Files
helm-charts-hardened/charts/spire/values.yaml
T
Marco Franssen 0b6198cf7c Fix loglevel values
Signed-off-by: Marco Franssen <[email protected]>
2023-02-18 13:04:04 +01:00

233 lines
6.1 KiB
YAML

# Default values for spire.
# This is a YAML-formatted file.
# Declare variables to be passed into your templates.
replicaCount: 1
waitForIt:
image:
registry: gcr.io
repository: spiffe-io/wait-for-it
pullPolicy: IfNotPresent
version: ""
workloadRegistrar:
image:
registry: gcr.io
repository: spiffe-io/k8s-workload-registrar
pullPolicy: IfNotPresent
# Overrides the image tag whose default is the chart appVersion.
version: ""
resources: {}
# We usually recommend not to specify default resources and to leave this as a conscious
# choice for the user. This also increases chances charts run on environments with little
# resources, such as Minikube. If you do want to specify resources, uncomment the following
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
# requests:
# cpu: 50m
# memory: 32Mi
# limits:
# cpu: 100m
# memory: 64Mi
server:
image:
registry: ghcr.io
repository: spiffe/spire-server
pullPolicy: IfNotPresent
# Overrides the image tag whose default is the chart appVersion.
version: ""
nodeSelector:
kubernetes.io/arch: amd64
resources: {}
# We usually recommend not to specify default resources and to leave this as a conscious
# choice for the user. This also increases chances charts run on environments with little
# resources, such as Minikube. If you do want to specify resources, uncomment the following
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
# requests:
# cpu: 200m
# memory: 256Mi
# limits:
# cpu: 200m
# memory: 256Mi
dataStorage:
enabled: true
size: 1Gi
accessMode: ReadWriteOnce
storageClass: null
service:
type: ClusterIP
port: 8081
csiDriver:
image:
registry: ghcr.io
repository: spiffe/spiffe-csi-driver
pullPolicy: IfNotPresent
version: 0.2.0
resources: {}
# We usually recommend not to specify default resources and to leave this as a conscious
# choice for the user. This also increases chances charts run on environments with little
# resources, such as Minikube. If you do want to specify resources, uncomment the following
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
# requests:
# cpu: 50m
# memory: 32Mi
# limits:
# cpu: 100m
# memory: 64Mi
nodeDriverRegistrar:
image:
registry: quay.io
repository: k8scsi/csi-node-driver-registrar
pullPolicy: IfNotPresent
version: v2.0.1
resources: {}
# We usually recommend not to specify default resources and to leave this as a conscious
# choice for the user. This also increases chances charts run on environments with little
# resources, such as Minikube. If you do want to specify resources, uncomment the following
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
# requests:
# cpu: 50m
# memory: 32Mi
# limits:
# cpu: 100m
# memory: 64Mi
oidc:
enabled: false
image:
registry: ghcr.io
repository: spiffe/spire-oidc-provider
pullPolicy: IfNotPresent
version: ""
nodeSelector:
kubernetes.io/arch: amd64
resources: {}
# We usually recommend not to specify default resources and to leave this as a conscious
# choice for the user. This also increases chances charts run on environments with little
# resources, such as Minikube. If you do want to specify resources, uncomment the following
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
# requests:
# cpu: 50m
# memory: 32Mi
# limits:
# cpu: 100m
# memory: 64Mi
logLevel: INFO
service:
type: NodePort
port: 80
annotations: {}
# external-dns.alpha.kubernetes.io/hostname: oidc-discovery.example.org
jwtIssuer: oidc-discovery.example.org
domains:
- localhost
- spire-oidc.spire
- spire-oidc.spire.svc.cluster.local
- oidc-discovery.example.org
insecureScheme:
enabled: false
nginx:
image:
registry: docker.io
repository: nginx
pullPolicy: IfNotPresent
version: alpine
acme:
tosAccepted: false
cacheDir: /run/spire
directoryUrl: https://acme-v02.api.letsencrypt.org/directory
emailAddress: [email protected]
agent:
image:
registry: ghcr.io
repository: spiffe/spire-agent
pullPolicy: IfNotPresent
# Overrides the image tag whose default is the chart appVersion.
version: ""
nodeSelector:
kubernetes.io/arch: amd64
resources: {}
# We usually recommend not to specify default resources and to leave this as a conscious
# choice for the user. This also increases chances charts run on environments with little
# resources, such as Minikube. If you do want to specify resources, uncomment the following
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
# requests:
# cpu: 50m
# memory: 64Mi
# limits:
# cpu: 100m
# memory: 128Mi
imagePullSecrets: []
# - name: my-docker-registry
# username: my-docker-user
# password: my-docker-password
# registryURL: my-private.docker-registry.com
nameOverride: ""
fullnameOverride: ""
serviceAccount:
# Specifies whether a service account should be created
create: true
# Annotations to add to the service account
annotations: {}
# The name of the service account to use.
# If not set and create is true, a name is generated using the fullname template
name: ""
podAnnotations: {}
podSecurityContext: {}
# fsGroup: 2000
securityContext: {}
# capabilities:
# drop:
# - ALL
# readOnlyRootFilesystem: true
# runAsNonRoot: true
# runAsUser: 1000
autoscaling:
enabled: false
minReplicas: 1
maxReplicas: 100
targetCPUUtilizationPercentage: 80
# targetMemoryUtilizationPercentage: 80
tolerations: []
affinity: {}
# spireSettings
spire:
clusterName: "example-cluster"
trustDomain: "example.org"
agent:
logLevel: info
server:
logLevel: info