RagLeap
ragleap-app-chart · release notes

ragleap-app-chart v0.1.0

First public release. Generic, reusable Helm chart for deploying arbitrary services to Kubernetes — not RagLeap-specific. Point it at your own app.

Fixed

First live cluster deploy (helm install against a real kind cluster) found 2 real bugs in the default example config, neither previously caught by helm lint/helm template alone:

  1. defaultSecurityContext's runAsNonRoot: true had no accompanying runAsUser — rejected postgres:16 outright, same class of bug found and fixed in ragleap-ops the same day (confirmed via docker run --rm postgres:16 id postgres — UID 999, not assumed). Fixed generically: added an opt-in per-service initChown flag in deployment.yaml that renders a one-time root fix-permissions init container using the service's own declared securityContext.runAsUser — not hardcoded to any specific UID, since this chart is not RagLeap-specific and different services will need different UIDs.
  2. The chart hardcodes /data as the mount path for any persistent: true service. postgres's official image defaults to /var/lib/postgresql/data, not /data — without an explicit PGDATA override, postgres would have initialized on the container's ephemeral filesystem, silently NOT persisting to the actual PVC. Real, generic risk for any persistent service whose image doesn't default to /data.

Verified

  • Full helm install against a real local kind cluster, using the chart's own default example services: list (web + postgres) — the genericity proof the design proposal requires ("proven against a non-RagLeap toy app"). After the fixes above: postgres reached 1/1 Running, 0 restarts sustained. Data persistence independently confirmed via SHOW data_directory; → /data/pgdata, not just pod status.
  • Existing NetworkPolicy/PVC/resources/securityContext override logic (previously only template-verified) now proven against real deployed resources.

Known limitations

  • The hardcoded /data mount path is a real generic risk — any persistent service whose image doesn't default its data directory to /data needs an explicit env override.
  • initChown requires the service to also declare its own securityContext.runAsUser — mismatched config isn't validated by the chart yet, would fail at apply-time.

Install: pip install ragleap-app-chart
Docs: https://packages.ragleap.com/docs/ragleap-app-chart.html

View on GitHub Package page All releases

Release notes mirrored from GitHub Releases.