* Specify ingress controller type Signed-off-by: Kevin Fox <[email protected]> * Fix indenting, docs Signed-off-by: Kevin Fox <[email protected]> * Fix spacing Signed-off-by: Kevin Fox <[email protected]> * Fix missing brackets Signed-off-by: Kevin Fox <[email protected]> * Fix missing brackets Signed-off-by: Kevin Fox <[email protected]> * Add ingress-nginx support Signed-off-by: Kevin Fox <[email protected]> * Use the right example values for test version to upgrade from. Signed-off-by: Kevin Fox <[email protected]> * Fix var in wrong location Signed-off-by: Kevin Fox <[email protected]> * Fix missing arg Signed-off-by: Kevin Fox <[email protected]> * Try this to checkout the right version Signed-off-by: Kevin Fox <[email protected]> * Switch to upgrading from 0.14.0 Signed-off-by: Kevin Fox <[email protected]> * Install crds Signed-off-by: Kevin Fox <[email protected]> * Incorperate feedback Signed-off-by: Kevin Fox <[email protected]> * Apply suggestions from code review Co-authored-by: Faisal Memon <[email protected]> Signed-off-by: kfox1111 <[email protected]> * Fix docs Signed-off-by: Kevin Fox <[email protected]> * Enable unset ingress controller type to use with openshift later Signed-off-by: Kevin Fox <[email protected]> * Fix docs after merge issue Signed-off-by: Kevin Fox <[email protected]> --------- Signed-off-by: Kevin Fox <[email protected]> Signed-off-by: kfox1111 <[email protected]> Co-authored-by: Faisal Memon <[email protected]>
343 lines
13 KiB
YAML
343 lines
13 KiB
YAML
# Default configuration for Spire OIDC Provider chart
|
|
# SPDX-License-Identifier: APACHE-2.0
|
|
|
|
## @skip global
|
|
global: {}
|
|
|
|
## @section Chart parameters
|
|
##
|
|
## @param agentSocketName The name of the spire-agent unix socket
|
|
agentSocketName: spire-agent.sock
|
|
|
|
## @param replicaCount Replica count
|
|
replicaCount: 1
|
|
|
|
## @param namespaceOverride Namespace override
|
|
namespaceOverride: ""
|
|
|
|
## @param annotations [object] Annotations for the deployment
|
|
annotations: {}
|
|
|
|
image:
|
|
## @param image.registry The OCI registry to pull the image from
|
|
## @param image.repository The repository within the registry
|
|
## @param image.pullPolicy The image pull policy
|
|
## @param image.version This value is deprecated in favor of tag. (Will be removed in a future release)
|
|
## @param image.tag Overrides the image tag whose default is the chart appVersion
|
|
##
|
|
registry: ghcr.io
|
|
repository: spiffe/oidc-discovery-provider
|
|
pullPolicy: IfNotPresent
|
|
version: ""
|
|
tag: ""
|
|
|
|
## @param resources [object] Resource requests and limits
|
|
resources: {}
|
|
# We usually recommend not to specify default resources and to leave this as a conscious
|
|
# choice for the user. This also increases chances charts run on environments with little
|
|
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
|
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
|
# requests:
|
|
# cpu: 50m
|
|
# memory: 32Mi
|
|
# limits:
|
|
# cpu: 100m
|
|
# memory: 64Mi
|
|
|
|
## @param service.type Service type
|
|
## @param service.port Service port
|
|
## @param service.annotations Annotations for service resource
|
|
##
|
|
service:
|
|
type: ClusterIP
|
|
port: 80
|
|
annotations: {}
|
|
# external-dns.alpha.kubernetes.io/hostname: oidc-discovery.example.org
|
|
|
|
configMap:
|
|
## @param configMap.annotations [object] Annotations to add to the SPIFFE OIDC Discovery Provider ConfigMap
|
|
annotations: {}
|
|
|
|
## @param podSecurityContext [object] Pod security context for OIDC discovery provider pods
|
|
podSecurityContext: {}
|
|
# fsGroup: 2000
|
|
|
|
