• v0.2.0 375b5ed2f7

    v0.2.0 — customize the pod TerdutServer runs in, and stop promising ingress
    CI / chart (push) Successful in 1s
    CI / security (push) Successful in 57s
    CI / test (push) Successful in 2m13s
    Release / test (push) Successful in 1m41s
    Release / chart (push) Successful in 2s
    Release / image (push) Successful in 6m10s
    Release / scan-image (push) Successful in 3s

    niklas released this 2026-10-02 16:53:47 +00:00

    TerdutServer.spec.pod lets you set pod annotations, nodeSelector,
    tolerations, affinity (node and pod, including anti-affinity),
    topologySpreadConstraints, resources, pod and container securityContext,
    serviceAccountName, extra env vars/envFrom, extra volumes/volumeMounts,
    imagePullSecrets, and an optional PodDisruptionBudget. All of it is a
    direct pass-through of the matching corev1 type, the same shape
    CloudNativePG and the Zalando postgres-operator use for the same knobs.
    affinity never gets a controller-generated default: this operator never
    spreads replicas of its own, since more than one replica isn't a
    supported topology (the sweeper/notifier singleton constraint). Not
    included, on purpose: priorityClassName, pod labels beyond annotations,
    and a HorizontalPodAutoscaler — the last of those would contradict that
    same constraint.

    Separately: spec.networking no longer carries any promise, implicit or
    explicit, that this operator will one day create a Gateway API HTTPRoute
    for a TerdutServer. That was always unimplemented, and is now an explicit,
    permanent non-goal (DESIGN.md §1) instead of a "near-term follow-up" —
    this operator creates a plain ClusterIP Service and stops there. The dead
    gatewayListener field (it never did anything — setting it had zero
    effect) is removed from the CRD; existing manifests that still set it
    will simply have it pruned on apply, nothing breaks. hostname and
    servicePort are unchanged and still required: hostname feeds
    terdut-server's own TERDUT_PUBLIC_URL (notifications, OIDC redirect
    URIs), servicePort is still the container and Service port — neither
    was ever about ingress. New examples/networking/ shows how to expose the
    Service the operator already creates, with a Gateway API HTTPRoute or an
    Istio VirtualService — illustrations to copy and adapt, not something any
    part of this operator applies for you.

    Requires no particular terdut-server version — both changes are
    CRD/controller-only, nothing about the bootstrap API this operator
    depends on changed. Nothing about replica count, RBAC scope (beyond the
    one new poddisruptionbudgets rule), or the chart's installer-only stance
    changed either.

    Downloads