8.6 KiB
8.6 KiB
spiffe-csi-driver
A Helm chart to install the SPIFFE CSI driver.
Homepage: https://github.com/spiffe/helm-charts/tree/main/charts/spire
Note
The recommended version is
0.2.3to support arm64 nodes. If running with any prior version to0.2.3you have to use anodeSelectorto limit tokubernetes.io/arch: amd64.
Maintainers
| Name | Url | |
|---|---|---|
| marcofranssen | [email protected] | https://marcofranssen.nl |
| kfox1111 | [email protected] | |
| faisal-memon | [email protected] | |
| edwbuck | [email protected] |
Source Code
Parameters
SPIFFE CSI Driver Chart parameters
| Name | Description | Value |
|---|---|---|
pluginName |
Set the csi driver name deployed to Kubernetes. | csi.spiffe.io |
image.registry |
The OCI registry to pull the image from | ghcr.io |
image.repository |
The repository within the registry | spiffe/spiffe-csi-driver |
image.pullPolicy |
The image pull policy | IfNotPresent |
image.version |
This value is deprecated in favor of tag. (Will be removed in a future release) | "" |
image.tag |
Overrides the image tag whose default is the chart appVersion | "" |
resources |
Resource requests and limits for spiffe-csi-driver | {} |
healthChecks.port |
The healthcheck port for spiffe-csi-driver | 9809 |
livenessProbe.initialDelaySeconds |
Initial delay seconds for livenessProbe | 5 |
livenessProbe.timeoutSeconds |
Timeout value in seconds for livenessProbe | 5 |
imagePullSecrets |
Image pull secret details for spiffe-csi-driver | [] |
nameOverride |
Name override for spiffe-csi-driver | "" |
namespaceOverride |
Namespace to install spiffe-csi-driver | "" |
fullnameOverride |
Full name override for spiffe-csi-driver | "" |
csiDriverLabels |
Labels to apply to the CSIDriver | {} |
initContainers |
Init Containers to apply to the CSI Driver DaemonSet | [] |
serviceAccount.create |
Specifies whether a service account should be created | true |
serviceAccount.annotations |
Annotations to add to the service account | {} |
serviceAccount.name |
The name of the service account to use. If not set and create is true, a name is generated. | "" |
podAnnotations |
Pod annotations for spiffe-csi-driver | {} |
podSecurityContext |
Security context for CSI driver pods | {} |
securityContext.readOnlyRootFilesystem |
Flag for read only root filesystem | true |
securityContext.privileged |
Flag for specifying privileged mode | true |
nodeSelector |
Node selector for CSI driver pods | {} |
tolerations |
Tolerations for CSI driver pods | [] |
nodeDriverRegistrar.image.registry |
The OCI registry to pull the image from | registry.k8s.io |
nodeDriverRegistrar.image.repository |
The repository within the registry | sig-storage/csi-node-driver-registrar |
nodeDriverRegistrar.image.pullPolicy |
The image pull policy | IfNotPresent |
nodeDriverRegistrar.image.version |
This value is deprecated in favor of tag. (Will be removed in a future release) | "" |
nodeDriverRegistrar.image.tag |
Overrides the image tag | v2.9.0 |
nodeDriverRegistrar.resources |
Resource requests and limits for CSI driver pods | {} |
agentSocketPath |
The unix socket path to the spire-agent | /run/spire/agent-sockets/spire-agent.sock |
kubeletPath |
Path to kubelet file | /var/lib/kubelet |
priorityClassName |
Priority class assigned to daemonset pods | "" |
restrictedScc.enabled |
Enables the creation of a SecurityContextConstraint based on the restricted SCC with CSI volume support | false |
restrictedScc.name |
Set the name of the restricted SCC with CSI support | "" |
restrictedScc.version |
Version of the restricted SCC | 2 |