{{- $NOTICE := "\n=== NOTICE" -}}
{{- $WARNING := "\n=== WARNING" -}}

{{/* PostgreSQL minimum version change */}}
{{ $NOTICE }}
The minimum required version of PostgreSQL is now 13. See https://gitlab.com/gitlab-org/charts/gitlab/-/blob/master/doc/installation/upgrade.md for more details.

{{- /* If the Container Registry metadata database is enabled, note it is not production ready */}}
{{- if eq .Values.registry.database.enabled true }}
{{ $WARNING }}
The Container Registry metadata database has been enabled. Please note that it is an experimental feature and must not be used in production.
{{- end }}

{{- /* If the Container Registry online garbage collection is enabled, note it is not production ready */}}
{{- if eq false .Values.registry.gc.disabled }}
{{ $WARNING }}
The Container Registry online garbage collection has been enabled. Please note that it is an experimental feature and must not be used in production.
{{- end }}

{{- /* If Praefect enabled, note it is not production ready */}}
{{- if eq .Values.global.praefect.enabled true }}
{{ $WARNING }}
The Praefect chart has been enabled. Please note that it is still under development and not ready for production use. Usage may require significant manual intervention during upgrades.
{{- end }}

{{- /* If shared-secrets is disable, manual secret creation will be needed */}}
{{- if not (index .Values "shared-secrets").enabled }}
{{ $NOTICE }}
The automatic generation of secrets has been disabled.
The user should ensure all necessary secrets are created according to documentation, or the deployment will fail to operate correctly.
{{- end }}
{{- /* If using self-signed auto-generated certificates, and a service needing them is enabled */}}
{{- if or .Values.gitlab.webservice.enabled .Values.registry.enabled .Values.global.minio.enabled }}
{{-   if not (or .Values.global.ingress.configureCertmanager (include "gitlab.ingress.tls.configured" .)) }}
{{ $WARNING }}
Automatic TLS certificate generation with cert-manager is disabled.
One or more of the components does not have a TLS certificate Secret configured.
As a result, Self-signed certificates were generated for these components.

You may retrieve the CA root for these certificates from the `{{ template "gitlab.wildcard-self-signed-cert-name" $ }}-ca` secret, via the following command. It can then be imported to a web browser or system store.

  kubectl get secret {{ template "gitlab.wildcard-self-signed-cert-name" $ }}-ca -ojsonpath='{.data.cfssl_ca}' | base64 --decode > {{ template "gitlab.gitlab.hostname" $ }}.ca.pem

If you do not wish to use self-signed certificates, please set the following properties:
- global.ingress.tls.secretName
OR all of:
- global.ingress.tls.enabled (set to `true`)
{{- if $.Values.gitlab.webservice.enabled }}
- gitlab.webservice.ingress.tls.secretName
{{- if $.Values.global.appConfig.smartcard.enabled }}
- gitlab.webservice.ingress.tls.smartcardSecretName
{{- end }}
{{- end }}
{{- if $.Values.registry.enabled }}
- registry.ingress.tls.secretName
{{- end }}
{{- if $.Values.global.minio.enabled }}
- minio.ingress.tls.secretName
{{- end }}
{{- if $.Values.global.pages.enabled }}
- gitlab.gitlab-pages.ingress.tls.secretName
{{- end }}
{{- if $.Values.global.kas.enabled }}
- gitlab.kas.ingress.tls.secretName
{{- end }}

{{- if (index .Values "gitlab-runner").install }}
{{ $WARNING }}
Automatic TLS certificate generation with cert-manager is disabled and no TLS certificates were provided. Self-signed certificates were generated that do not work with gitlab-runner. Please either disable gitlab-runner by setting `gitlab-runner.install=false` or provide valid certificates.
{{- end -}}
{{- end -}}
{{- end -}}
{{- /* Runner notice if .install && ! .runners.privileged */}}
{{- if and (index .Values "gitlab-runner").install (not (index .Values "gitlab-runner").runners.privileged) }}
{{ $NOTICE }}
You've installed GitLab Runner without the ability to use 'docker in docker'.
The GitLab Runner chart (gitlab/gitlab-runner) is deployed without the `privileged` flag by default for security purposes. This can be changed by setting `gitlab-runner.runners.privileged` to `true`. Before doing so, please read the GitLab Runner chart's documentation on why we
chose not to enable this by default. See https://docs.gitlab.com/runner/install/kubernetes.html#running-docker-in-docker-containers-with-gitlab-runners
{{- end }}

