Initial spire chart setup
Signed-off-by: Marco Franssen <[email protected]>
This commit is contained in:
@@ -0,0 +1,98 @@
|
||||
# spire
|
||||
|
||||
  
|
||||
|
||||
A Helm chart for deploying spire-server and spire-agent.
|
||||
|
||||
> :warning: Please note this chart requires Projected Service Account Tokens which has to be enabled on your k8s api server.
|
||||
|
||||
To enable Projected Service Account Tokens on Docker for Mac/Windows run the following
|
||||
command to SSH into the Docker Desktop K8s VM.
|
||||
|
||||
```bash
|
||||
docker run -it --privileged --pid=host debian nsenter -t 1 -m -u -n -i sh
|
||||
```
|
||||
|
||||
Then add the following to `/etc/kubernetes/manifests/kube-apiserver.yaml`
|
||||
|
||||
```yaml
|
||||
spec:
|
||||
containers:
|
||||
- command:
|
||||
- kube-apiserver
|
||||
- --api-audiences=api,spire-server
|
||||
- --service-account-issuer=api,spire-agent
|
||||
- --service-account-key-file=/run/config/pki/sa.pub
|
||||
- --service-account-signing-key-file=/run/config/pki/sa.key
|
||||
```
|
||||
|
||||
**Homepage:** <https://github.com/philips-labs/helm-charts/charts/spire>
|
||||
|
||||
## Maintainers
|
||||
|
||||
| Name | Email | Url |
|
||||
| ---- | ------ | --- |
|
||||
| marcofranssen | <marco.franssen@gmail.com> | <https://marcofranssen.nl> |
|
||||
|
||||
## Source Code
|
||||
|
||||
* <https://github.com/philips-labs/helm-charts/charts/spire>
|
||||
|
||||
## Requirements
|
||||
|
||||
Kubernetes: `>=1.19.0-0`
|
||||
|
||||
## Values
|
||||
|
||||
| Key | Type | Default | Description |
|
||||
|-----|------|---------|-------------|
|
||||
| affinity | object | `{}` | |
|
||||
| agent.image.pullPolicy | string | `"IfNotPresent"` | |
|
||||
| agent.image.repository | string | `"gcr.io/spiffe-io/spire-agent"` | |
|
||||
| agent.image.tag | string | `""` | |
|
||||
| autoscaling.enabled | bool | `false` | |
|
||||
| autoscaling.maxReplicas | int | `100` | |
|
||||
| autoscaling.minReplicas | int | `1` | |
|
||||
| autoscaling.targetCPUUtilizationPercentage | int | `80` | |
|
||||
| fullnameOverride | string | `""` | |
|
||||
| imagePullSecrets | list | `[]` | |
|
||||
| nameOverride | string | `""` | |
|
||||
| nodeSelector | object | `{}` | |
|
||||
| oidc.enabled | bool | `false` | |
|
||||
| oidc.image.pullPolicy | string | `"IfNotPresent"` | |
|
||||
| oidc.image.repository | string | `"gcr.io/spiffe-io/oidc-discovery-provider"` | |
|
||||
| oidc.image.tag | string | `""` | |
|
||||
| oidc.ingress.domain | string | `"oidc-discovery.example.org"` | |
|
||||
| oidc.ingress.enabled | bool | `false` | |
|
||||
| oidc.letsEncrypt.emailAddress | string | `"[email protected]"` | |
|
||||
| oidc.logLevel | string | `"INFO"` | |
|
||||
| oidc.service.port | int | `80` | |
|
||||
| oidc.service.type | string | `"NodePort"` | |
|
||||
| podAnnotations | object | `{}` | |
|
||||
| podSecurityContext | object | `{}` | |
|
||||
| replicaCount | int | `1` | |
|
||||
| resources | object | `{}` | |
|
||||
| securityContext | object | `{}` | |
|
||||
| server.dataStorage.accessMode | string | `"ReadWriteOnce"` | |
|
||||
| server.dataStorage.enabled | bool | `true` | |
|
||||
| server.dataStorage.size | string | `"1Gi"` | |
|
||||
| server.dataStorage.storageClass | string | `nil` | |
|
||||
| server.image.pullPolicy | string | `"IfNotPresent"` | |
|
||||
| server.image.repository | string | `"gcr.io/spiffe-io/spire-server"` | |
|
||||
| server.image.tag | string | `""` | |
|
||||
| server.service.port | int | `8081` | |
|
||||
| server.service.type | string | `"NodePort"` | |
|
||||
| serviceAccount.annotations | object | `{}` | |
|
||||
| serviceAccount.create | bool | `true` | |
|
||||
| serviceAccount.name | string | `""` | |
|
||||
| spire.agent.logLevel | string | `"INFO"` | |
|
||||
| spire.clusterName | string | `"example-cluster"` | |
|
||||
| spire.server.logLevel | string | `"INFO"` | |
|
||||
| spire.trustDomain | string | `"example.org"` | |
|
||||
| tolerations | list | `[]` | |
|
||||
| workloadRegistrar.image.pullPolicy | string | `"IfNotPresent"` | |
|
||||
| workloadRegistrar.image.repository | string | `"gcr.io/spiffe-io/k8s-workload-registrar"` | |
|
||||
| workloadRegistrar.image.tag | string | `""` | |
|
||||
|
||||
----------------------------------------------
|
||||
Autogenerated from chart metadata using [helm-docs v1.11.0](https://github.com/norwoodj/helm-docs/releases/v1.11.0)
|
||||
Reference in New Issue
Block a user