }}"
|
||||||
|
key: clientId
|
||||||
|
- name: OAUTH_GITHUB_CLIENT_SECRET
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: "{{ .Values.app.oauth.github.secretName }}"
|
||||||
|
key: clientSecret
|
||||||
|
{{ end }}
|
||||||
ports:
|
ports:
|
||||||
- name: http
|
- name: http
|
||||||
containerPort: {{ .Values.service.port }}
|
containerPort: {{ .Values.service.port }}
|
||||||
protocol: TCP
|
protocol: TCP
|
||||||
livenessProbe:
|
livenessProbe:
|
||||||
httpGet:
|
httpGet:
|
||||||
path: /info
|
path: /
|
||||||
port: http
|
port: http
|
||||||
initialDelaySeconds: {{ .Values.probe.initialDelaySeconds }}
|
initialDelaySeconds: {{ .Values.probe.initialDelaySeconds }}
|
||||||
readinessProbe:
|
readinessProbe:
|
||||||
httpGet:
|
httpGet:
|
||||||
path: /info
|
path: /
|
||||||
port: http
|
port: http
|
||||||
initialDelaySeconds: {{ .Values.probe.initialDelaySeconds }}
|
initialDelaySeconds: {{ .Values.probe.initialDelaySeconds }}
|
||||||
resources:
|
resources:
|
||||||
|
|||||||
7
.github/helm/affine/charts/graphql/templates/jwt-secret.yaml
vendored
Normal file
7
.github/helm/affine/charts/graphql/templates/jwt-secret.yaml
vendored
Normal file
@@ -0,0 +1,7 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: "{{ .Values.app.jwt.secretName }}"
|
||||||
|
type: Opaque
|
||||||
|
data:
|
||||||
|
{{- ( include "jwt.key" . ) | indent 2 -}}
|
||||||
@@ -22,37 +22,36 @@ spec:
|
|||||||
value: "{{ .Values.env }}"
|
value: "{{ .Values.env }}"
|
||||||
- name: AFFINE_ENV
|
- name: AFFINE_ENV
|
||||||
value: "{{ .Release.Namespace }}"
|
value: "{{ .Release.Namespace }}"
|
||||||
- name: DEPLOYMENT_TYPE
|
|
||||||
value: "{{ .Values.global.deployment.type }}"
|
|
||||||
- name: DEPLOYMENT_PLATFORM
|
|
||||||
value: "{{ .Values.global.deployment.platform }}"
|
|
||||||
- name: DATABASE_PASSWORD
|
- name: DATABASE_PASSWORD
|
||||||
valueFrom:
|
valueFrom:
|
||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
name: pg-postgresql
|
name: pg-postgresql
|
||||||
key: postgres-password
|
key: postgres-password
|
||||||
|
{{ if not .Values.global.database.gcloud.enabled }}
|
||||||
- name: DATABASE_URL
|
- name: DATABASE_URL
|
||||||
value: postgres://{{ .Values.global.database.user }}:$(DATABASE_PASSWORD)@{{ .Values.global.database.host }}:{{ .Values.global.database.port }}/{{ .Values.global.database.name }}
|
value: postgres://{{ .Values.global.database.user }}:$(DATABASE_PASSWORD)@{{ .Values.global.database.url }}:{{ .Values.global.database.port }}/{{ .Values.global.database.name }}
|
||||||
- name: REDIS_SERVER_HOST
|
{{ end }}
|
||||||
value: "{{ .Values.global.redis.host }}"
|
{{ if .Values.global.database.gcloud.enabled }}
|
||||||
- name: REDIS_SERVER_PORT
|
- name: DATABASE_URL
|
||||||
value: "{{ .Values.global.redis.port }}"
|
value: postgres://{{ .Values.global.database.user }}:$(DATABASE_PASSWORD)@{{ .Values.global.database.gcloud.cloudSqlInternal }}:{{ .Values.global.database.port }}/{{ .Values.global.database.name }}
|
||||||
- name: REDIS_SERVER_USER
|
{{ end }}
|
||||||
value: "{{ .Values.global.redis.username }}"
|
{{ if .Values.app.objectStorage.r2.enabled }}
|
||||||
- name: REDIS_SERVER_PASSWORD
|
- name: R2_OBJECT_STORAGE_ACCOUNT_ID
|
||||||
valueFrom:
|
valueFrom:
|
||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
name: redis
