global: enabled: true imagePullSecrets: [] tlsDisable: true externalVaultAddr: "" openshift: false # Create PodSecurityPolicy for pods psp: enable: false # Annotation for PodSecurityPolicy. # This is a multi-line templated string map, and can also be set as YAML. annotations: | seccomp.security.alpha.kubernetes.io/allowedProfileNames: docker/default,runtime/default apparmor.security.beta.kubernetes.io/allowedProfileNames: runtime/default seccomp.security.alpha.kubernetes.io/defaultProfileName: runtime/default apparmor.security.beta.kubernetes.io/defaultProfileName: runtime/default serverTelemetry: # Enable integration with the Prometheus Operator # See the top level serverTelemetry section below before enabling this feature. prometheusOperator: false injector: enabled: true replicas: 1 # Configures the port the injector should listen on port: 8080 # If multiple replicas are specified, by default a leader will be determined # so that only one injector attempts to create TLS certificates. leaderElector: enabled: true # If true, will enable a node exporter metrics endpoint at /metrics. metrics: enabled: false # Deprecated: Please use global.externalVaultAddr instead. externalVaultAddr: "" # image sets the repo and tag of the vault-k8s image to use for the injector. image: repository: "{{ .Modules.SecretsStorage.Injector.Image }}" tag: "{{ .Modules.SecretsStorage.Injector.Tag }}" pullPolicy: IfNotPresent # agentImage sets the repo and tag of the Vault image to use for the Vault Agent # containers. This should be set to the official Vault image. Vault 1.3.1+ is # required. agentImage: repository: "{{ .Modules.SecretsStorage.Agent.Image }}" tag: "{{ .Modules.SecretsStorage.Agent.Tag }}" agentDefaults: cpuLimit: "500m" cpuRequest: "250m" memLimit: "128Mi" memRequest: "64Mi" # ephemeralLimit: "128Mi" # ephemeralRequest: "64Mi" # Default template type for secrets when no custom template is specified. # Possible values include: "json" and "map". template: "map" # Default values within Agent's template_config stanza. templateConfig: exitOnRetryFailure: true staticSecretRenderInterval: "" # Used to define custom livenessProbe settings livenessProbe: # When a probe fails, Kubernetes will try failureThreshold times before giving up failureThreshold: 2 # Number of seconds after the container has started before probe initiates initialDelaySeconds: 5 # How often (in seconds) to perform the probe periodSeconds: 2 # Minimum consecutive successes for the probe to be considered successful after having failed successThreshold: 1 # Number of seconds after which the probe times out. timeoutSeconds: 5 # Used to define custom readinessProbe settings readinessProbe: # When a probe fails, Kubernetes will try failureThreshold times before giving up failureThreshold: 2 # Number of seconds after the container has started before probe initiates initialDelaySeconds: 5 # How often (in seconds) to perform the probe periodSeconds: 2 # Minimum consecutive successes for the probe to be considered successful after having failed successThreshold: 1 # Number of seconds after which the probe times out. timeoutSeconds: 5 # Used to define custom startupProbe settings startupProbe: # When a probe fails, Kubernetes will try failureThreshold times before giving up failureThreshold: 12 # Number of seconds after the container has started before probe initiates initialDelaySeconds: 5 # How often (in seconds) to perform the probe periodSeconds: 5 # Minimum consecutive successes for the probe to be considered successful after having failed successThreshold: 1 # Number of seconds after which the probe times out. timeoutSeconds: 5 # Mount Path of the Vault Kubernetes Auth Method. authPath: "auth/kubernetes" # Configures the log verbosity of the injector. # Supported log levels include: trace, debug, info, warn, error logLevel: "info" # Configures the log format of the injector. Supported log formats: "standard", "json". logFormat: "standard" # Configures all Vault Agent sidecars to revoke their token when shutting down revokeOnShutdown: false webhook: # Configures failurePolicy of the webhook. The "unspecified" default behaviour depends on the # API Tag of the WebHook. # To block pod creation while the webhook is unavailable, set the policy to `Fail` below. # See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#failure-policy # failurePolicy: Ignore # matchPolicy specifies the approach to accepting changes based on the rules of # the MutatingWebhookConfiguration. # See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#matching-requests-matchpolicy # for more details. # matchPolicy: Exact # timeoutSeconds is the amount of seconds before the webhook request will be ignored # or fails. # If it is ignored or fails depends on the failurePolicy # See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#timeouts # for more details. # timeoutSeconds: 30 # namespaceSelector is the selector for restricting the webhook to only # specific namespaces. # See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#matching-requests-namespaceselector # for more details. # Example: # namespaceSelector: # matchLabels: # sidecar-injector: enabled namespaceSelector: {} # objectSelector is the selector for