This repository has been archived by the owner on Jul 11, 2023. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 3
/
values.yaml
80 lines (68 loc) · 2.25 KB
/
values.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
# Default values for the Delina Secret Server (TSS) Secrets Injector
# Kubernetes API Server Mutating Webhook.
# This is a YAML-formatted file.
# Declare variables to be passed into your templates.
replicaCount: 1
image:
repository: thycotic/tss-injector
pullPolicy: IfNotPresent
# Overrides the image tag whose default is the chart appVersion.
tag: ""
imagePullSecrets: []
nameOverride: ""
fullnameOverride: ""
serviceAccount:
# Specifies whether a service account should be created
create: true
# Annotations to add to the service account
annotations: {}
# The name of the service account to use.
# If not set and create is true, a name is generated using the fullname template
name: ""
podAnnotations: {}
podSecurityContext: {}
# fsGroup: 2000
securityContext: {}
# capabilities:
# drop:
# - ALL
# readOnlyRootFilesystem: true
# runAsNonRoot: true
# runAsUser: 1000
service:
type: LoadBalancer
port: 8543
resources: {}
# We usually recommend not to specify default resources and to leave this as a conscious
# choice for the user. This also increases chances charts run on environments with little
# resources, such as Minikube. If you do want to specify resources, uncomment the following
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
# limits:
# cpu: 100m
# memory: 128Mi
# requests:
# cpu: 100m
# memory: 128Mi
# webhookUri is path portion of the URL of the webhook endpoint
webhookUri: /inject
# webhookPort is the port that the webhook endpoint is listening on
webhookPort: 8543
# webhookScope specifies which resources are in scope, "Cluster", "Namespaced" or "*"
webhookScope: "Namespaced"
# webhookCertExpireDays is the days for which the webhook self-sign certificate is valid
webhookCertExpireDays: 1825
# containerPort is the port that the container itself listens on
containerPort: 18543
# Secret name for rolesJson containing JSON-formatted roles file
rolesJsonSecretName:
# rolesJson contains the JSON-formatted roles file (see README.md)
rolesJson: >-
{
"default": {
"credentials": {
"username": "appuser1",
"password": "Password1!"
},
"ServerURL": "https://hostname/SecretServer"
}
}