|
name: "{{ .Values.app.objectStorage.r2.secretName }}"
|
||||||
key: redis-password
|
key: accountId
|
||||||
- name: AFFINE_INDEXER_SEARCH_PROVIDER
|
- name: R2_OBJECT_STORAGE_ACCESS_KEY_ID
|
||||||
value: "{{ .Values.global.indexer.provider }}"
|
|
||||||
- name: AFFINE_INDEXER_SEARCH_ENDPOINT
|
|
||||||
value: "{{ .Values.global.indexer.endpoint }}"
|
|
||||||
- name: AFFINE_INDEXER_SEARCH_API_KEY
|
|
||||||
valueFrom:
|
valueFrom:
|
||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
name: indexer
|
name: "{{ .Values.app.objectStorage.r2.secretName }}"
|
||||||
key: indexer-apiKey
|
key: accessKeyId
|
||||||
|
- name: R2_OBJECT_STORAGE_SECRET_ACCESS_KEY
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: "{{ .Values.app.objectStorage.r2.secretName }}"
|
||||||
|
key: secretAccessKey
|
||||||
|
{{ end }}
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
cpu: '100m'
|
cpu: '100m'
|
||||||
|
|||||||
33
.github/helm/affine/charts/graphql/templates/oauth.yaml
vendored
Normal file
33
.github/helm/affine/charts/graphql/templates/oauth.yaml
vendored
Normal file
@@ -0,0 +1,33 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: "{{ .Values.app.oauth.email.secretName }}"
|
||||||
|
type: Opaque
|
||||||
|
data:
|
||||||
|
sender: "{{ .Values.app.oauth.email.sender | b64enc }}"
|
||||||
|
login: "{{ .Values.app.oauth.email.login | b64enc }}"
|
||||||
|
password: "{{ .Values.app.oauth.email.password | b64enc }}"
|
||||||
|
server: "{{ .Values.app.oauth.email.server | b64enc }}"
|
||||||
|
port: "{{ .Values.app.oauth.email.port | b64enc }}"
|
||||||
|
---
|
||||||
|
{{- if .Values.app.oauth.google.enabled -}}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: "{{ .Values.app.oauth.google.secretName }}"
|
||||||
|
type: Opaque
|
||||||
|
data:
|
||||||
|
clientId: "{{ .Values.app.oauth.google.clientId | b64enc }}"
|
||||||
|
clientSecret: "{{ .Values.app.oauth.google.clientSecret | b64enc }}"
|
||||||
|
{{- end }}
|
||||||
|
---
|
||||||
|
{{- if .Values.app.oauth.github.enabled -}}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: "{{ .Values.app.oauth.github.secretName }}"
|
||||||
|
type: Opaque
|
||||||
|
data:
|
||||||
|
clientId: "{{ .Values.app.oauth.github.clientId | b64enc }}"
|
||||||
|
clientSecret: "{{ .Values.app.oauth.github.clientSecret | b64enc }}"
|
||||||
|
{{- end }}
|
||||||
8
.github/helm/affine/charts/graphql/templates/payment.yml
vendored
Normal file
8
.github/helm/affine/charts/graphql/templates/payment.yml
vendored
Normal file
@@ -0,0 +1,8 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: "{{ .Values.app.payment.stripe.secretName }}"
|
||||||
|
type: Opaque
|
||||||
|
data:
|
||||||
|
stripeAPIKey: "{{ .Values.app.payment.stripe.apiKey | b64enc }}"
|
||||||
|
stripeWebhookKey: "{{ .Values.app.payment.stripe.webhookKey | b64enc }}"
|
||||||
11
.github/helm/affine/charts/graphql/templates/r2-secret.yaml
vendored
Normal file
11
.github/helm/affine/charts/graphql/templates/r2-secret.yaml
vendored
Normal file
@@ -0,0 +1,11 @@
|
|||||||
|
{{- if .Values.app.objectStorage.r2.enabled -}}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: "{{ .Values.app.objectStorage.r2.secretName }}"
|
||||||
|
type: Opaque
|
||||||
|
data:
|
||||||
|
accountId: {{ .Values.app.objectStorage.r2.accountId | b64enc }}
|
||||||
|
