GitLabCore configuration

Status: Implemented Issue: none Parent: GitLabCore reconciler

Goal

An administrator configures a working GitLab instance through a few typed fields, and reaches every other chart setting through free-form values. For the chart values each field sets, see Effective values.

Requirements

  • spec.hostname sets the GitLab host, and its parent domain sets the domain of the sibling hosts. An apex hostname is its own domain.
  • spec.edition selects ee or ce, and defaults to ee.
  • spec.license, spec.postgresql, spec.redis, and spec.objectStorage each reference a Secret. No license key, password, or connection is stored in the resource.
  • Setting spec.objectStorage turns the consolidated object storage on.
  • Setting spec.openbao turns on the GitLab Secret Manager and the bundled OpenBao, against a PostgreSQL connection of its own. It creates no ServiceAccount, Role, or RoleBinding.
  • Leaving spec.networking unset turns the Gateway API off.
  • spec.networking accepts at most one of envoyGatewayController, gatewayClass, and gateway. The API server rejects a second one, and a change of envoyGatewayController.controllerName.
  • envoyGatewayController provisions a GatewayClass named after the namespace and name of the resource, so two instances never share one.
  • gatewayClass and gateway provision no GatewayClass, and add the Envoy extensions only when configureEnvoy is set.
  • A certManager.issuerRef points the provisioned Gateway at an existing Issuer or ClusterIssuer.
  • spec.chart.values win over every value a structured field derives.
  • The Operator overrides win over both: no cert-manager, no GitLab Runner, no bundled Ingress, Gateway, or proxy controller, and no chart-provisioned ACME issuer for the Gateway.
  • The container registry is off unless spec.chart.values turn it on.
  • The shared secrets Job runs under the ServiceAccount of the Operator, and creates no RBAC.

Out of scope

  • Provisioning PostgreSQL, Redis, object storage, or the OpenBao database.
  • An Ingress mode in spec.networking.
  • Structured fields for the registry, Pages, or backups.

FAQ

  • Why do the free-form values win over the structured fields? To keep them a working escape hatch. ADR 26 decides it.
  • Why is the Gateway API off when networking is unset? The chart default relies on the bundled Envoy Gateway, which the Operator never installs. For more information, see ADR 33.
  • Which chart version do envoyGatewayController and gatewayClass need? 10.4.0 or later. An older chart renders a Gateway whose GatewayClass never renders, and nothing reports it.
  • Why is the registry off by default? It stores images in object storage of its own, which no structured field covers.
  • Why does an instance without spec.objectStorage fail? The chart enables object storage for artifacts, LFS, uploads, and packages with no connection of its own. Unless the free-form values supply one, its checkConfig fails.