* use spire-agent.resources to set resources for associated initContainers, remove specific keys for those initContainers corresponding resources Signed-off-by: Daniel Schlatter <[email protected]> * set resources for spire-agent init containers fingerprint-tpm and init-tpm-direct Signed-off-by: Daniel Schlatter <[email protected]> * use spiffe-csi-driver.resources to set resources for associated initContainers, remove specific keys for those initContainers corresponding resources Signed-off-by: Daniel Schlatter <[email protected]> * set resources for spiffe-csi-driver init container set-context Signed-off-by: Daniel Schlatter <[email protected]> --------- Signed-off-by: Daniel Schlatter <[email protected]>
14 KiB
14 KiB
spiffe-csi-driver
A Helm chart to install the SPIFFE CSI driver.
Homepage: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire
Maintainers
| Name | Url | |
|---|---|---|
| marcofranssen | [email protected] | https://marcofranssen.nl |
| kfox1111 | [email protected] | |
| faisal-memon | [email protected] | |
| edwbuck | [email protected] |
Source Code
Parameters
SPIFFE CSI Driver Chart parameters
| Name | Description | Value |
|---|---|---|
pluginName |
Set the csi driver name deployed to Kubernetes. | csi.spiffe.io |
image.registry |
The OCI registry to pull the image from | ghcr.io |
image.repository |
The repository within the registry | spiffe/spiffe-csi-driver |
image.pullPolicy |
The image pull policy | IfNotPresent |
image.tag |
Overrides the image tag whose default is the chart appVersion | "" |
resources |
Resource requests and limits for spiffe-csi-driver and its initContainers | {} |
extraEnvVars |
Extra environment variables to be added to the spiffe-csi-driver container | [] |
healthChecks.port |
The healthcheck port for spiffe-csi-driver | 9809 |
updateStrategy.type |
The update strategy to use to replace existing DaemonSet pods with new pods. Can be RollingUpdate or OnDelete. | RollingUpdate |
updateStrategy.rollingUpdate.maxUnavailable |
Max unavailable pods during update. Can be a number or a percentage. | 1 |
livenessProbe.initialDelaySeconds |
Initial delay seconds for livenessProbe | 5 |
livenessProbe.timeoutSeconds |
Timeout value in seconds for livenessProbe | 5 |
imagePullSecrets |
Image pull secret details for spiffe-csi-driver | [] |
nameOverride |
Name override for spiffe-csi-driver | "" |
namespaceOverride |
Namespace to install spiffe-csi-driver | "" |
serverNamespaceOverride |
Override the namespace that the spire-server is installed into | "" |
validatingAdmissionPolicy.enabled |
When set to auto, the validatingAdmissionPolicy will be enabled when the pluginName == "upstream.csi.spiffe.io" and k8s >= 1.30.0. Valid options are [auto, true, false] | auto |
fullnameOverride |
Full name override for spiffe-csi-driver | "" |
csiDriverLabels |
Labels to apply to the CSIDriver | {} |
initContainers |
Init Containers to apply to the CSI Driver DaemonSet | [] |
serviceAccount.create |
Specifies whether a service account should be created | true |
serviceAccount.annotations |
Annotations to add to the service account | {} |
serviceAccount.name |
The name of the service account to use. If not set and create is true, a name is generated. | "" |
podAnnotations |
Pod annotations for spiffe-csi-driver | {} |
podSecurityContext |
Security context for CSI driver pods | {} |
securityContext.readOnlyRootFilesystem |
Flag for read only root filesystem | true |
securityContext.privileged |
Flag for specifying privileged mode | true |
nodeSelector |
Node selector for CSI driver pods | {} |
tolerations |
Tolerations for CSI driver pods | [] |
affinity |
Node affinity | {} |
nodeDriverRegistrar.image.registry |
The OCI registry to pull the image from | registry.k8s.io |
nodeDriverRegistrar.image.repository |
The repository within the registry | sig-storage/csi-node-driver-registrar |
nodeDriverRegistrar.image.pullPolicy |
The image pull policy | IfNotPresent |
nodeDriverRegistrar.image.tag |
Overrides the image tag | v2.9.4 |
nodeDriverRegistrar.extraEnvVars |
Extra environment variables to be added to the nodeDriverRegistrar container | [] |
agentSocketPath |
The unix socket path to the spire-agent | /run/spire/agent-sockets/spire-agent.sock |
kubeletPath |
Path to kubelet file | /var/lib/kubelet |
priorityClassName |
Priority class assigned to daemonset pods. Can be auto set with global.recommendations.priorityClassName. | "" |
restrictedScc.enabled |
Enables the creation of a SecurityContextConstraint based on the restricted SCC with CSI volume support | false |
restrictedScc.name |
Set the name of the restricted SCC with CSI support | "" |
restrictedScc.version |
Version of the restricted SCC | 2 |
selinux.enabled |
Enable selinux support | false |
selinux.context |
Which selinux context to use | container_file_t |
selinux.image.registry |
The OCI registry to pull the image from | registry.access.redhat.com |
selinux.image.repository |
The repository within the registry | ubi9 |
selinux.image.pullPolicy |
The image pull policy | IfNotPresent |
selinux.image.tag |
Overrides the image tag whose default is the chart appVersion | 9.7-1763340522 |