accessKeyId: {{ .Values.app.objectStorage.r2.accessKeyId | b64enc }}
|
||||||
|
secretAccessKey: {{ .Values.app.objectStorage.r2.secretAccessKey | b64enc }}
|
||||||
|
{{- end }}
|
||||||
@@ -1,18 +0,0 @@
|
|||||||
{{- $privateKey := default (genPrivateKey "ecdsa") .Values.global.secret.privateKey | b64enc | quote }}
|
|
||||||
|
|
||||||
{{- if not .Values.global.secret.privateKey }}
|
|
||||||
{{- $existingKey := (lookup "v1" "Secret" .Release.Namespace .Values.global.secret.secretName) }}
|
|
||||||
{{- if $existingKey }}
|
|
||||||
{{- $privateKey = index $existingKey.data "key" }}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: {{ .Values.global.secret.secretName }}
|
|
||||||
annotations:
|
|
||||||
"helm.sh/resource-policy": "keep"
|
|
||||||
type: Opaque
|
|
||||||
data:
|
|
||||||
key: {{ $privateKey }}
|
|
||||||
@@ -4,10 +4,6 @@ metadata:
|
|||||||
name: {{ include "graphql.fullname" . }}
|
name: {{ include "graphql.fullname" . }}
|
||||||
labels:
|
labels:
|
||||||
{{- include "graphql.labels" . | nindent 4 }}
|
{{- include "graphql.labels" . | nindent 4 }}
|
||||||
{{- with .Values.service.annotations }}
|
|
||||||
annotations:
|
|
||||||
{{- toYaml . | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
spec:
|
spec:
|
||||||
type: {{ .Values.service.type }}
|
type: {{ .Values.service.type }}
|
||||||
ports:
|
ports:
|
||||||
|
|||||||
56
.github/helm/affine/charts/graphql/values.yaml
vendored
56
.github/helm/affine/charts/graphql/values.yaml
vendored
@@ -1,6 +1,6 @@
|
|||||||
replicaCount: 1
|
replicaCount: 1
|
||||||
image:
|
image:
|
||||||
repository: ghcr.io/toeverything/affine
|
repository: ghcr.io/toeverything/affine-graphql
|
||||||
pullPolicy: IfNotPresent
|
pullPolicy: IfNotPresent
|
||||||
tag: ''
|
tag: ''
|
||||||
|
|
||||||
@@ -10,12 +10,57 @@ fullnameOverride: ''
|
|||||||
# map to NODE_ENV environment variable
|
# map to NODE_ENV environment variable
|
||||||
env: 'production'
|
env: 'production'
|
||||||
app:
|
app:
|
||||||
|
experimental:
|
||||||
|
enableJwstCodec: true
|
||||||
# AFFINE_SERVER_SUB_PATH
|
# AFFINE_SERVER_SUB_PATH
|
||||||
path: ''
|
path: ''
|
||||||
# AFFINE_SERVER_HOST
|
# AFFINE_SERVER_HOST
|
||||||
host: '0.0.0.0'
|
host: '0.0.0.0'
|
||||||
https: true
|
https: true
|
||||||
|
doc:
|
||||||
|
mergeInterval: "3000"
|
||||||
|
jwt:
|
||||||
|
secretName: jwt-private-key
|
||||||
|
# base64 encoded ecdsa private key
|
||||||
|
privateKey: ''
|
||||||
|
captcha:
|
||||||
|
enable: false
|
||||||
|
secretName: captcha
|
||||||
|
turnstile:
|
||||||
|
secret: ''
|
||||||
|
objectStorage:
|
||||||
|
r2:
|
||||||
|
enabled: false
|
||||||
|
secretName: r2
|
||||||
|
accountId: ''
|
||||||
|
accessKeyId: ''
|
||||||
|
secretAccessKey: ''
|
||||||
|
oauth:
|
||||||
|
email:
|
||||||
|
secretName: 'oauth-email'
|
||||||
|
sender: 'noreply@toeverything.info'
|
||||||
|
login: ''
|
||||||
|
password: ''
|
||||||
|
server: 'smtp.gmail.com'
|
||||||
|
port: '465'
|
||||||
|
google:
|
||||||
|
enabled: false
|
||||||
|
secretName: oauth-google
|
||||||
|
clientId: ''
|
||||||
|
clientSecret: ''
|
||||||
|
github:
|
||||||
|
enabled: false
|
||||||
|
secretName: oauth-github
|
||||||
|
clientId: ''
|
||||||
|
clientSecret: ''
|
||||||
|
payment:
|
||||||
|
stripe:
|
||||||
|
secretName: 'stripe'
|
||||||
|
