Configure this chart with External Gitaly

This document intends to provide documentation on how to configure this Helm chart with an external Gitaly service.

If you don’t have Gitaly configured, for on-premise or deployment to VM, consider using our Omnibus GitLab package.

Configure the Chart

Disable the gitaly chart and the Gitaly service it provides, and point the other services to the external service.

You need to set the following parameters:

  • global.gitaly.enabled: Set to false to disable the included Gitaly chart.
  • Set to the hostname of the external Gitaly, can be a domain or an IP address.
  • global.gitaly.authToken.secret: The name of the secret which contains the token for authentication.
  • global.gitaly.authToken.key: The key within the secret, which contains the token content.
  • The name of the secret which contains secret for GitLab Shell.
  • The key within the secret, which contains the secret content.

Items below can be further customized if you are not using the defaults:

  • global.gitaly.port: The port the service is available on, defaults to 8075
helm install .  \
  --set global.gitaly.enabled=false \
  --set \
  --set global.gitaly.authToken.secret=gitaly-secret \
  --set global.gitaly.authToken.key=token

Multiple external Gitaly

If your implementation uses multiple Gitaly nodes external to these charts, you can define multiple hosts as well. The syntax is slightly different, as to allow the complexity required.

An example values file is provided, which shows the appropriate set of configuration. The content of this values file is not interpreted correctly via --set arguments, so should be passed to Helm with the -f / --values flag.

Connecting to external Gitaly over TLS

If your external Gitaly server listens over TLS port, you can make your GitLab instance communicate with it over TLS. To do this, you have to

  1. Create a Kubernetes secret containing the certificate of the Gitaly server

    kubectl create secret generic gitlab-gitaly-tls-certificate --from-file=gitaly-tls.crt=<path to certificate>
  2. Add the certificate of external Gitaly server to the list of custom Certificate Authorities In the values file, specify the following

          - secret: gitlab-gitaly-tls-certificate

    or pass it to the helm upgrade command using --set

    --set global.certificates.customCAs[0].secret=gitlab-gitaly-tls-certificate
  3. Enable Gitaly TLS by setting global.gitaly.tls.enabled=true

Note: You can choose any valid secret name and key for this, but make sure the key is unique across all the secrets specified in customCAs to avoid collision since all keys within the secrets will be mounted. You do not need to provide the key for the certificate, as this is the client side.