First public release. Generic, reusable Helm chart for deploying arbitrary services to Kubernetes — not RagLeap-specific. Point it at your own app.
Fixed
First live cluster deploy (helm install against a real kind cluster) found 2 real bugs in the default example config, neither previously caught by helm lint/helm template alone:
defaultSecurityContext'srunAsNonRoot: truehad no accompanyingrunAsUser— rejectedpostgres:16outright, same class of bug found and fixed inragleap-opsthe same day (confirmed viadocker run --rm postgres:16 id postgres— UID 999, not assumed). Fixed generically: added an opt-in per-serviceinitChownflag indeployment.yamlthat renders a one-time rootfix-permissionsinit container using the service's own declaredsecurityContext.runAsUser— not hardcoded to any specific UID, since this chart is not RagLeap-specific and different services will need different UIDs.- The chart hardcodes
/dataas the mount path for anypersistent: trueservice.postgres's official image defaults to/var/lib/postgresql/data, not/data— without an explicitPGDATAoverride,postgreswould have initialized on the container's ephemeral filesystem, silently NOT persisting to the actual PVC. Real, generic risk for any persistent service whose image doesn't default to/data.
Verified
- Full
helm installagainst a real local kind cluster, using the chart's own default exampleservices:list (web + postgres) — the genericity proof the design proposal requires ("proven against a non-RagLeap toy app"). After the fixes above:postgresreached1/1 Running, 0 restarts sustained. Data persistence independently confirmed viaSHOW data_directory;→/data/pgdata, not just pod status. - Existing NetworkPolicy/PVC/resources/securityContext override logic (previously only template-verified) now proven against real deployed resources.
Known limitations
- The hardcoded
/datamount path is a real generic risk — any persistent service whose image doesn't default its data directory to/dataneeds an explicit env override. initChownrequires the service to also declare its ownsecurityContext.runAsUser— mismatched config isn't validated by the chart yet, would fail at apply-time.
Install: pip install ragleap-app-chart
Docs: https://packages.ragleap.com/docs/ragleap-app-chart.html