apiKey: ''
|
||||||
|
webhookKey: ''
|
||||||
|
features:
|
||||||
|
earlyAccessPreview: false
|
||||||
|
|
||||||
serviceAccount:
|
serviceAccount:
|
||||||
create: true
|
create: true
|
||||||
annotations: {}
|
annotations: {}
|
||||||
@@ -27,12 +72,9 @@ podSecurityContext:
|
|||||||
fsGroup: 2000
|
fsGroup: 2000
|
||||||
|
|
||||||
resources:
|
resources:
|
||||||
limits:
|
|
||||||
cpu: '1'
|
|
||||||
memory: 4Gi
|
|
||||||
requests:
|
requests:
|
||||||
cpu: '1'
|
cpu: '4'
|
||||||
memory: 2Gi
|
memory: 4Gi
|
||||||
|
|
||||||
probe:
|
probe:
|
||||||
initialDelaySeconds: 20
|
initialDelaySeconds: 20
|
||||||
|
|||||||
23
.github/helm/affine/charts/sync/.helmignore
vendored
Normal file
23
.github/helm/affine/charts/sync/.helmignore
vendored
Normal file
@@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
11
.github/helm/affine/charts/sync/Chart.yaml
vendored
Normal file
11
.github/helm/affine/charts/sync/Chart.yaml
vendored
Normal file
@@ -0,0 +1,11 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: sync
|
||||||
|
description: AFFiNE Sync Server
|
||||||
|
type: application
|
||||||
|
version: 0.0.0
|
||||||
|
appVersion: "0.12.0"
|
||||||
|
dependencies:
|
||||||
|
- name: gcloud-sql-proxy
|
||||||
|
version: 0.0.0
|
||||||
|
repository: "file://../gcloud-sql-proxy"
|
||||||
|
condition: .global.database.gcloud.enabled
|
||||||
16
.github/helm/affine/charts/sync/templates/NOTES.txt
vendored
Normal file
16
.github/helm/affine/charts/sync/templates/NOTES.txt
vendored
Normal file
@@ -0,0 +1,16 @@
|
|||||||
|
1. Get the application URL by running these commands:
|
||||||
|
{{- if contains "NodePort" .Values.service.type }}
|
||||||
|
export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "sync.fullname" . }})
|
||||||
|
export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}")
|
||||||
|
echo http://$NODE_IP:$NODE_PORT
|
||||||
|
{{- else if contains "LoadBalancer" .Values.service.type }}
|
||||||
|
NOTE: It may take a few minutes for the LoadBalancer IP to be available.
|
||||||
|
You can watch the status of by running 'kubectl get --namespace {{ .Release.Namespace }} svc -w {{ include "sync.fullname" . }}'
|
||||||
|
export SERVICE_IP=$(kubectl get svc --namespace {{ .Release.Namespace }} {{ include "sync.fullname" . }} --template "{{"{{ range (index .status.loadBalancer.ingress 0) }}{{.}}{{ end }}"}}")
|
||||||
|
echo http://$SERVICE_IP:{{ .Values.service.port }}
|
||||||
|
{{- else if contains "ClusterIP" .Values.service.type }}
|
||||||
|
export POD_NAME=$(kubectl get pods --namespace {{ .Release.Namespace }} -l "app.kubernetes.io/name={{ include "sync.name" . }},app.kubernetes.io/instance={{ .Release.Name }}" -o jsonpath="{.items[0].metadata.name}")
|
||||||
|
export CONTAINER_PORT=$(kubectl get pod --namespace {{ .Release.Namespace }} $POD_NAME -o jsonpath="{.spec.containers[0].ports[0].containerPort}")
|
||||||
|
echo "Visit http://127.0.0.1:8080 to use your application"
|
||||||
|
kubectl --namespace {{ .Release.Namespace }} port-forward $POD_NAME 8080:$CONTAINER_PORT
|
||||||
|
{{- end }}
|
||||||
63
.github/helm/affine/charts/sync/templates/_helpers.tpl
vendored
Normal file
63
.github/helm/affine/charts/sync/templates/_helpers.tpl
vendored
Normal file
@@ -0,0 +1,63 @@
|
|||||||
|
{{/*
|
||||||
|
Expand the name of the chart.
