global: openshift: true telemetry: prometheus: enabled: true spire-server: tornjak: image: registry: ghcr.io repository: spiffe/tornjak-backend tag: ubi-v1.4.1 nodeAttestor: k8sPsat: serviceAccountAllowList: ["spire-system:spire-agent"] notifier: k8sbundle: namespace: spire-system podSecurityContext: # These are unset so that openshift can automatically assign its own restricted uids to the pods runAsUser: null runAsGroup: null fsGroup: null spire-agent: podSecurityContext: runAsUser: null runAsGroup: null fsGroup: null upstream-spire-agent: podSecurityContext: runAsUser: null runAsGroup: null fsGroup: null spiffe-oidc-discovery-provider: podSecurityContext: runAsUser: null runAsGroup: null fsGroup: null tornjak-frontend: workingDir: /opt/app-root/src image: registry: ghcr.io repository: spiffe/tornjak-frontend tag: ubi-v1.4.1 podSecurityContext: runAsUser: null runAsGroup: null fsGroup: null spiffe-csi-driver: initContainers: - terminationMessagePath: /dev/termination-log name: set-context command: - chcon - '-Rvt' - container_file_t - spire-agent-socket/ securityContext: capabilities: drop: - all privileged: true imagePullPolicy: Always volumeMounts: - name: spire-agent-socket-dir mountPath: /spire-agent-socket terminationMessagePolicy: File image: 'registry.access.redhat.com/ubi9:latest'