global: k8s: clusterDomain: cluster.local spire: clusterName: homelab trustDomain: ddupan.top # This is a stable external identity even before its Gateway route is added. # Changing the issuer after consumers trust it would invalidate their config. jwtIssuer: https://spire-oidc.ad.ddupan.top caSubject: country: CN organization: ddupan homelab commonName: ddupan.top namespaces: create: false system: name: spire-system server: name: spire-server recommendations: enabled: true namespaceLayout: true namespacePSS: true priorityClassName: true strictMode: true securityContexts: true prometheus: false spire-server: kind: statefulset replicaCount: 1 auditLogEnabled: true service: type: LoadBalancer port: 8081 loadBalancerIP: 192.168.10.127 kubeConfigs: sandbox: externalSecret: name: spire-external-kubeconfigs key: sandbox sandbox-controller: externalSecret: name: spire-external-kubeconfigs key: sandbox-controller nodeAttestor: externalK8sPSAT: enabled: true clusters: sandbox: kubeConfigName: sandbox serviceAccountAllowList: - spire-system:spire-agent sandbox-kata: kubeConfigName: sandbox serviceAccountAllowList: - spire-smoke:spire-smoke usePodUIDForAgentID: true externalControllerManagers: enabled: true clusters: sandbox: kubeConfigName: sandbox-controller bundlePublisher: externalK8sConfigMap: enabled: true clusters: sandbox: kubeConfigName: sandbox-controller namespace: spire-system configMapName: spire-bundle configMapKey: bundle.spiffe format: spiffe persistence: # PostgreSQL stores registrations, but the disk KeyManager still needs durable # storage for the trust-domain signing keys. type: pvc size: 1Gi accessMode: ReadWriteOnce storageClass: localpv-zfs-ceph dataStore: sql: databaseType: postgres databaseName: spire host: shared-postgresql-rw.shared-db.svc.cluster.local port: 5432 username: spire options: - sslmode: require externalSecret: enabled: true name: spire-postgresql key: password maxOpenConns: 20 maxIdleConns: 2 connMaxLifetime: 30m controllerManager: enabled: true # Identities are opt-in. Do not issue a fallback SVID to every pod in the # cluster merely because it can mount the Workload API socket. identities: clusterSPIFFEIDs: default: enabled: false test-keys: enabled: false spire-agent: server: # Keep the Agent endpoint aligned with spire-server.service.port. The # chart defaults this to 443, which only remained unnoticed while the # Agent's pre-upgrade gRPC connection stayed alive. port: 8081 nodeAttestor: k8sPSAT: enabled: true workloadAttestors: k8s: enabled: true unix: # The node Agent also exposes its Workload API socket on the host. Enable # Unix attestation so local development processes can receive an identity # through an explicitly scoped ClusterStaticEntry. enabled: true spiffe-csi-driver: enabled: true spiffe-oidc-discovery-provider: enabled: true # TLS will terminate at the existing Envoy Gateway when the stable issuer is # exposed. The service remains ClusterIP-only during the first deployment. tls: spire: enabled: false externalSecret: enabled: false certManager: enabled: false upstream: enabled: false tornjak-frontend: enabled: false spire-identity-exchange: enabled: false spike-keeper: enabled: false spike-nexus: enabled: false spike-pilot: enabled: false