|
||||||
|
*/}}
|
||||||
|
{{- define "sync.name" -}}
|
||||||
|
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||||
|
If release name contains chart name it will be used as a full name.
|
||||||
|
*/}}
|
||||||
|
{{- define "sync.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride }}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- $name := default .Chart.Name .Values.nameOverride }}
|
||||||
|
{{- if contains $name .Release.Name }}
|
||||||
|
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create chart name and version as used by the chart label.
|
||||||
|
*/}}
|
||||||
|
{{- define "sync.chart" -}}
|
||||||
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Common labels
|
||||||
|
*/}}
|
||||||
|
{{- define "sync.labels" -}}
|
||||||
|
helm.sh/chart: {{ include "sync.chart" . }}
|
||||||
|
{{ include "sync.selectorLabels" . }}
|
||||||
|
{{- if .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
{{- end }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
monitoring: enabled
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Selector labels
|
||||||
|
*/}}
|
||||||
|
{{- define "sync.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "sync.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "sync.serviceAccountName" -}}
|
||||||
|
{{- if .Values.serviceAccount.create }}
|
||||||
|
{{- default (include "sync.fullname" .) .Values.serviceAccount.name }}
|
||||||
|
{{- else }}
|
||||||
|
{{- default "default" .Values.serviceAccount.name }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
96
.github/helm/affine/charts/sync/templates/deployment.yaml
vendored
Normal file
96
.github/helm/affine/charts/sync/templates/deployment.yaml
vendored
Normal file
@@ -0,0 +1,96 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "sync.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "sync.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "sync.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
{{- with .Values.podAnnotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
labels:
|
||||||
|
{{- include "sync.selectorLabels" . | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
serviceAccountName: {{ include "sync.serviceAccountName" . }}
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml .Values.podSecurityContext | nindent 8 }}
|
||||||
|
containers:
|
||||||
|
- name: {{ .Chart.Name }}
|
||||||
|
securityContext:
|
||||||
|
{{- toYaml .Values.securityContext | nindent 12 }}
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
env:
|
||||||
|
- name: NODE_ENV
|
||||||
|
value: "{{ .Values.env }}"
|
||||||
|
- name: NO_COLOR
|
||||||
|
value: "1"
|
||||||
|
- name: SERVER_FLAVOR
|
||||||
|
value: "sync"
|
||||||
|
- name: NEXTAUTH_URL
|
||||||
|
value: "{{ .Values.global.ingress.host }}"
|
||||||
|
- name: AFFINE_ENV
|
||||||
|
value: "{{ .Release.Namespace }}"
|
||||||
|
- name: DATABASE_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: pg-postgresql
|
||||||
|
key: postgres-password
|
||||||
|
- name: DATABASE_URL
|
||||||
|
value: postgres://{{ .Values.global.database.user }}:$(DATABASE_PASSWORD)@{{ .Values.global.database.url }}:{{ .Values.global.database.port }}/{{ .Values.global.database.name }}
|
||||||
|
- name: REDIS_SERVER_ENABLED
|
||||||
|
value: "true"
|
||||||
|
- name: REDIS_SERVER_HOST
|
||||||
|
value: "{{ .Values.global.redis.host }}"
|
||||||
|
- name: REDIS_SERVER_PORT
|
||||||
|
value: "{{ .Values.global.redis.port }}"
|
||||||
|
- name: REDIS_SERVER_USER
|
||||||
|
value: "{{ .Values.global.redis.username }}"
|
||||||
|
- name: REDIS_SERVER_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: redis
|
||||||
|
key: redis-password
|
||||||
|
- name: REDIS_SERVER_DATABASE
|
||||||
|
value: "{{ .Values.global.redis.database }}"
|
||||||
|
- name: AFFINE_SERVER_PORT
|
||||||
|
value: "{{ .Values.service.port }}"
|
||||||
|
- name: AFFINE_SERVER_HOST
|
||||||
|
value: "{{ .Values.app.host }}"
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
containerPort: {{ .Values.service.port }}
|
||||||
|
protocol: TCP
|
||||||
|
livenessProbe:
|
||||||
|
tcpSocket:
|
||||||
|
port: http
|
||||||
|
initialDelaySeconds: {{ .Values.probe.initialDelaySeconds }}
|
||||||
|
readinessProbe:
|
||||||
|
tcpSocket:
|
||||||
|
port: http
|
||||||
|
initialDelaySeconds: {{ .Values.probe.initialDelaySeconds }}
|
||||||
|
resources:
|
||||||
|
{{- toYaml .Values.resources | nindent 12 }}
|
||||||
