Add skipKubeletVerification configurable (#243)

This commit is contained in:
Faisal Memon
2023-04-26 21:38:14 +02:00
committed by GitHub
parent 46f10e1df2
commit 3d81928ff8
3 changed files with 5 additions and 1 deletions
@@ -54,6 +54,7 @@ A Helm chart to install the SPIRE agent.
| waitForIt.image.repository | string | `"chainguard/wait-for-it"` | |
| waitForIt.image.version | string | `"latest-20230113"` | |
| waitForIt.resources | object | `{}` | |
| workloadAttestors.k8s.skipKubeletVerification | bool | `true` | If true, kubelet certificate verification is skipped |
| workloadAttestors.unix.enabled | bool | `false` | enables the Unix workload attestor |
----------------------------------------------
@@ -24,7 +24,7 @@ plugins:
# Defaults to the secure kubelet port by default.
# Minikube does not have a cert in the cluster CA bundle that
# can authenticate the kubelet cert, so skip validation.
skip_kubelet_verification: true
skip_kubelet_verification: {{ .Values.workloadAttestors.k8s.skipKubeletVerification }}
{{- if .Values.workloadAttestors.unix.enabled }}
- unix:
@@ -81,6 +81,9 @@ workloadAttestors:
unix:
# -- enables the Unix workload attestor
enabled: false
k8s:
# -- If true, kubelet certificate verification is skipped
skipKubeletVerification: true
telemetry:
prometheus: