Move spire-server to dedicated subchart
Signed-off-by: Marco Franssen <[email protected]> Signed-off-by: Marco Franssen <[email protected]>
This commit is contained in:
@@ -12,84 +12,13 @@ waitForIt:
|
||||
k8s-workload-registrar:
|
||||
enabled: true
|
||||
|
||||
server:
|
||||
replicaCount: 1
|
||||
image:
|
||||
# registry: gcr.io
|
||||
# repository: spiffe-io/spire-server
|
||||
registry: ghcr.io
|
||||
repository: spiffe/spire-server
|
||||
pullPolicy: IfNotPresent
|
||||
# Overrides the image tag whose default is the chart appVersion.
|
||||
version: ""
|
||||
|
||||
nodeSelector:
|
||||
kubernetes.io/arch: amd64
|
||||
|
||||
resources: {}
|
||||
# We usually recommend not to specify default resources and to leave this as a conscious
|
||||
# choice for the user. This also increases chances charts run on environments with little
|
||||
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
||||
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
||||
# requests:
|
||||
# cpu: 200m
|
||||
# memory: 256Mi
|
||||
# limits:
|
||||
# cpu: 200m
|
||||
# memory: 256Mi
|
||||
|
||||
dataStorage:
|
||||
enabled: true
|
||||
size: 1Gi
|
||||
accessMode: ReadWriteOnce
|
||||
storageClass: null
|
||||
|
||||
service:
|
||||
type: ClusterIP
|
||||
port: 8081
|
||||
annotations: {}
|
||||
|
||||
podAnnotations: {}
|
||||
|
||||
podSecurityContext: {}
|
||||
# fsGroup: 2000
|
||||
|
||||
securityContext: {}
|
||||
# capabilities:
|
||||
# drop:
|
||||
# - ALL
|
||||
# readOnlyRootFilesystem: true
|
||||
# runAsNonRoot: true
|
||||
# runAsUser: 1000
|
||||
|
||||
topologySpreadConstraints: []
|
||||
|
||||
config:
|
||||
logLevel: info
|
||||
socketPath: /run/spire/server-sockets/spire-server.sock
|
||||
jwtIssuer: oidc-discovery.example.org
|
||||
|
||||
ca_subject:
|
||||
country: NL
|
||||
organization: Example
|
||||
common_name: example.org
|
||||
|
||||
upstreamAuthority:
|
||||
disk:
|
||||
enabled: false
|
||||
secret:
|
||||
# -- If disabled requires you to create a secret with the given keys (certificate, key and optional bundle) yourself.
|
||||
create: true
|
||||
# -- If secret creation is disabled, the secret with this name will be used.
|
||||
name: "spiffe-upstream-ca"
|
||||
# -- If secret creation is enabled, will create a secret with following certificate info
|
||||
data:
|
||||
certificate: ""
|
||||
key: ""
|
||||
bundle: ""
|
||||
spire-server:
|
||||
nameOverride: server
|
||||
bundleConfigMap: &bundleConfigMap spire-bundle
|
||||
|
||||
spire-agent:
|
||||
nameOverride: agent
|
||||
bundleConfigMap: *bundleConfigMap
|
||||
|
||||
spiffe-oidc-discovery-provider:
|
||||
enabled: false
|
||||
|
||||
Reference in New Issue
Block a user