|
{{- with .Values.nodeSelector }}
|
||||||
|
nodeSelector:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.affinity }}
|
||||||
|
affinity:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.tolerations }}
|
||||||
|
tolerations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
19
.github/helm/affine/charts/sync/templates/service.yaml
vendored
Normal file
19
.github/helm/affine/charts/sync/templates/service.yaml
vendored
Normal file
@@ -0,0 +1,19 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "sync.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "sync.labels" . | nindent 4 }}
|
||||||
|
{{- with .Values.service.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type }}
|
||||||
|
ports:
|
||||||
|
- port: {{ .Values.service.port }}
|
||||||
|
targetPort: http
|
||||||
|
protocol: TCP
|
||||||
|
name: http
|
||||||
|
selector:
|
||||||
|
{{- include "sync.selectorLabels" . | nindent 4 }}
|
||||||
12
.github/helm/affine/charts/sync/templates/serviceaccount.yaml
vendored
Normal file
12
.github/helm/affine/charts/sync/templates/serviceaccount.yaml
vendored
Normal file
@@ -0,0 +1,12 @@
|
|||||||
|
{{- if .Values.serviceAccount.create -}}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ include "sync.serviceAccountName" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "sync.labels" . | nindent 4 }}
|
||||||
|
{{- with .Values.serviceAccount.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
15
.github/helm/affine/charts/sync/templates/tests/test-connection.yaml
vendored
Normal file
15
.github/helm/affine/charts/sync/templates/tests/test-connection.yaml
vendored
Normal file
@@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: "{{ include "sync.fullname" . }}-test-connection"
|
||||||
|
labels:
|
||||||
|
{{- include "sync.labels" . | nindent 4 }}
|
||||||
|
annotations:
|
||||||
|
"helm.sh/hook": test
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: wget
|
||||||
|
image: busybox
|
||||||
|
command: ['wget']
|
||||||
|
args: ['{{ include "sync.fullname" . }}:{{ .Values.service.port }}']
|
||||||
|
restartPolicy: Never
|
||||||
39
.github/helm/affine/charts/sync/values.yaml
vendored
Normal file
39
.github/helm/affine/charts/sync/values.yaml
vendored
Normal file
@@ -0,0 +1,39 @@
|
|||||||
|
replicaCount: 1
|
||||||
|
image:
|
||||||
|
repository: ghcr.io/toeverything/affine-graphql
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
tag: ''
|
||||||
|
|
||||||
|
imagePullSecrets: []
|
||||||
|
nameOverride: ''
|
||||||
|
fullnameOverride: ''
|
||||||
|
# map to NODE_ENV environment variable
|
||||||
|
env: 'production'
|
||||||
|
app:
|
||||||
|
# AFFINE_SERVER_HOST
|
||||||
|
host: '0.0.0.0'
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
create: true
|
||||||
|
annotations: {}
|
||||||
|
name: 'affine-sync'
|
||||||
|
|
||||||
|
podAnnotations: {}
|
||||||
|
|
||||||
|
podSecurityContext:
|
||||||
|
fsGroup: 2000
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu: '4'
|
||||||
|
memory: 8Gi
|
||||||
|
requests:
|
||||||
|
cpu: '2'
|
||||||
|
memory: 4Gi
|
||||||
|
|
||||||
|
probe:
|
||||||
|
initialDelaySeconds: 20
|
||||||
|
|
||||||
|
nodeSelector: {}
|
||||||
|
tolerations: []
|
||||||
|
affinity: {}
|
||||||
23
.github/helm/affine/charts/web/.helmignore
vendored
Normal file
23
.github/helm/affine/charts/web/.helmignore
vendored
Normal file
@@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
6
.github/helm/affine/charts/web/Chart.yaml
vendored
Normal file
6
.github/helm/affine/charts/web/Chart.yaml
vendored
Normal file
@@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: web
|
||||||
|
description: A Helm chart for Kubernetes
|
||||||
|
type: application
|
||||||
|
version: 0.0.0
|
||||||
|
appVersion: "0.7.0-canary.18"
|
||||||
16
.github/helm/affine/charts/web/templates/NOTES.txt
vendored
Normal file
16
.github/helm/affine/charts/web/templates/NOTES.txt
vendored
Normal file
@@ -0,0 +1,16 @@
|
|||||||
|
1. Get the application URL by running these commands:
|
||||||
|
{{- if contains "NodePort" .Values.service.type }}
|
||||||
|
export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "web.fullname" . }})
|
||||||
|
export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}")
|
||||||
|
echo http://$NODE_IP:$NODE_PORT
|
||||||
|
{{- else if contains "LoadBalancer" .Values.service.type }}
|
||||||
|
NOTE: It may take a few minutes for the LoadBalancer IP to be available.
|
||||||
|
You can watch the status of by running 'kubectl get --namespace {{ .Release.Namespace }} svc -w {{ include "web.fullname" . }}'
|
||||||
|
export SERVICE_IP=$(kubectl get svc --namespace {{ .Release.Namespace }} {{ include "web.fullname" . }} --template "{{"{{ range (index .status.loadBalancer.ingress 0) }}{{.}}{{ end }}"}}")
|
||||||
|
echo http://$SERVICE_IP:{{ .Values.service.port }}
|
||||||
|
{{- else if contains "ClusterIP" .Values.service.type }}
|
||||||
|
export POD_NAME=$(kubectl get pods --namespace {{ .Release.Namespace }} -l "app.kubernetes.io/name={{ include "web.name" . }},app.kubernetes.io/instance={{ .Release.Name }}" -o jsonpath="{.items[0].metadata.name}")
|
||||||
|
export CONTAINER_PORT=$(kubectl get pod --namespace {{ .Release.Namespace }} $POD_NAME -o jsonpath="{.spec.containers[0].ports[0].containerPort}")
|
||||||
|
echo "Visit http://127.0.0.1:8080 to use your application"
|
||||||
|
kubectl --namespace {{ .Release.Namespace }} port-forward $POD_NAME 8080:$CONTAINER_PORT
|
||||||
|
{{- end }}
|
||||||
63
.github/helm/affine/charts/web/templates/_helpers.tpl
vendored
Normal file
63
.github/helm/affine/charts/web/templates/_helpers.tpl
vendored
Normal file
@@ -0,0 +1,63 @@
|
|||||||
|
{{/*
|
||||||
|
Expand the name of the chart.
|
||||||
|
*/}}
|
||||||
|
{{- define "web.name" -}}
|
||||||
|
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||||
|
If release name contains chart name it will be used as a full name.
|
||||||
|
*/}}
|
||||||
|
{{- define "web.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride }}
|
||||||
|
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- $name := default .Chart.Name .Values.nameOverride }}
|
||||||
|
{{- if contains $name .Release.Name }}
|
||||||
|
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create chart name and version as used by the chart label.
