Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
@amplication/plugin-deployment-helm-chart
Advanced tools
Adds a helm chart for the generated service.
Adds a helm chart for the generated service which can be used for deployment of the application within a Kubernetes cluster.
The root_level
setting determines whether the directory for the helm charts is placed at the root of the repository or in the base directory of the service.
The directory_name
setting determines what the sub-directory for the helm chart in the root level or service base directory is called.
For both the server
and the admin_ui
additional configuration can be provided to further customize the helm charts to be able to deploy them quicker. As these are the options that are specific to each deployment other than additional Kubernetes objects.
Note: If no configuration is provided the .amplicationrc.json file will use be used as the default values for the code generation as the helm chart would otherwise break - making templating/rendering impossible.
{
"root_level": false,
"directory_name": "helm",
"server": {
"chart_version": "0.0.1",
"application_version": "0.0.1",
"repository": "ghcr.io/NAMESPACE/IMAGE_NAME",
"tag": "latest",
"host": "server.example.com",
"port": "3000"
},
"admin_ui": {
"enabled": false,
"chart_version": "0.0.1",
"application_version": "0.0.1",
"repository": "ghcr.io/NAMESPACE/IMAGE_NAME",
"tag": "latest",
"host": "admin.example.com",
"port": "8080"
}
}
As this is an addition to the code base, where non of the other code is touched, using the plugin won't impact the final build.
Note: everything that is in the environments variable file for the service is moved to the configmap part of the helm chart, it would be adviced to move secret related configuration to the secrets object and preferably not have the secrets stored in the generated code at all (as this is implementation specific the decision was made to add everything to the configmap).
Note: as this plugin uses the environment variables provided to the service it is advised to use this plugin as the last plugin in the plugin order, so that it can take advantage of possible variables generated by a previous plugin.
FAQs
Add helm chart for deployment of the service
The npm package @amplication/plugin-deployment-helm-chart receives a total of 8,817 weekly downloads. As such, @amplication/plugin-deployment-helm-chart popularity was classified as popular.
We found that @amplication/plugin-deployment-helm-chart demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 8 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.