{{- /* toolbox replicas */}}
{{- if eq (index $.Values.gitlab "toolbox" "replicas" | int) 0 }}
{{ $NOTICE }}
The GitLab toolbox is scaled to 0.
The `toolbox` Pod is very useful for administration and debugging of this application suite. You may configure `gitlab.toolbox.replicas=1` if you wish to leave a Pod running at all times, or you can scale the deployment up when needed:

    `kubectl scale --replicas=1 deployment/{{ .Release.Name }}-toolbox`
{{- end }}

{{- /* WARN: global.registry.notificationSecret */}}
{{- if and (not (index .Values "shared-secrets" "enabled")) (not .Values.global.registry.notificationSecret) }}
{{ $WARNING }}
The attribute `shared-secrets.enabled` is `false`, no `global.registry.notificationSecret` provided.
The shared-secrets chart has been disabled, and `global.registry.notificationSecret` has not been provided.
Starting in 4.11.x of this chart, this secret must be present, but shared-secrets will not be run to generated it.
Please see https://docs.gitlab.com/charts/charts/globals#configure-registry-settings
{{- end }}
{{- /* print install survey link */}}
{{- $appVersion := coalesce .Values.global.gitlabVersion .Chart.AppVersion -}}
{{- if and .Release.IsInstall (regexMatch "^\\d+\\.\\d+\\.\\d+(-rc\\d+)?(-pre)?$" $appVersion) }}
Help us improve the installation experience, let us know how we did with a 1 minute survey:
{{- printf "https://gitlab.fra1.qualtrics.com/jfe/form/SV_6kVqZANThUQ1bZb?installation=helm&release=%s" (regexReplaceAll "^(\\d+)\\.(\\d+)\\..+" $appVersion "${1}-${2}") }}
{{- end }}

{{- /* WARN: Usage of PAGES_UPDATE_LEGACY_STORAGE with bundled Pages discouraged.*/}}
{{- if .Values.global.pages.enabled }}
{{-   $envValues := dict }}
{{-   $_ := set $envValues "gitlab.webservice" (default false .Values.gitlab.webservice.extraEnv.PAGES_UPDATE_LEGACY_STORAGE) }}
{{-   $_ := set $envValues "gitlab.sidekiq" (default false .Values.gitlab.sidekiq.extraEnv.PAGES_UPDATE_LEGACY_STORAGE) }}
{{-   $_ := set $envValues "global" (default false .Values.global.extraEnv.PAGES_UPDATE_LEGACY_STORAGE) }}
{{-   $toolboxExtraEnv := index .Values.gitlab "toolbox" "extraEnv" }}
{{-   $_ := set $envValues "gitlab.toolbox" (default false $toolboxExtraEnv.PAGES_UPDATE_LEGACY_STORAGE) }}
{{-   range $component, $value := $envValues }}
{{-     if eq $value true }}
{{ $WARNING }}
GitLab Pages configured to use disk storage via `{{ $component }}.extraEnv.PAGES_UPDATE_LEGACY_STORAGE`.
Using `PAGES_UPDATE_LEGACY_STORAGE` environment variable with bundled Pages service is not recommended. This setting is specifically used when using an external GitLab Pages deployment.
{{-     end }}
{{-   end }}
{{- end }}

{{- /* In-chart NGINX Ingress Controller notices */}}
{{- if eq true (index $.Values "nginx-ingress").enabled }}
{{ $NOTICE }}
The in-chart NGINX Ingress Controller has the following requirements:
    - Kubernetes version must be 1.20 or newer (unless NGINX version is set
      to v1.2.1 via `nginx-ingress.controller.image.tag=v1.2.1`, which will
      restore Kubernetes 1.19 compatibility).
    - Ingress objects must be in group/version `networking.k8s.io/v1`.
{{- end }}

{{- /* Deprecation notice for `gitlab.deprecate.kas.privateApi.tls.enabled` setting */}}
{{- if eq true $.Values.gitlab.kas.privateApi.tls.enabled }}
{{ $NOTICE }}
kas:
    The configuration of `gitlab.kas.privateApi.tls.enabled` has moved. Please use `global.kas.tls.enabled` instead.
    Other components of the GitLab chart other than KAS also need to be configured to talk to KAS via TLS.
    With a global value the chart can take care of these configurations without the need for other specific values.
{{- end }}