|
||||||
|
*/}}
|
||||||
|
{{- define "web.chart" -}}
|
||||||
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Common labels
|
||||||
|
*/}}
|
||||||
|
{{- define "web.labels" -}}
|
||||||
|
helm.sh/chart: {{ include "web.chart" . }}
|
||||||
|
{{ include "web.selectorLabels" . }}
|
||||||
|
{{- if .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
{{- end }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
monitoring: enabled
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Selector labels
|
||||||
|
*/}}
|
||||||
|
{{- define "web.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "web.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "web.serviceAccountName" -}}
|
||||||
|
{{- if .Values.serviceAccount.create }}
|
||||||
|
{{- default (include "web.fullname" .) .Values.serviceAccount.name }}
|
||||||
|
{{- else }}
|
||||||
|
{{- default "default" .Values.serviceAccount.name }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
57
.github/helm/affine/charts/web/templates/deployment.yaml
vendored
Normal file
57
.github/helm/affine/charts/web/templates/deployment.yaml
vendored
Normal file
@@ -0,0 +1,57 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "web.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "web.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.replicaCount }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "web.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
{{- with .Values.podAnnotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
labels:
|
||||||
|
{{- include "web.selectorLabels" . | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
serviceAccountName: {{ include "web.serviceAccountName" . }}
|
||||||
|
containers:
|
||||||
|
- name: {{ .Chart.Name }}
|
||||||
|
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
|
||||||
|
imagePullPolicy: {{ .Values.image.pullPolicy }}
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
containerPort: {{ .Values.service.port }}
|
||||||
|
protocol: TCP
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /
|
||||||
|
port: http
|
||||||
|
initialDelaySeconds: {{ .Values.probe.initialDelaySeconds }}
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /
|
||||||
|
port: http
|
||||||
|
initialDelaySeconds: {{ .Values.probe.initialDelaySeconds }}
|
||||||
|
resources:
|
||||||
|
{{- toYaml .Values.resources | nindent 12 }}
|
||||||
|
{{- with .Values.nodeSelector }}
|
||||||
|
nodeSelector:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.affinity }}
|
||||||
|
affinity:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.tolerations }}
|
||||||
|
tolerations:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
15
.github/helm/affine/charts/web/templates/service.yaml
vendored
Normal file
15
.github/helm/affine/charts/web/templates/service.yaml
vendored
Normal file
@@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "web.fullname" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "web.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type }}
|
||||||
|
ports:
|
||||||
|
- port: {{ .Values.service.port }}
|
||||||
|
targetPort: http
|
||||||
|
protocol: TCP
|
||||||
|
name: http
|
||||||
|
selector:
|
||||||
|
{{- include "web.selectorLabels" . | nindent 4 }}
|
||||||
12
.github/helm/affine/charts/web/templates/serviceaccount.yaml
vendored
Normal file
12
.github/helm/affine/charts/web/templates/serviceaccount.yaml
vendored
Normal file
@@ -0,0 +1,12 @@
|
|||||||
|
{{- if .Values.serviceAccount.create -}}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ include "web.serviceAccountName" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "web.labels" . | nindent 4 }}
|
||||||
|
{{- with .Values.serviceAccount.annotations }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml . | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
15
.github/helm/affine/charts/web/templates/tests/test-connection.yaml
vendored
Normal file
15
.github/helm/affine/charts/web/templates/tests/test-connection.yaml
vendored
Normal file
@@ -0,0 +1,15 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Pod
|
||||||
|
metadata:
|
||||||
|
name: "{{ include "web.fullname" . }}-test-connection"
|
||||||
|
labels:
|
||||||
|
{{- include "web.labels" . | nindent 4 }}
|
||||||
|
annotations:
|
||||||
|
"helm.sh/hook": test
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: wget
|
||||||
|
image: busybox
|
||||||
|
command: ['wget']
|
||||||
|
args: ['{{ include "web.fullname" . }}:{{ .Values.service.port }}']
|
||||||
|
restartPolicy: Never
|
||||||
37
.github/helm/affine/charts/web/values.yaml
vendored
Normal file
37
.github/helm/affine/charts/web/values.yaml
vendored
Normal file
@@ -0,0 +1,37 @@
|
|||||||
|
replicaCount: 1
|
||||||
|
|
||||||
|
image:
|
||||||
|
repository: ghcr.io/toeverything/affine-front
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
tag: ""
|
||||||
|
|
||||||
|
imagePullSecrets: []
|
||||||
|
nameOverride: ""
|
||||||
|
fullnameOverride: ""
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
create: true
|
||||||
|
annotations: {}
|
||||||
|
name: "affine-web"
|
||||||
|
|
||||||
|
podAnnotations: {}
|
||||||
|
|
||||||
|
podSecurityContext:
|
||||||
|
fsGroup: 2000
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu: '500m'
|
||||||
|
memory: 2Gi
|
||||||
|
requests:
|
||||||
|
cpu: '500m'
|
||||||
|
memory: 2Gi
|
||||||
|
|
||||||
|
nodeSelector: {}
|
||||||
|
|
||||||
|
tolerations: []
|
||||||
|
|
||||||
|
affinity: {}
|
||||||
|
|
||||||
|
probe:
|
||||||
|
initialDelaySeconds: 1
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user