Move spire-server to dedicated subchart

Signed-off-by: Marco Franssen <[email protected]>
Signed-off-by: Marco Franssen <[email protected]>
This commit is contained in:
Marco Franssen
2023-02-18 13:04:10 +01:00
committed by Marco Franssen
parent e312d42350
commit ce9b58e725
24 changed files with 430 additions and 252 deletions
+4 -75
View File
@@ -12,84 +12,13 @@ waitForIt:
k8s-workload-registrar:
enabled: true
server:
replicaCount: 1
image:
# registry: gcr.io
# repository: spiffe-io/spire-server
registry: ghcr.io
repository: spiffe/spire-server
pullPolicy: IfNotPresent
# Overrides the image tag whose default is the chart appVersion.
version: ""
nodeSelector:
kubernetes.io/arch: amd64
resources: {}
# We usually recommend not to specify default resources and to leave this as a conscious
# choice for the user. This also increases chances charts run on environments with little
# resources, such as Minikube. If you do want to specify resources, uncomment the following
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
# requests:
# cpu: 200m
# memory: 256Mi
# limits:
# cpu: 200m
# memory: 256Mi
dataStorage:
enabled: true
size: 1Gi
accessMode: ReadWriteOnce
storageClass: null
service:
type: ClusterIP
port: 8081
annotations: {}
podAnnotations: {}
podSecurityContext: {}
# fsGroup: 2000
securityContext: {}
# capabilities:
# drop:
# - ALL
# readOnlyRootFilesystem: true
# runAsNonRoot: true
# runAsUser: 1000
topologySpreadConstraints: []
config:
logLevel: info
socketPath: /run/spire/server-sockets/spire-server.sock
jwtIssuer: oidc-discovery.example.org
ca_subject:
country: NL
organization: Example
common_name: example.org
upstreamAuthority:
disk:
enabled: false
secret:
# -- If disabled requires you to create a secret with the given keys (certificate, key and optional bundle) yourself.
create: true
# -- If secret creation is disabled, the secret with this name will be used.
name: "spiffe-upstream-ca"
# -- If secret creation is enabled, will create a secret with following certificate info
data:
certificate: ""
key: ""
bundle: ""
spire-server:
nameOverride: server
bundleConfigMap: &bundleConfigMap spire-bundle
spire-agent:
nameOverride: agent
bundleConfigMap: *bundleConfigMap
spiffe-oidc-discovery-provider:
enabled: false