{{- /* Deprecation notice for `gitlab.deprecate.kas.privateApi.tls.secretName` setting */}}
{{- if hasKey $.Values.gitlab.kas.privateApi.tls "secretName" }}
{{ $NOTICE }}
kas:
    The configuration of `gitlab.kas.privateApi.tls.secretName` has moved. Please use `global.kas.tls.secretName` instead.
    Other components of the GitLab chart other than KAS also need to be configured to talk to KAS via TLS.
    With a global value the chart can take care of these configurations without the need for other specific values.
{{- end }}

{{- /* Deprecation notice for `gitlab.deprecate.sidekiq.queueSelector` setting */}}
{{- if and (hasKey .Values.gitlab.sidekiq "queueSelector") (eq true .Values.gitlab.sidekiq.queueSelector) -}}
{{ $NOTICE }}
sidekiq:
    The configuration of 'gitlab.sidekiq.queueSelector' should be removed. Please follow the steps at https://docs.gitlab.com/ee/administration/sidekiq/extra_sidekiq_processes.html#start-multiple-processes, to run Sidekiq with multiple processes while listening to all queues.
{{- end }}

{{- /* Deprecation notice for `gitlab.deprecate.sidekiq.pods.queueSelector` setting */}}
{{- range $index, $pod := .Values.gitlab.sidekiq.pods -}}
{{-   if and (hasKey $pod "queueSelector") -}}
{{ $NOTICE }}
sidekiq.pods[{{ $index }}] ({{ $pod.name }}):
    The configuration of 'gitlab.sidekiq.pods[{{ $index }}].queueSelector' should be removed. Please follow the steps at https://docs.gitlab.com/ee/administration/sidekiq/extra_sidekiq_processes.html#start-multiple-processes, to run Sidekiq with multiple processes while listening to all queues.
{{-   end -}}
{{- end }}

{{- /* Deprecation notice for `gitlab.deprecate.sidekiq.negateQueues` setting */}}
{{- if hasKey .Values.gitlab.sidekiq "negateQueues" -}}
{{ $NOTICE }}
sidekiq:
    The configuration of 'gitlab.sidekiq.negateQueues' should be removed. Please follow the steps at https://docs.gitlab.com/ee/administration/sidekiq/extra_sidekiq_processes.html#start-multiple-processes, to run Sidekiq with multiple processes while listening to all queues.
{{- end }}

{{- /* Deprecation notice for `gitlab.deprecate.sidekiq.pods.negateQueues` setting */}}
{{- range $index, $pod := .Values.gitlab.sidekiq.pods -}}
{{-   if hasKey $pod "negateQueues" -}}
{{ $NOTICE }}
sidekiq.pods[{{ $index }}] ({{ $pod.name }}):
    The configuration of 'gitlab.sidekiq.pods[{{ $index }}].negateQueues' should be removed. Please follow the steps at https://docs.gitlab.com/ee/administration/sidekiq/extra_sidekiq_processes.html#start-multiple-processes, to run Sidekiq with multiple processes while listening to all queues.
{{-   end -}}
{{- end }}

{{- /* Deprecation notice for global.redis.password */}}
{{- if kindIs "map" .Values.global.redis.password }}
{{ $NOTICE }}
redis:
    The configuration key `global.redis.password` has been renamed. Please use
    `globa.redis.auth` instead. This is the source of the `coalesce.go` warning
    message from Helm as well. For more details, please see:
    https://docs.gitlab.com/charts/installation/upgrade.html#use-of-globalredispassword
{{- end -}}

{{- /* Deprecation notice for global.busybox */}}
{{- if hasKey .Values.global "busybox" }}
{{ $NOTICE }}
global.busybox:
    The configuration key `global.busybox` is deprecated in favor of `global.gitlabBase`.
    For more details, please see:
    https://docs.gitlab.com/charts/charts/globals#gitlab-base-image
{{- end -}}

{{- /* run deprecations */}}
{{ include "gitlab.deprecations" . }}
{{- /* run checkConfig */}}
{{ include "gitlab.checkConfig" . }}