## @param securityContext [object] Security context for OIDC discovery provider deployment
|
|
securityContext: {}
|
|
# capabilities:
|
|
# drop:
|
|
# - ALL
|
|
# readOnlyRootFilesystem: true
|
|
# runAsNonRoot: true
|
|
# runAsUser: 1000
|
|
|
|
## @param readinessProbe.initialDelaySeconds Initial delay seconds for readinessProbe
|
|
## @param readinessProbe.periodSeconds Period seconds for readinessProbe
|
|
##
|
|
readinessProbe:
|
|
initialDelaySeconds: 5
|
|
periodSeconds: 5
|
|
|
|
## @param livenessProbe.initialDelaySeconds Initial delay seconds for livenessProbe
|
|
## @param livenessProbe.periodSeconds Period seconds for livenessProbe
|
|
##
|
|
livenessProbe:
|
|
initialDelaySeconds: 5
|
|
periodSeconds: 5
|
|
|
|
## @param podAnnotations [object] Pod annotations for Spire OIDC discovery provider
|
|
podAnnotations: {}
|
|
|
|
insecureScheme:
|
|
## @param insecureScheme.enabled Flag to enable insecure schema
|
|
enabled: false
|
|
|
|
nginx:
|
|
## @param insecureScheme.nginx.image.registry The OCI registry to pull the image from
|
|
## @param insecureScheme.nginx.image.repository The repository within the registry
|
|
## @param insecureScheme.nginx.image.pullPolicy The image pull policy
|
|
## @param insecureScheme.nginx.image.version This value is deprecated in favor of tag. (Will be removed in a future release)
|
|
## @param insecureScheme.nginx.image.tag Overrides the image tag whose default is the chart appVersion
|
|
## Example:
|
|
## chainguard image does not support the templates feature
|
|
## https://github.com/chainguard-images/nginx/issues/43
|
|
## registry: cgr.dev
|
|
## repository: chainguard/nginx
|
|
## pullPolicy: IfNotPresent
|
|
## tag: "1.23.2"
|
|
##
|
|
image:
|
|
registry: docker.io
|
|
repository: nginxinc/nginx-unprivileged
|
|
pullPolicy: IfNotPresent
|
|
version: ""
|
|
tag: 1.25.2-alpine
|
|
## @param insecureScheme.nginx.resources Resource requests and limits
|
|
resources: {}
|
|
# We usually recommend not to specify default resources and to leave this as a conscious
|
|
# choice for the user. This also increases chances charts run on environments with little
|
|
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
|
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
|
# requests:
|
|
# cpu: 50m
|
|
# memory: 32Mi
|
|
# limits:
|
|
# cpu: 100m
|
|
# memory: 64Mi
|
|
|
|
## @param jwtIssuer Path to JWT issuer
|
|
jwtIssuer: https://oidc-discovery.example.org
|
|
|
|
config:
|
|
## @param config.logLevel The log level, valid values are "debug", "info", "warn", and "error"
|
|
logLevel: info
|
|
## @param config.additionalDomains [array] Add additional domains that can be used for oidc discovery
|
|
additionalDomains:
|
|
- localhost
|
|
|
|
acme:
|
|
## @param config.acme.tosAccepted Flag for Terms of Service acceptance
|
|
tosAccepted: false
|
|
## @param config.acme.cacheDir Path for cache directory
|
|
cacheDir: /run/spire
|
|
## @param config.acme.directoryUrl URL for acme directory
|
|
directoryUrl: https://acme-v02.api.letsencrypt.org/directory
|
|
## @param config.acme.emailAddress Email address for registration
|
|
emailAddress: [email protected]
|
|
|
|
## @param imagePullSecrets [array] Image pull secret names
|
|
imagePullSecrets: []
|
|
|
|
## @param nameOverride Name override
|
|
nameOverride: ""
|
|
|
|
## @param fullnameOverride Full name override
|
|
fullnameOverride: ""
|
|
|
|
## @param serviceAccount.create Specifies whether a service account should be created
|
|
## @param serviceAccount.annotations Annotations to add to the service account
|
|
## @param serviceAccount.name The name of the service account to use. If not set and create is true, a name is generated.
