Co-authored-by: Krishnakumar Venkataraman <[email protected]> Co-authored-by: Marco Franssen <[email protected]>
341 lines
13 KiB
YAML
341 lines
13 KiB
YAML
# Default configuration for Spire OIDC Provider chart
|
|
# SPDX-License-Identifier: APACHE-2.0
|
|
|
|
## @skip global
|
|
global: {}
|
|
|
|
## @section Chart parameters
|
|
##
|
|
## @param agentSocketName The name of the spire-agent unix socket
|
|
agentSocketName: spire-agent.sock
|
|
|
|
## @param replicaCount Replica count
|
|
replicaCount: 1
|
|
|
|
## @param namespaceOverride Namespace override
|
|
namespaceOverride: ""
|
|
|
|
## @param annotations [object] Annotations for the deployment
|
|
annotations: {}
|
|
|
|
image:
|
|
## @param image.registry The OCI registry to pull the image from
|
|
## @param image.repository The repository within the registry
|
|
## @param image.pullPolicy The image pull policy
|
|
## @param image.version This value is deprecated in favor of tag. (Will be removed in a future release)
|
|
## @param image.tag Overrides the image tag whose default is the chart appVersion
|
|
##
|
|
registry: ghcr.io
|
|
repository: spiffe/oidc-discovery-provider
|
|
pullPolicy: IfNotPresent
|
|
version: ""
|
|
tag: ""
|
|
|
|
## @param resources [object] Resource requests and limits
|
|
resources: {}
|
|
# We usually recommend not to specify default resources and to leave this as a conscious
|
|
# choice for the user. This also increases chances charts run on environments with little
|
|
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
|
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
|
# requests:
|
|
# cpu: 50m
|
|
# memory: 32Mi
|
|
# limits:
|
|
# cpu: 100m
|
|
# memory: 64Mi
|
|
|
|
## @param service.type Service type
|
|
## @param service.port Service port
|
|
## @param service.annotations Annotations for service resource
|
|
##
|
|
service:
|
|
type: ClusterIP
|
|
port: 80
|
|
annotations: {}
|
|
# external-dns.alpha.kubernetes.io/hostname: oidc-discovery.example.org
|
|
|
|
configMap:
|
|
## @param configMap.annotations [object] Annotations to add to the SPIFFE OIDC Discovery Provider ConfigMap
|
|
annotations: {}
|
|
|
|
## @param podSecurityContext [object] Pod security context for OIDC discovery provider pods
|
|
podSecurityContext: {}
|
|
# fsGroup: 2000
|
|
|
|
## @param securityContext [object] Security context for OIDC discovery provider deployment
|
|
securityContext: {}
|
|
# capabilities:
|
|
# drop:
|
|
# - ALL
|
|
# readOnlyRootFilesystem: true
|
|
# runAsNonRoot: true
|
|
# runAsUser: 1000
|
|
|
|
## @param readinessProbe.initialDelaySeconds Initial delay seconds for readinessProbe
|
|
## @param readinessProbe.periodSeconds Period seconds for readinessProbe
|
|
##
|
|
readinessProbe:
|
|
initialDelaySeconds: 5
|
|
periodSeconds: 5
|
|
|
|
## @param livenessProbe.initialDelaySeconds Initial delay seconds for livenessProbe
|
|
## @param livenessProbe.periodSeconds Period seconds for livenessProbe
|
|
##
|
|
livenessProbe:
|
|
initialDelaySeconds: 5
|
|
periodSeconds: 5
|
|
|
|
## @param podAnnotations [object] Pod annotations for Spire OIDC discovery provider
|
|
podAnnotations: {}
|
|
|
|
insecureScheme:
|
|
## @param insecureScheme.enabled Flag to enable insecure schema
|
|
enabled: false
|
|
|
|
nginx:
|
|
## @param insecureScheme.nginx.image.registry The OCI registry to pull the image from
|
|
## @param insecureScheme.nginx.image.repository The repository within the registry
|
|
## @param insecureScheme.nginx.image.pullPolicy The image pull policy
|
|
## @param insecureScheme.nginx.image.version This value is deprecated in favor of tag. (Will be removed in a future release)
|
|
## @param insecureScheme.nginx.image.tag Overrides the image tag whose default is the chart appVersion
|
|
## Example:
|
|
## chainguard image does not support the templates feature
|
|
## https://github.com/chainguard-images/nginx/issues/43
|
|
## registry: cgr.dev
|
|
## repository: chainguard/nginx
|
|
## pullPolicy: IfNotPresent
|
|
## tag: "1.23.2"
|
|
##
|
|
image:
|
|
registry: docker.io
|
|
repository: nginxinc/nginx-unprivileged
|
|
pullPolicy: IfNotPresent
|
|
version: ""
|
|
tag: 1.24.0-alpine
|
|
## @param insecureScheme.nginx.resources Resource requests and limits
|
|
resources: {}
|
|
# We usually recommend not to specify default resources and to leave this as a conscious
|
|
# choice for the user. This also increases chances charts run on environments with little
|
|
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
|
