Files
helm-charts-hardened/charts/spire/charts/spiffe-oidc-discovery-provider/README.md
T
kfox1111 f5d1376cb6 Documentation cleanup (#97)
Fix links to the repo after move. Remove references to other versions
of images we don't support.

Signed-off-by: Kevin Fox <[email protected]>
2023-11-11 12:28:41 -08:00

38 KiB

spiffe-oidc-discovery-provider

Version: 0.1.0 Type: application AppVersion: 1.7.2

A Helm chart to install the SPIFFE OIDC discovery provider.

Homepage: https://github.com/spiffe/helm-charts-hardened/tree/main/charts/spire

Maintainers

Name Email Url
marcofranssen [email protected] https://marcofranssen.nl
kfox1111 [email protected]
faisal-memon [email protected]
edwbuck [email protected]

Source Code

Parameters

Chart parameters

Name Description Value
agentSocketName The name of the spire-agent unix socket spire-agent.sock
replicaCount Replica count 1
namespaceOverride Namespace override ""
annotations Annotations for the deployment {}
image.registry The OCI registry to pull the image from ghcr.io
image.repository The repository within the registry spiffe/oidc-discovery-provider
image.pullPolicy The image pull policy IfNotPresent
image.version This value is deprecated in favor of tag. (Will be removed in a future release) ""
image.tag Overrides the image tag whose default is the chart appVersion ""
resources Resource requests and limits {}
service.type Service type ClusterIP
service.port Service port 80
service.annotations Annotations for service resource {}
configMap.annotations Annotations to add to the SPIFFE OIDC Discovery Provider ConfigMap {}
podSecurityContext Pod security context for OIDC discovery provider pods {}
securityContext Security context for OIDC discovery provider deployment {}
readinessProbe.initialDelaySeconds Initial delay seconds for readinessProbe 5
readinessProbe.periodSeconds Period seconds for readinessProbe 5
livenessProbe.initialDelaySeconds Initial delay seconds for livenessProbe 5
livenessProbe.periodSeconds Period seconds for livenessProbe 5
podAnnotations Pod annotations for Spire OIDC discovery provider {}
insecureScheme.enabled Flag to enable insecure schema false
insecureScheme.nginx.image.registry The OCI registry to pull the image from docker.io
insecureScheme.nginx.image.repository The repository within the registry nginxinc/nginx-unprivileged
insecureScheme.nginx.image.pullPolicy The image pull policy IfNotPresent
insecureScheme.nginx.image.version This value is deprecated in favor of tag. (Will be removed in a future release) ""
insecureScheme.nginx.image.tag Overrides the image tag whose default is the chart appVersion 1.25.2-alpine
insecureScheme.nginx.resources Resource requests and limits {}
jwtIssuer Path to JWT issuer. Defaults to oidc-discovery.$trustDomain if unset ""
config.logLevel The log level, valid values are "debug", "info", "warn", and "error" info
config.additionalDomains Add additional domains that can be used for oidc discovery []
config.acme.tosAccepted Flag for Terms of Service acceptance false
config.acme.cacheDir Path for cache directory /run/spire
config.acme.directoryUrl URL for acme directory https://acme-v02.api.letsencrypt.org/directory
config.acme.emailAddress Email address for registration [email protected]
imagePullSecrets Image pull secret names []
nameOverride Name override ""
fullnameOverride Full name override ""
serviceAccount.create Specifies whether a service account should be created true
serviceAccount.annotations Annotations to add to the service account {}
serviceAccount.name The name of the service account to use. If not set and create is true, a name is generated. ""
deleteHook.enabled Enable Helm hooks to autofix common delete issues (should be disabled when using helm template) true
autoscaling.enabled Flag to enable autoscaling false
autoscaling.minReplicas Minimum replicas for autoscaling 1
autoscaling.maxReplicas Maximum replicas for autoscaling 5
autoscaling.targetCPUUtilizationPercentage Target CPU utlization that triggers autoscaling 80
autoscaling.targetMemoryUtilizationPercentage Target Memory utlization that triggers autoscaling 80
nodeSelector Node selector {}
tolerations iist of tolerations []
affinity Node affinity {}
trustDomain Set the trust domain to be used for the SPIFFE identifiers example.org
clusterDomain The name of the Kubernetes cluster (kubeadm init --service-dns-domain) cluster.local
