Because we are already in the context of spire-agent the API looks more logical to not have another 'agent' part in the name. Furthermore to make it more clear the oidc provider only requires the name of the socket as opposed to the entire path like in the other charts I made that more explicit in the name of the value. --------- Signed-off-by: Marco Franssen <[email protected]>
140 lines
3.7 KiB
YAML
140 lines
3.7 KiB
YAML
# Default values for spiffe-oidc-discovery-provider.
|
|
# This is a YAML-formatted file.
|
|
# Declare variables to be passed into your templates.
|
|
|
|
agentSocketName: spire-agent.sock
|
|
|
|
replicaCount: 1
|
|
|
|
namespaceOverride: ""
|
|
|
|
image:
|
|
# registry: gcr.io
|
|
# repository: spiffe-io/oidc-discovery-provider
|
|
registry: ghcr.io
|
|
repository: spiffe/oidc-discovery-provider
|
|
pullPolicy: IfNotPresent
|
|
version: ""
|
|
|
|
resources: {}
|
|
# We usually recommend not to specify default resources and to leave this as a conscious
|
|
# choice for the user. This also increases chances charts run on environments with little
|
|
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
|
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
|
# requests:
|
|
# cpu: 50m
|
|
# memory: 32Mi
|
|
# limits:
|
|
# cpu: 100m
|
|
# memory: 64Mi
|
|
|
|
service:
|
|
type: ClusterIP
|
|
port: 80
|
|
annotations: {}
|
|
# external-dns.alpha.kubernetes.io/hostname: oidc-discovery.example.org
|
|
|
|
podSecurityContext: {}
|
|
# fsGroup: 2000
|
|
|
|
securityContext: {}
|
|
# capabilities:
|
|
# drop:
|
|
# - ALL
|
|
# readOnlyRootFilesystem: true
|
|
# runAsNonRoot: true
|
|
# runAsUser: 1000
|
|
|
|
podAnnotations: {}
|
|
|
|
insecureScheme:
|
|
enabled: false
|
|
|
|
nginx:
|
|
image:
|
|
registry: docker.io
|
|
repository: nginxinc/nginx-unprivileged
|
|
pullPolicy: IfNotPresent
|
|
version: 1.23.2-alpine
|
|
# chainguard image does not support the templates feature
|
|
# https://github.com/chainguard-images/nginx/issues/43
|
|
# registry: cgr.dev
|
|
# repository: chainguard/nginx
|
|
# pullPolicy: IfNotPresent
|
|
# version: "1.23.2"
|
|
resources: {}
|
|
# We usually recommend not to specify default resources and to leave this as a conscious
|
|
# choice for the user. This also increases chances charts run on environments with little
|
|
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
|
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
|
# requests:
|
|
# cpu: 50m
|
|
# memory: 32Mi
|
|
# limits:
|
|
# cpu: 100m
|
|
# memory: 64Mi
|
|
|
|
config:
|
|
logLevel: info
|
|
domains:
|
|
- localhost
|
|
- oidc-discovery.example.org
|
|
|
|
acme:
|
|
tosAccepted: false
|
|
cacheDir: /run/spire
|
|
directoryUrl: https://acme-v02.api.letsencrypt.org/directory
|
|
emailAddress: [email protected]
|
|
|
|
imagePullSecrets: []
|
|
nameOverride: ""
|
|
fullnameOverride: ""
|
|
|
|
serviceAccount:
|
|
# Specifies whether a service account should be created
|
|
create: true
|
|
# Annotations to add to the service account
|
|
annotations: {}
|
|
# The name of the service account to use.
|
|
# If not set and create is true, a name is generated using the fullname template
|
|
name: ""
|
|
|
|
autoscaling:
|
|
enabled: false
|
|
minReplicas: 1
|
|
maxReplicas: 5
|
|
targetCPUUtilizationPercentage: 80
|
|
targetMemoryUtilizationPercentage: 80
|
|
|
|
nodeSelector: {}
|
|
|
|
tolerations: []
|
|
|
|
affinity: {}
|
|
|
|
trustDomain: "example.org"
|
|
|
|
telemetry:
|
|
prometheus:
|
|
enabled: false
|
|
port: 9988
|
|
|
|
nginxExporter:
|
|
image:
|
|
registry: docker.io
|
|
repository: nginx/nginx-prometheus-exporter
|
|
pullPolicy: IfNotPresent
|
|
version: "0.11.0"
|
|
|
|
resources: {}
|
|
# We usually recommend not to specify default resources and to leave this as a conscious
|
|
# choice for the user. This also increases chances charts run on environments with little
|
|
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
|
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
|
# requests:
|
|
# cpu: 50m
|
|
# memory: 32Mi
|
|
# limits:
|
|
# cpu: 100m
|
|
# memory: 64Mi
|