mirror of
https://github.com/netbirdio/helms.git
synced 2026-05-22 17:13:06 -07:00
166 lines
5.0 KiB
YAML
166 lines
5.0 KiB
YAML
clusterSecretsPermissions:
|
|
# Required for NBSetupKey validation
|
|
# Required for Ingress functionality to create and validate secrets for routing peers
|
|
allowAllSecrets: true
|
|
|
|
webhook:
|
|
service:
|
|
type: ClusterIP
|
|
port: 443
|
|
targetPort: 9443
|
|
|
|
# TLS configuration for webhook
|
|
# Optional, unused if webhook.enableCertManager is set to true
|
|
tls: {}
|
|
|
|
# Use cert-manager to provision webhook certificates (recommended)
|
|
enableCertManager: true
|
|
|
|
# Narrow down validation and mutation webhooks namespaces
|
|
namespaceSelectors: []
|
|
# - key: foo
|
|
# operator: In
|
|
# values:
|
|
# - bar
|
|
|
|
# Narrow down validation and mutation webhooks objects
|
|
objectSelector:
|
|
matchExpressions: []
|
|
# - key: app.kubernetes.io/name
|
|
# operator: NotIn
|
|
# values:
|
|
# - foo
|
|
|
|
# Failure Policy for webhook
|
|
failurePolicy: Fail
|
|
|
|
operator:
|
|
# This will set the replicaset count more information can be found here: https://kubernetes.io/docs/concepts/workloads/controllers/replicaset/
|
|
replicaCount: 1
|
|
|
|
# This sets the container image more information can be found here: https://kubernetes.io/docs/concepts/containers/images/
|
|
image:
|
|
# Set operator image registry
|
|
registry: docker.io
|
|
# Set operator image repository
|
|
repository: netbirdio/kubernetes-operator
|
|
# This sets the pull policy for images.
|
|
pullPolicy: IfNotPresent
|
|
# Overrides the image tag whose default is the chart appVersion.
|
|
tag: ""
|
|
|
|
metrics:
|
|
enabled: true
|
|
type: ClusterIP
|
|
port: 8080
|
|
|
|
# This is for the secretes for pulling an image from a private repository more information can be found here: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
|
|
imagePullSecrets: []
|
|
# This is to override the chart name.
|
|
nameOverride: ""
|
|
fullnameOverride: ""
|
|
|
|
#This section builds out the service account more information can be found here: https://kubernetes.io/docs/concepts/security/service-accounts/
|
|
serviceAccount:
|
|
# Specifies whether a service account should be created
|
|
create: true
|
|
# Automatically mount a ServiceAccount's API credentials?
|
|
automount: true
|
|
# Annotations to add to the service account
|
|
annotations: {}
|
|
# The name of the service account to use.
|
|
# If not set and create is true, a name is generated using the fullname template
|
|
name: ""
|
|
|
|
# This is for setting Kubernetes Annotations to a Pod.
|
|
# For more information checkout: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/
|
|
podAnnotations: {}
|
|
# This is for setting Kubernetes Labels to a Pod.
|
|
# For more information checkout: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
|
|
podLabels: {}
|
|
|
|
securityContext:
|
|
allowPrivilegeEscalation: false
|
|
capabilities:
|
|
drop:
|
|
- ALL
|
|
|
|
podSecurityContext:
|
|
runAsNonRoot: true
|
|
seccompProfile:
|
|
type: RuntimeDefault
|
|
|
|
|
|
# This is for setting up a service more information can be found here: https://kubernetes.io/docs/concepts/services-networking/service/
|
|
service:
|
|
# This sets the service type more information can be found here: https://kubernetes.io/docs/concepts/services-networking/service/#publishing-services-service-types
|
|
type: ClusterIP
|
|
# This sets the ports more information can be found here: https://kubernetes.io/docs/concepts/services-networking/service/#field-spec-ports
|
|
port: 9443
|
|
|
|
resources: {}
|
|
# limits:
|
|
# cpu: 100m
|
|
# memory: 128Mi
|
|
# requests:
|
|
# cpu: 100m
|
|
# memory: 128Mi
|
|
|
|
# This is to setup the liveness and readiness probes more information can be found here: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
|
|
livenessProbe:
|
|
port: 8081
|
|
initialDelaySeconds: 15
|
|
periodSeconds: 20
|
|
successThreshold: 1
|
|
timeoutSeconds: 1
|
|
|
|
readinessProbe:
|
|
port: 8081
|
|
initialDelaySeconds: 5
|
|
periodSeconds: 10
|
|
successThreshold: 1
|
|
timeoutSeconds: 1
|
|
|
|
# Additional volumes on the output Deployment definition.
|
|
volumes: []
|
|
|
|
# Additional volumeMounts on the output Deployment definition.
|
|
volumeMounts: []
|
|
|
|
nodeSelector: {}
|
|
|
|
tolerations: []
|
|
|
|
affinity: {}
|
|
|
|
# DEPRECATED: Use NetworkRouters and NetworkResources instead.
|
|
ingress:
|
|
# Enable ingress capabilities to expose services
|
|
enabled: false
|
|
# Create router per namespace, useful for strict networking requirements
|
|
namespacedNetworks: false
|
|
# Allow creating policies through Service annotations
|
|
allowAutomaticPolicyCreation: false
|
|
|
|
cluster:
|
|
# Cluster DNS name (used for webhooks certificates and for network resource DNS names)
|
|
dns: svc.cluster.local
|
|
# Cluster name (used for generating network and network resource names in NetBird)
|
|
name: kubernetes
|
|
|
|
netbirdAPI:
|
|
keyFromSecret:
|
|
name: "netbird-mgmt-api-key"
|
|
key: "NB_API_KEY"
|
|
|
|
#routingClientImage: "netbirdio/netbird:latest"
|
|
|
|
gatewayAPI:
|
|
enabled: false
|
|
|
|
general:
|
|
# General labels, applied to all created K8s resources
|
|
labels: {}
|
|
# acme_com_managed_by: platform-engineering
|
|
# acme_com_owned_by: release-engineering
|