File tree Expand file tree Collapse file tree 5 files changed +37
-1
lines changed Expand file tree Collapse file tree 5 files changed +37
-1
lines changed Original file line number Diff line number Diff line change 11
11
addr: 0.0.0.0:8000
12
12
timeout: 1s
13
13
grpc:
14
+ {{- if .Values.cas.tlsConfig.secret }}
15
+ tls_config:
16
+ certificate: /data/server-certs/tls.crt
17
+ private_key: /data/server-certs/tls.key
18
+ {{- end }}
14
19
addr: 0.0.0.0:9000
15
20
timeout: 1s
16
21
http_metrics:
17
- addr: 0.0.0.0:5000
22
+ addr: 0.0.0.0:5000
Original file line number Diff line number Diff line change 62
62
- name : gcp-secretmanager-serviceaccountkey
63
63
mountPath : /gcp-secrets
64
64
{{- end }}
65
+ {{- if .Values.cas.tlsConfig.secret }}
66
+ - name : server-certs
67
+ mountPath : /data/server-certs
68
+ {{- end }}
65
69
volumes :
66
70
- name : config
67
71
projected :
73
77
- name : jwt-public-key
74
78
secret :
75
79
secretName : {{ include "chainloop.cas.fullname" . }}-jwt-public-key
80
+ {{- if .Values.cas.tlsConfig.secret }}
81
+ - name : server-certs
82
+ secret :
83
+ secretName : {{ .Values.cas.tlsConfig.secret }}
84
+ {{- end }}
76
85
{{- if eq "gcpSecretManager" .Values.secretsBackend.backend }}
77
86
- name : gcp-secretmanager-serviceaccountkey
78
87
secret :
Original file line number Diff line number Diff line change 24
24
grpc:
25
25
addr: 0.0.0.0:9000
26
26
timeout: 10s
27
+ {{- if .Values.cas.tlsConfig.secret }}
28
+ tls_config:
29
+ certificate: /data/server-certs/tls.crt
30
+ private_key: /data/server-certs/tls.key
31
+ {{- end }}
27
32
cas_server:
28
33
grpc:
29
34
addr: {{ printf "%s-api:%.0f" (include "chainloop.cas.fullname" .) .Values.cas.serviceAPI.port }}
Original file line number Diff line number Diff line change 85
85
mountPath : /tmp
86
86
- name : jwt-cas-private-key
87
87
mountPath : /secrets
88
+ {{- if .Values.controlplane.tlsConfig.secret }}
89
+ - name : server-certs
90
+ mountPath : /data/server-certs
91
+ {{- end }}
88
92
{{- if eq "gcpSecretManager" .Values.secretsBackend.backend }}
89
93
- name : gcp-secretmanager-serviceaccountkey
90
94
mountPath : /gcp-secrets
@@ -103,6 +107,11 @@ spec:
103
107
- name : jwt-cas-private-key
104
108
secret :
105
109
secretName : {{ include "chainloop.controlplane.fullname" . }}-jwt-cas
110
+ {{- if .Values.controlplane.tlsConfig.secret }}
111
+ - name : server-certs
112
+ secret :
113
+ secretName : {{ .Values.controlplane.tlsConfig.secret }}
114
+ {{- end }}
106
115
{{- if eq "gcpSecretManager" .Values.secretsBackend.backend }}
107
116
- name : gcp-secretmanager-serviceaccountkey
108
117
secret :
Original file line number Diff line number Diff line change @@ -103,6 +103,10 @@ controlplane:
103
103
# Overrides the image tag whose default is the chart appVersion.
104
104
# tag: latest
105
105
106
+ # # @param controlplane.tlsConfig.secret name of a secret containing TLS certificate to be used by the controlplane grpc server.
107
+ tlsConfig :
108
+ secret : " "
109
+
106
110
# # @param controlplane.pluginsDir Directory where to look for plugins
107
111
pluginsDir : /plugins
108
112
@@ -443,6 +447,10 @@ cas:
443
447
# Overrides the image tag whose default is the chart appVersion.
444
448
# tag: latest
445
449
450
+ # # @param cas.tlsConfig.secret name of a secret containing TLS certificate to be used by the controlplane grpc server.
451
+ tlsConfig :
452
+ secret : " "
453
+
446
454
# # @skip cas.serviceAccount
447
455
serviceAccount :
448
456
# Specifies whether a service account should be created
You can’t perform that action at this time.
0 commit comments