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
|
# requests:
|
|
# cpu: 50m
|
|
# memory: 32Mi
|
|
# limits:
|
|
# cpu: 100m
|
|
# memory: 64Mi
|
|
|
|
## @param jwtIssuer Path to JWT issuer
|
|
jwtIssuer: https://oidc-discovery.example.org
|
|
|
|
config:
|
|
## @param config.logLevel The log level, valid values are "debug", "info", "warn", and "error"
|
|
logLevel: info
|
|
## @param config.additionalDomains [array] Add additional domains that can be used for oidc discovery
|
|
additionalDomains:
|
|
- localhost
|
|
|
|
acme:
|
|
## @param config.acme.tosAccepted Flag for Terms of Service acceptance
|
|
tosAccepted: false
|
|
## @param config.acme.cacheDir Path for cache directory
|
|
cacheDir: /run/spire
|
|
## @param config.acme.directoryUrl URL for acme directory
|
|
directoryUrl: https://acme-v02.api.letsencrypt.org/directory
|
|
## @param config.acme.emailAddress Email address for registration
|
|
emailAddress: [email protected]
|
|
|
|
## @param imagePullSecrets [array] Image pull secret names
|
|
imagePullSecrets: []
|
|
|
|
## @param nameOverride Name override
|
|
nameOverride: ""
|
|
|
|
## @param fullnameOverride Full name override
|
|
fullnameOverride: ""
|
|
|
|
## @param serviceAccount.create Specifies whether a service account should be created
|
|
## @param serviceAccount.annotations Annotations to add to the service account
|
|
## @param serviceAccount.name The name of the service account to use. If not set and create is true, a name is generated.
|
|
##
|
|
serviceAccount:
|
|
create: true
|
|
annotations: {}
|
|
name: ""
|
|
|
|
deleteHook:
|
|
## @param deleteHook.enabled Enable Helm hooks to autofix common delete issues (should be disabled when using `helm template`)
|
|
enabled: true
|
|
|
|
## @param autoscaling.enabled Flag to enable autoscaling
|
|
## @param autoscaling.minReplicas Minimum replicas for autoscaling
|
|
## @param autoscaling.maxReplicas Maximum replicas for autoscaling
|
|
## @param autoscaling.targetCPUUtilizationPercentage Target CPU utlization that triggers autoscaling
|
|
## @param autoscaling.targetMemoryUtilizationPercentage Target Memory utlization that triggers autoscaling
|
|
##
|
|
autoscaling:
|
|
enabled: false
|
|
minReplicas: 1
|
|
maxReplicas: 5
|
|
targetCPUUtilizationPercentage: 80
|
|
targetMemoryUtilizationPercentage: 80
|
|
|
|
## @param nodeSelector [object] Node selector
|
|
nodeSelector: {}
|
|
|
|
## @param tolerations [array] iist of tolerations
|
|
tolerations: []
|
|
|
|
## @param affinity [object] Node affinity
|
|
affinity: {}
|
|
|
|
## @param trustDomain Set the trust domain to be used for the SPIFFE identifiers
|
|
trustDomain: example.org
|
|
|
|
## @param clusterDomain The name of the Kubernetes cluster (`kubeadm init --service-dns-domain`)
|
|
clusterDomain: cluster.local
|
|
|
|
telemetry:
|
|
prometheus:
|
|
## @param telemetry.prometheus.enabled Flag to enable prometheus monitoring
|
|
enabled: false
|
|
## @param telemetry.prometheus.port Port for prometheus metrics
|
|
port: 9988
|
|
podMonitor:
|
|
## @param telemetry.prometheus.podMonitor.enabled Enable podMonitor for prometheus
|
|
enabled: false
|
|
## @param telemetry.prometheus.podMonitor.namespace Override where to install the podMonitor, if not set will use the same namespace as the helm release
|
|
namespace: ""
|
|
## @param telemetry.prometheus.podMonitor.labels [object] Pod labels to filter for prometheus monitoring
|
|
labels: {}
|
|
|
|
nginxExporter:
|
|
## @param telemetry.prometheus.nginxExporter.image.registry The OCI registry to pull the image from
|
|
## @param telemetry.prometheus.nginxExporter.image.repository The repository within the registry
|
|
## @param telemetry.prometheus.nginxExporter.image.pullPolicy The image pull policy
|
|
## @param telemetry.prometheus.nginxExporter.image.version This value is deprecated in favor of tag. (Will be removed in a future release)
|
|
## @param telemetry.prometheus.nginxExporter.image.tag Overrides the image tag whose default is the chart appVersion
|
|
##
|
|
image:
|
|
registry: docker.io
|
|
repository: nginx/nginx-prometheus-exporter
|
|
pullPolicy: IfNotPresent
|
|
version: ""
|
|
tag: "0.11.0"
|
|
|
|
## @param telemetry.prometheus.nginxExporter.resources [object] Resource requests and limits
|
|
resources: {}
|
|
# We usually recommend not to specify default resources and to leave this as a conscious
|
|
# choice for the user. This also increases chances charts run on environments with little
|
|