|
|
##
|
|
serviceAccount:
|
|
create: true
|
|
annotations: {}
|
|
name: ""
|
|
|
|
deleteHook:
|
|
## @param deleteHook.enabled Enable Helm hooks to autofix common delete issues (should be disabled when using `helm template`)
|
|
enabled: true
|
|
|
|
## @param autoscaling.enabled Flag to enable autoscaling
|
|
## @param autoscaling.minReplicas Minimum replicas for autoscaling
|
|
## @param autoscaling.maxReplicas Maximum replicas for autoscaling
|
|
## @param autoscaling.targetCPUUtilizationPercentage Target CPU utlization that triggers autoscaling
|
|
## @param autoscaling.targetMemoryUtilizationPercentage Target Memory utlization that triggers autoscaling
|
|
##
|
|
autoscaling:
|
|
enabled: false
|
|
minReplicas: 1
|
|
maxReplicas: 5
|
|
targetCPUUtilizationPercentage: 80
|
|
targetMemoryUtilizationPercentage: 80
|
|
|
|
## @param nodeSelector [object] Node selector
|
|
nodeSelector: {}
|
|
|
|
## @param tolerations [array] iist of tolerations
|
|
tolerations: []
|
|
|
|
## @param affinity [object] Node affinity
|
|
affinity: {}
|
|
|
|
## @param trustDomain Set the trust domain to be used for the SPIFFE identifiers
|
|
trustDomain: example.org
|
|
|
|
## @param clusterDomain The name of the Kubernetes cluster (`kubeadm init --service-dns-domain`)
|
|
clusterDomain: cluster.local
|
|
|
|
telemetry:
|
|
prometheus:
|
|
## @param telemetry.prometheus.enabled Flag to enable prometheus monitoring
|
|
enabled: false
|
|
## @param telemetry.prometheus.port Port for prometheus metrics
|
|
port: 9988
|
|
podMonitor:
|
|
## @param telemetry.prometheus.podMonitor.enabled Enable podMonitor for prometheus
|
|
enabled: false
|
|
## @param telemetry.prometheus.podMonitor.namespace Override where to install the podMonitor, if not set will use the same namespace as the helm release
|
|
namespace: ""
|
|
## @param telemetry.prometheus.podMonitor.labels [object] Pod labels to filter for prometheus monitoring
|
|
labels: {}
|
|
|
|
nginxExporter:
|
|
## @param telemetry.prometheus.nginxExporter.image.registry The OCI registry to pull the image from
|
|
## @param telemetry.prometheus.nginxExporter.image.repository The repository within the registry
|
|
## @param telemetry.prometheus.nginxExporter.image.pullPolicy The image pull policy
|
|
## @param telemetry.prometheus.nginxExporter.image.version This value is deprecated in favor of tag. (Will be removed in a future release)
|
|
## @param telemetry.prometheus.nginxExporter.image.tag Overrides the image tag whose default is the chart appVersion
|
|
##
|
|
image:
|
|
registry: docker.io
|
|
repository: nginx/nginx-prometheus-exporter
|
|
pullPolicy: IfNotPresent
|
|
version: ""
|
|
tag: "0.11.0"
|
|
|
|
## @param telemetry.prometheus.nginxExporter.resources [object] Resource requests and limits
|
|
resources: {}
|
|
# We usually recommend not to specify default resources and to leave this as a conscious
|
|
# choice for the user. This also increases chances charts run on environments with little
|
|
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
|
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
|
# requests:
|
|
# cpu: 50m
|
|
# memory: 32Mi
|
|
# limits:
|
|
# cpu: 100m
|
|
# memory: 64Mi
|
|
|
|
ingress:
|
|
## @param ingress.enabled Flag to enable ingress
|
|
enabled: false
|
|
## @param ingress.className Ingress class name
|
|
className: ""
|
|
## @param ingress.controllerType Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, other is assumed. If other, no annotations will be added. Must be one of [ingress-nginx, other, ""].
