GitLabCore configuration
Status: Implemented Issue: none Parent: GitLabCore reconciler
Goal
An administrator configures a working GitLab instance through a few typed fields, and reaches every other chart setting through free-form values. For the chart values each field sets, see Effective values.
Requirements
spec.hostnamesets the GitLab host, and its parent domain sets the domain of the sibling hosts. An apex hostname is its own domain.spec.editionselectseeorce, and defaults toee.spec.license,spec.postgresql,spec.redis, andspec.objectStorageeach reference a Secret. No license key, password, or connection is stored in the resource.- Setting
spec.objectStorageturns the consolidated object storage on. - Setting
spec.openbaoturns on the GitLab Secret Manager and the bundled OpenBao, against a PostgreSQL connection of its own. It creates no ServiceAccount, Role, or RoleBinding. - Leaving
spec.networkingunset turns the Gateway API off. spec.networkingaccepts at most one ofenvoyGatewayController,gatewayClass, andgateway. The API server rejects a second one, and a change ofenvoyGatewayController.controllerName.envoyGatewayControllerprovisions aGatewayClassnamed after the namespace and name of the resource, so two instances never share one.gatewayClassandgatewayprovision noGatewayClass, and add the Envoy extensions only whenconfigureEnvoyis set.- A
certManager.issuerRefpoints the provisionedGatewayat an existingIssuerorClusterIssuer. spec.chart.valueswin over every value a structured field derives.- The Operator overrides win over both: no cert-manager, no GitLab Runner, no bundled Ingress, Gateway, or proxy controller, and no chart-provisioned ACME issuer for the Gateway.
- The container registry is off unless
spec.chart.valuesturn it on. - The shared secrets
Jobruns under the ServiceAccount of the Operator, and creates no RBAC.
Out of scope
- Provisioning PostgreSQL, Redis, object storage, or the OpenBao database.
- An Ingress mode in
spec.networking. - Structured fields for the registry, Pages, or backups.
FAQ
- Why do the free-form values win over the structured fields? To keep them a working escape hatch. ADR 26 decides it.
- Why is the Gateway API off when networking is unset? The chart default relies on the bundled Envoy Gateway, which the Operator never installs. For more information, see ADR 33.
- Which chart version do
envoyGatewayControllerandgatewayClassneed? 10.4.0 or later. An older chart renders aGatewaywhoseGatewayClassnever renders, and nothing reports it. - Why is the registry off by default? It stores images in object storage of its own, which no structured field covers.
- Why does an instance without
spec.objectStoragefail? The chart enables object storage for artifacts, LFS, uploads, and packages with no connection of its own. Unless the free-form values supply one, itscheckConfigfails.
Was this page helpful?