# resources, such as Minikube. If you do want to specify resources, uncomment the following
|
|
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
|
|
# requests:
|
|
# cpu: 50m
|
|
# memory: 32Mi
|
|
# limits:
|
|
# cpu: 100m
|
|
# memory: 64Mi
|
|
|
|
ingress:
|
|
## @param ingress.enabled Flag to enable ingress
|
|
enabled: false
|
|
## @param ingress.className Ingress class name
|
|
className: ""
|
|
## @param ingress.annotations [object] Annotations for ingress object
|
|
annotations: {}
|
|
# kubernetes.io/ingress.class: nginx
|
|
# kubernetes.io/tls-acme: "true"
|
|
# nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
|
# nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
|
|
|
|
## @param ingress.hosts [array] Host paths for ingress object
|
|
hosts:
|
|
- host: oidc-discovery.example.org
|
|
paths:
|
|
- path: /
|
|
pathType: Prefix
|
|
## @param ingress.tls [array] Secrets containining TLS certs to enable https on ingress
|
|
tls: []
|
|
# - secretName: chart-example-tls
|
|
# hosts:
|
|
# - oidc-discovery.example.org
|
|
|
|
tests:
|
|
## @param tests.hostAliases [array] List of host aliases for testing
|
|
hostAliases: []
|
|
tls:
|
|
## @param tests.tls.enabled Flag for enabling tls for tests
|
|
enabled: false
|
|
## @param tests.tls.customCA Custom CA value for tests
|
|
customCA: ""
|
|
bash:
|
|
## @param tests.bash.image.registry The OCI registry to pull the image from
|
|
## @param tests.bash.image.repository The repository within the registry
|
|
## @param tests.bash.image.pullPolicy The image pull policy
|
|
## @param tests.bash.image.version This value is deprecated in favor of tag. (Will be removed in a future release)
|
|
## @param tests.bash.image.tag Overrides the image tag whose default is the chart appVersion
|
|
##
|
|
image:
|
|
registry: cgr.dev
|
|
repository: chainguard/bash
|
|
pullPolicy: IfNotPresent
|
|
version: ""
|
|
tag: latest@sha256:96ab1600d945b4a99c8610b5c8b31e346da63dc20573a26bb0777dd0190db5d4
|
|
|
|
toolkit:
|
|
## @param tests.toolkit.image.registry The OCI registry to pull the image from
|
|
## @param tests.toolkit.image.repository The repository within the registry
|
|
## @param tests.toolkit.image.pullPolicy The image pull policy
|
|
## @param tests.toolkit.image.version This value is deprecated in favor of tag. (Will be removed in a future release)
|
|
## @param tests.toolkit.image.tag Overrides the image tag whose default is the chart appVersion
|
|
##
|
|
image:
|
|
registry: cgr.dev
|
|
repository: chainguard/slim-toolkit-debug
|
|
pullPolicy: IfNotPresent
|
|
version: ""
|
|
tag: latest@sha256:d717d0a2c88518f8e36d9cfe1571639a40617e8c4291e34876d46bdeefb1ab5a
|
|
|
|
busybox:
|
|
## @param tests.busybox.image.registry The OCI registry to pull the image from
|
|
## @param tests.busybox.image.repository The repository within the registry
|
|
## @param tests.busybox.image.pullPolicy The image pull policy
|
|
## @param tests.busybox.image.version This value is deprecated in favor of tag. (Will be removed in a future release)
|
|
## @param tests.busybox.image.tag Overrides the image tag whose default is the chart appVersion
|
|
##
|
|
image:
|
|
registry: ""
|
|
repository: busybox
|
|
pullPolicy: IfNotPresent
|
|
version: ""
|
|
tag: uclibc@sha256:3e516f71d8801b0ce6c3f8f8e4f11093ec04e168177a90f1da4498014ee06b6b
|
|
|
|
agent:
|
|
## @param tests.agent.image.registry The OCI registry to pull the image from
|
|
## @param tests.agent.image.repository The repository within the registry
|
|
## @param tests.agent.image.pullPolicy The image pull policy
|
|
## @param tests.agent.image.version This value is deprecated in favor of tag. (Will be removed in a future release)
|
|
## @param tests.agent.image.tag Overrides the image tag whose default is the chart appVersion
|
|
##
|
|
image:
|
|
registry: ghcr.io
|
|
repository: spiffe/spire-agent
|
|
pullPolicy: IfNotPresent
|
|
version: ""
|
|
tag: ""
|
|
|
|
tools:
|
|
kubectl:
|
|
## @param tools.kubectl.image.registry The OCI registry to pull the image from
|
|
## @param tools.kubectl.image.repository The repository within the registry
|
|
## @param tools.kubectl.image.pullPolicy The image pull policy
|
|
## @param tools.kubectl.image.version This value is deprecated in favor of tag. (Will be removed in a future release)
|
|
## @param tools.kubectl.image.tag Overrides the image tag whose default is the chart appVersion
|
|
##
|
|
image:
|
|
registry: docker.io
|
|
repository: rancher/kubectl
|
|
pullPolicy: IfNotPresent
|
|
version: ""
|
|
tag: ""
|