|
|
controllerType: ""
|
|
## @param ingress.annotations [object] Annotations for ingress object
|
|
annotations: {}
|
|
# kubernetes.io/ingress.class: nginx
|
|
# kubernetes.io/tls-acme: "true"
|
|
# nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
|
# nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
|
|
|
|
## @param ingress.hosts [array] Host paths for ingress object
|
|
hosts:
|
|
- host: oidc-discovery.example.org
|
|
paths:
|
|
- path: /
|
|
pathType: Prefix
|
|
## @param ingress.tls [array] Secrets containining TLS certs to enable https on ingress
|
|
tls: []
|
|
# - secretName: chart-example-tls
|
|
# hosts:
|
|
# - oidc-discovery.example.org
|
|
|
|
tests:
|
|
## @param tests.hostAliases [array] List of host aliases for testing
|
|
hostAliases: []
|
|
tls:
|
|
## @param tests.tls.enabled Flag for enabling tls for tests
|
|
enabled: false
|
|
## @param tests.tls.customCA Custom CA value for tests
|
|
customCA: ""
|
|
bash:
|
|
## @param tests.bash.image.registry The OCI registry to pull the image from
|
|
## @param tests.bash.image.repository The repository within the registry
|
|
## @param tests.bash.image.pullPolicy The image pull policy
|
|
## @param tests.bash.image.version This value is deprecated in favor of tag. (Will be removed in a future release)
|
|
## @param tests.bash.image.tag Overrides the image tag whose default is the chart appVersion
|
|
##
|
|
image:
|
|
registry: cgr.dev
|
|
repository: chainguard/bash
|
|
pullPolicy: IfNotPresent
|
|
version: ""
|
|
tag: latest@sha256:985a0c0ab82bd243bab1827fb48f8e11c8ec331391aad95d1a2f42b3810c1ec2
|
|
|
|
toolkit:
|
|
## @param tests.toolkit.image.registry The OCI registry to pull the image from
|
|
## @param tests.toolkit.image.repository The repository within the registry
|
|
## @param tests.toolkit.image.pullPolicy The image pull policy
|
|
## @param tests.toolkit.image.version This value is deprecated in favor of tag. (Will be removed in a future release)
|
|
## @param tests.toolkit.image.tag Overrides the image tag whose default is the chart appVersion
|
|
##
|
|
image:
|
|
registry: cgr.dev
|
|
repository: chainguard/slim-toolkit-debug
|
|
pullPolicy: IfNotPresent
|
|
version: ""
|
|
tag: latest@sha256:6881d2c00c5178d98b97ae5c73d2b22b8d751f6c73f97a85ab0436c9a82602cd
|
|
|
|
busybox:
|
|
## @param tests.busybox.image.registry The OCI registry to pull the image from
|
|
## @param tests.busybox.image.repository The repository within the registry
|
|
## @param tests.busybox.image.pullPolicy The image pull policy
|
|
## @param tests.busybox.image.version This value is deprecated in favor of tag. (Will be removed in a future release)
|
|
## @param tests.busybox.image.tag Overrides the image tag whose default is the chart appVersion
|
|
##
|
|
image:
|
|
registry: ""
|
|
repository: busybox
|
|
pullPolicy: IfNotPresent
|
|
version: ""
|
|
tag: 1.36.1-uclibc
|
|
|
|
agent:
|
|
## @param tests.agent.image.registry The OCI registry to pull the image from
|
|
## @param tests.agent.image.repository The repository within the registry
|
|
## @param tests.agent.image.pullPolicy The image pull policy
|
|
## @param tests.agent.image.version This value is deprecated in favor of tag. (Will be removed in a future release)
|
|
## @param tests.agent.image.tag Overrides the image tag whose default is the chart appVersion
|
|
##
|
|
image:
|
|
registry: ghcr.io
|
|
repository: spiffe/spire-agent
|
|
pullPolicy: IfNotPresent
|
|
version: ""
|
|
tag: ""
|
|
|
|
tools:
|
|
kubectl:
|
|
## @param tools.kubectl.image.registry The OCI registry to pull the image from
|
|
## @param tools.kubectl.image.repository The repository within the registry
|
|
## @param tools.kubectl.image.pullPolicy The image pull policy
|
|
## @param tools.kubectl.image.version This value is deprecated in favor of tag. (Will be removed in a future release)
|
|
## @param tools.kubectl.image.tag Overrides the image tag whose default is the chart appVersion
|
|
##
|
|
image:
|
|
registry: docker.io
|
|
repository: rancher/kubectl
|
|
pullPolicy: IfNotPresent
|
|
version: ""
|
|
tag: ""
|