telemetry.prometheus.enabled Flag to enable prometheus monitoring false
telemetry.prometheus.port Port for prometheus metrics 9988
telemetry.prometheus.podMonitor.enabled Enable podMonitor for prometheus false
telemetry.prometheus.podMonitor.namespace Override where to install the podMonitor, if not set will use the same namespace as the helm release ""
telemetry.prometheus.podMonitor.labels Pod labels to filter for prometheus monitoring {}
telemetry.prometheus.nginxExporter.image.registry The OCI registry to pull the image from docker.io
telemetry.prometheus.nginxExporter.image.repository The repository within the registry nginx/nginx-prometheus-exporter
telemetry.prometheus.nginxExporter.image.pullPolicy The image pull policy IfNotPresent
telemetry.prometheus.nginxExporter.image.version This value is deprecated in favor of tag. (Will be removed in a future release) ""
telemetry.prometheus.nginxExporter.image.tag Overrides the image tag whose default is the chart appVersion 0.11.0
telemetry.prometheus.nginxExporter.resources Resource requests and limits {}
ingress.enabled Flag to enable ingress false
ingress.className Ingress class name ""
ingress.controllerType Specify what type of ingress controller you're using to add the necessary annotations accordingly. If blank, autodetection is attempted. If other, no annotations will be added. Must be one of [ingress-nginx, openshift, other, ""]. ""
ingress.annotations Annotations for ingress object {}
ingress.host Host name for the ingress. If no '.' in host, trustDomain is automatically appended. The rest of the rules will be autogenerated. For more customizability, use hosts[] instead. oidc-discovery
ingress.tlsSecret Secret that has the certs. If blank will use default certs. Used with host var. ""
ingress.hosts Host paths for ingress object. If emtpy, rules will be built based on the host var. []
ingress.tls Secrets containining TLS certs to enable https on ingress. If emtpy, rules will be built based on the host and tlsSecret vars. []
tests.hostAliases List of host aliases for testing []
tests.tls.enabled Flag for enabling tls for tests false
tests.tls.customCA Custom CA value for tests ""
tests.bash.image.registry The OCI registry to pull the image from cgr.dev
tests.bash.image.repository The repository within the registry chainguard/bash
tests.bash.image.pullPolicy The image pull policy IfNotPresent
tests.bash.image.version This value is deprecated in favor of tag. (Will be removed in a future release) ""
tests.bash.image.tag Overrides the image tag whose default is the chart appVersion latest@sha256:3d077aae77eb552abd85a015d087047a7a7353d974e5f7fc6a402180c1501214
tests.toolkit.image.registry The OCI registry to pull the image from cgr.dev
tests.toolkit.image.repository The repository within the registry chainguard/slim-toolkit-debug
tests.toolkit.image.pullPolicy The image pull policy IfNotPresent
tests.toolkit.image.version This value is deprecated in favor of tag. (Will be removed in a future release) ""
tests.toolkit.image.tag Overrides the image tag whose default is the chart appVersion latest@sha256:d1fc4d296994f28d7e0264c933a12ba75c9a80478ff1eb4b6f692bb91a073a4c
tests.busybox.image.registry The OCI registry to pull the image from ""
tests.busybox.image.repository The repository within the registry busybox
tests.busybox.image.pullPolicy The image pull policy IfNotPresent
tests.busybox.image.version This value is deprecated in favor of tag. (Will be removed in a future release) ""
tests.busybox.image.tag Overrides the image tag whose default is the chart appVersion 1.36.1-uclibc
tests.agent.image.registry The OCI registry to pull the image from ghcr.io
tests.agent.image.repository The repository within the registry spiffe/spire-agent
tests.agent.image.pullPolicy The image pull policy IfNotPresent
tests.agent.image.version This value is deprecated in favor of tag. (Will be removed in a future release) ""
tests.agent.image.tag Overrides the image tag whose default is the chart appVersion ""
tools.kubectl.image.registry The OCI registry to pull the image from docker.io
tools.kubectl.image.repository The repository within the registry rancher/kubectl
tools.kubectl.image.pullPolicy The image pull policy IfNotPresent
tools.kubectl.image.version This value is deprecated in favor of tag. (Will be removed in a future release) ""
tools.kubectl.image.tag Overrides the image tag whose default is the chart appVersion ""