# Default values for spiffe-oidc-discovery-provider. # This is a YAML-formatted file. # Declare variables to be passed into your templates. # @ignored global: {} # -- The name of the spire-agent unix socket agentSocketName: spire-agent.sock replicaCount: 1 namespaceOverride: "" image: # -- The OCI registry to pull the image from registry: ghcr.io # -- The repository within the registry repository: spiffe/oidc-discovery-provider # -- The image pull policy pullPolicy: IfNotPresent # -- This value is deprecated in favor of tag. (Will be removed in a future release) version: "" # -- Overrides the image tag whose default is the chart appVersion tag: "" resources: {} # We usually recommend not to specify default resources and to leave this as a conscious # choice for the user. This also increases chances charts run on environments with little # resources, such as Minikube. If you do want to specify resources, uncomment the following # lines, adjust them as necessary, and remove the curly braces after 'resources:'. # requests: # cpu: 50m # memory: 32Mi # limits: # cpu: 100m # memory: 64Mi service: type: ClusterIP port: 80 annotations: {} # external-dns.alpha.kubernetes.io/hostname: oidc-discovery.example.org configMap: # -- Annotations to add to the SPIFFE OIDC Discovery Provider ConfigMap annotations: {} podSecurityContext: {} # fsGroup: 2000 securityContext: {} # capabilities: # drop: # - ALL # readOnlyRootFilesystem: true # runAsNonRoot: true # runAsUser: 1000 readinessProbe: # -- Initial delay seconds for readinessProbe initialDelaySeconds: 5 # -- Period seconds for readinessProbe periodSeconds: 5 livenessProbe: # -- Initial delay seconds for livenessProbe initialDelaySeconds: 5 # -- Period seconds for livenessProbe periodSeconds: 5 podAnnotations: {} insecureScheme: enabled: false nginx: image: # -- The OCI registry to pull the image from registry: docker.io # -- The repository within the registry repository: nginxinc/nginx-unprivileged # -- The image pull policy pullPolicy: IfNotPresent # -- This value is deprecated in favor of tag. (Will be removed in a future release) version: "" # -- Overrides the image tag tag: 1.24.0-alpine # chainguard image does not support the templates feature # https://github.com/chainguard-images/nginx/issues/43 # registry: cgr.dev # repository: chainguard/nginx # pullPolicy: IfNotPresent # tag: "1.23.2" resources: {} # We usually recommend not to specify default resources and to leave this as a conscious # choice for the user. This also increases chances charts run on environments with little # resources, such as Minikube. If you do want to specify resources, uncomment the following # lines, adjust them as necessary, and remove the curly braces after 'resources:'. # requests: # cpu: 50m # memory: 32Mi # limits: # cpu: 100m # memory: 64Mi config: # -- The log level, valid values are "debug", "info", "warn", and "error" logLevel: info domains: - localhost - oidc-discovery.example.org acme: tosAccepted: false cacheDir: /run/spire directoryUrl: https://acme-v02.api.letsencrypt.org/directory emailAddress: letsencrypt@example.org imagePullSecrets: [] nameOverride: "" fullnameOverride: "" serviceAccount: # -- Specifies whether a service account should be created create: true # -- Annotations to add to the service account annotations: {} # -- The name of the service account to use. # If not set and create is true, a name is generated using the fullname template name: "" autoscaling: enabled: false minReplicas: 1 maxReplicas: 5 targetCPUUtilizationPercentage: 80 targetMemoryUtilizationPercentage: 80 nodeSelector: {} tolerations: [] affinity: {} # -- Set the trust domain to be used for the SPIFFE identifiers trustDomain: example.org # -- The name of the Kubernetes cluster (`kubeadm init --service-dns-domain`) clusterDomain: cluster.local telemetry: prometheus: enabled: false port: 9988 podMonitor: enabled: false # -- Override where to install the podMonitor, if not set will use the same namespace as the spiffe-oidc-discovery-provider namespace: "" labels: {} nginxExporter: image: # -- The OCI registry to pull the image from registry: docker.io # -- The repository within the registry repository: nginx/nginx-prometheus-exporter # -- The image pull policy pullPolicy: IfNotPresent # -- This value is deprecated in favor of tag. (Will be removed in a future release) version: "" # -- Overrides the image tag tag: "0.11.0" resources: {} # We usually recommend not to specify default resources and to leave this as a conscious # choice for the user. This also increases chances charts run on environments with little # resources, such as Minikube. If you do want to specify resources, uncomment the following # lines, adjust them as necessary, and remove the curly braces after 'resources:'. # requests: # cpu: 50m # memory: 32Mi # limits: # cpu: 100m # memory: 64Mi ingress: enabled: false className: "" annotations: {} # kubernetes.io/ingress.class: nginx # kubernetes.io/tls-acme: "true" # nginx.ingress.kubernetes.io/ssl-redirect: "true" # nginx.ingress.kubernetes.io/force-ssl-redirect: "true" hosts: - host: oidc-discovery.example.org paths: - path: / pathType: Prefix tls: [] # - secretName: chart-example-tls # hosts: # - oidc-discovery.example.org # @ignored tests: bash: image: # -- The OCI registry to pull the tests image from registry: cgr.dev # -- The repository within the registry repository: chainguard/bash # -- The tests image pull policy pullPolicy: IfNotPresent # -- This value is deprecated in favor of tag. (Will be removed in a future release) version: "" # -- Overrides the image tag tag: 5.2.15