# Default values for spire. # This is a YAML-formatted file. # Declare variables to be passed into your templates. replicaCount: 1 workloadRegistrar: image: repository: gcr.io/spiffe-io/k8s-workload-registrar pullPolicy: IfNotPresent # Overrides the image tag whose default is the chart appVersion. tag: "" server: image: repository: gcr.io/spiffe-io/spire-server pullPolicy: IfNotPresent # Overrides the image tag whose default is the chart appVersion. tag: "" dataStorage: enabled: true size: 1Gi accessMode: ReadWriteOnce storageClass: null service: type: NodePort port: 8081 oidc: enabled: false image: repository: gcr.io/spiffe-io/oidc-discovery-provider pullPolicy: IfNotPresent tag: "" logLevel: INFO service: type: NodePort port: 80 ingress: enabled: false domain: "oidc-discovery.example.org" letsEncrypt: emailAddress: letsencrypt@example.org agent: image: repository: gcr.io/spiffe-io/spire-agent pullPolicy: IfNotPresent # Overrides the image tag whose default is the chart appVersion. tag: "" imagePullSecrets: [] # - name: my-docker-registry # username: my-docker-user # password: my-docker-password # registryURL: my-private.docker-registry.com nameOverride: "" fullnameOverride: "" serviceAccount: # Specifies whether a service account should be created create: true # Annotations to add to the service account annotations: {} # The name of the service account to use. # If not set and create is true, a name is generated using the fullname template name: "" podAnnotations: {} podSecurityContext: {} # fsGroup: 2000 securityContext: {} # capabilities: # drop: # - ALL # readOnlyRootFilesystem: true # runAsNonRoot: true # runAsUser: 1000 resources: {} # We usually recommend not to specify default resources and to leave this as a conscious # choice for the user. This also increases chances charts run on environments with little # resources, such as Minikube. If you do want to specify resources, uncomment the following # lines, adjust them as necessary, and remove the curly braces after 'resources:'. # limits: # cpu: 100m # memory: 128Mi # requests: # cpu: 100m # memory: 128Mi autoscaling: enabled: false minReplicas: 1 maxReplicas: 100 targetCPUUtilizationPercentage: 80 # targetMemoryUtilizationPercentage: 80 nodeSelector: {} tolerations: [] affinity: {} # spireSettings spire: clusterName: "example-cluster" trustDomain: "example.org" agent: logLevel: INFO server: logLevel: INFO