restricting the webhook to only # specific labels. # See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#matching-requests-objectselector # for more details. # Example: # objectSelector: # matchLabels: # vault-sidecar-injector: enabled # Extra annotations to attach to the webhook annotations: {} # Deprecated: please use 'webhook.failurePolicy' instead # Configures failurePolicy of the webhook. The "unspecified" default behaviour depends on the # API Tag of the WebHook. # To block pod creation while webhook is unavailable, set the policy to `Fail` below. # See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#failure-policy # failurePolicy: Ignore # Deprecated: please use 'webhook.namespaceSelector' instead # namespaceSelector is the selector for restricting the webhook to only # specific namespaces. # See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#matching-requests-namespaceselector # for more details. # Example: # namespaceSelector: # matchLabels: # sidecar-injector: enabled namespaceSelector: {} # Deprecated: please use 'webhook.objectSelector' instead # objectSelector is the selector for restricting the webhook to only # specific labels. # See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#matching-requests-objectselector # for more details. # Example: # objectSelector: # matchLabels: # vault-sidecar-injector: enabled objectSelector: {} # Deprecated: please use 'webhook.annotations' instead # Extra annotations to attach to the webhook webhookAnnotations: {} certs: # secretName is the name of the secret that has the TLS certificate and # private key to serve the injector webhook. If this is null, then the # injector will default to its automatic management mode that will assign # a service account to the injector to generate its own certificates. secretName: null # caBundle is a base64-encoded PEM-encoded certificate bundle for the CA # that signed the TLS certificate that the webhook serves. This must be set # if secretName is non-null unless an external service like cert-manager is # keeping the caBundle updated. caBundle: "" # certName and keyName are the names of the files within the secret for # the TLS cert and private key, respectively. These have reasonable # defaults but can be customized if necessary. certName: tls.crt keyName: tls.key securityContext: pod: {} container: {} resources: {} # extraEnvironmentVars is a list of extra environment variables to set in the # injector deployment. extraEnvironmentVars: {} # KUBERNETES_SERVICE_HOST: kubernetes.default.svc topologySpreadConstraints: [] tolerations: [] nodeSelector: {} priorityClassName: "" annotations: {} extraLabels: {} hostNetwork: false service: # Extra annotations to attach to the injector service annotations: {} # Injector serviceAccount specific config serviceAccount: # Extra annotations to attach to the injector serviceAccount annotations: {} # A disruption budget limits the number of pods of a replicated application # that are down simultaneously from voluntary disruptions podDisruptionBudget: {} # podDisruptionBudget: # maxUnavailable: 1 # strategy for updating the deployment. This can be a multi-line string or a # YAML map. strategy: {} # strategy: | # rollingUpdate: # maxSurge: 25% # maxUnavailable: 25% # type: RollingUpdate server: enabled: true enterpriseLicense: # The name of the Kubernetes secret that holds the enterprise license. The # secret must be in the same namespace that Vault is installed into. secretName: "" # The key within the Kubernetes secret that holds the enterprise license. secretKey: "license" image: repository: "{{ .Modules.SecretsStorage.Server.Image }}" tag: "{{ .Modules.SecretsStorage.Server.Tag }}" # Overrides the default Image Pull Policy pullPolicy: IfNotPresent updateStrategyType: "RollingUpdate" # Supported log levels include: trace, debug, info, warn, error logLevel: "" # Supported log formats include: standard, json logFormat: "" resources: {} hostAliases: [] # - ip: 127.0.0.1 # hostnames: # - chart-example.local route: enabled: false # When HA mode is enabled and K8s service registration is being used, # configure the route to point to the Vault active service. activeService: true labels: {} annotations: {} host: chart-example.local # tls will be passed directly to the route's TLS config, which # can be used to configure other termination methods that terminate # TLS at the router tls: termination: passthrough # authDelegator enables a cluster role binding to be attached to the service # account. This cluster role binding can be used to setup Kubernetes auth # method. See https://developer.hashicorp.com/vault/docs/auth/kubernetes authDelegator: enabled: true extraInitContainers: null extraContainers: null shareProcessNamespace: false extraArgs: "" extraPorts: null # - containerPort: 8300 # name: http-monitoring readinessProbe: enabled: false # If you need to use a http path instead of the default exec # path: /v1/sys/health?standbyok=true # Port number on which readinessProbe will be checked. port: 8200 # When a probe fails, Kubernetes will try failureThreshold times before giving up failureThreshold: 2 # Number of seconds after the container has started before probe initiates initialDelaySeconds: 5 # How often (in seconds) to perform the probe periodSeconds: 5 # Minimum consecutive successes for the probe to be considered successful after having failed successThreshold: 1 # Number of seconds after which the probe times out. timeoutSeconds: 3 # Used to enable a livenessProbe for the pods livenessProbe: enabled: false # Used to define a liveness exec command. If provided, exec is preferred to httpGet (path) as the livenessProbe handler. execCommand: [] # - /bin/sh # - -c # - /vault/userconfig/mylivenessscript/run.sh # Path for the livenessProbe to use httpGet as the livenessProbe handler path: "/v1/sys/health?standbyok=true" # Port number on which livenessProbe will be checked if httpGet is used as the livenessProbe handler port: 8200 # When a probe fails, Kubernetes will try failureThreshold times before giving up failureThreshold: 2 # Number of seconds after the container has started before probe initiates initialDelaySeconds: 60 # How often (in seconds) to perform the probe periodSeconds: 5 # Minimum consecutive successes for the probe to be considered successful after having failed successThreshold: 1 # Number of seconds after which the probe times out. timeoutSeconds: 3 terminationGracePeriodSeconds: 10 # Used to set the sleep time during the preStop step preStopSleepSeconds: 5 extraEnvironmentVars: {} extraSecretEnvironmentVars: [] extraVolumes: [] volumes: null volumeMounts: null topologySpreadConstraints: [] tolerations: [] nodeSelector: {} # Enables network policy for server pods networkPolicy: enabled: false egress: [] # egress: # - to: # - ipBlock: # cidr: 10.0.0.0/24 # ports: # - protocol: TCP # port: 443 ingress: - from: - namespaceSelector: {} ports: - port: 8200 protocol: TCP - port: 8201 protocol: TCP priorityClassName: "" extraLabels: {} annotations: {} service: enabled: true # Enable or disable the vault-active service, which selects Vault pods that # have labeled themselves as the cluster leader with `vault-active: "true"`. active: enabled: true # Extra annotations for the service definition. This can either be YAML or a # YAML-formatted multi-line templated string map of the annotations to apply # to the active service. annotations: {} # Enable or disable the vault-standby service, which selects Vault pods that # have labeled themselves as a cluster follower with `vault-active: "false"`. standby: enabled: true # Extra annotations for the service definition. This can either be YAML or a # YAML-formatted multi-line templated string map of the annotations to apply # to the standby service. annotations: {} # When disabled, services may select Vault pods not deployed from the chart. # Does not affect the headless vault-internal service with `ClusterIP: None` instanceSelector: enabled: true # clusterIP controls whether a Cluster IP address is attached to the # Vault service within Kubernetes. By default, the Vault service will # be given a Cluster IP address, set to None to disable. When disabled # Kubernetes will create a "headless" service. Headless services can be # used to communicate with pods directly through DNS instead of a round-robin # load balancer. # clusterIP: None # Configures the service type for the main Vault service. Can be ClusterIP # or NodePort. #type: ClusterIP # The IP family and IP families options are to set the behaviour in a dual-stack environment. # Omitting these values will let the service fall back to whatever the CNI dictates the defaults # should be. # These are only supported for kubernetes versions >=1.23.0 # # Configures the service's supported IP family policy, can be either: # SingleStack: Single-stack service. The control plane allocates a cluster IP for the Service, using the first configured service cluster IP range. # PreferDualStack: Allocates IPv4 and IPv6 cluster IPs for the Service. # RequireDualStack: Allocates Service .spec.ClusterIPs from both IPv4 and IPv6 address ranges. ipFamilyPolicy: "" # Sets the families that should be supported and the order in which they should be applied to ClusterIP as well. # Can be IPv4 and/or IPv6. ipFamilies: [] # Do not wait for pods to be ready before including them in the services' # targets. Does not apply to the headless service, which is used for # cluster-internal communication. publishNotReadyAddresses: true # The externalTrafficPolicy can be set to either Cluster or Local # and is only valid for LoadBalancer and NodePort service types. # The default value is Cluster. # ref: https://kubernetes.io/docs/concepts/services-networking/service/#external-traffic-policy externalTrafficPolicy: Cluster # If type is set to "NodePort", a specific nodePort value can be configured, # will be random if left blank. #nodePort: 30000 # When HA mode is enabled # If type is set to "NodePort", a specific nodePort value can be configured, # will be random if left blank. #activeNodePort: 30001 # When HA mode is enabled # If type is set to "NodePort", a specific nodePort value can be configured, # will be random if left blank. #standbyNodePort: 30002 # Port on which Vault server is listening port: 8200 # Target port to which the service should be mapped to targetPort: 8200 # Extra annotations for the service definition. This can either be YAML or a # YAML-formatted multi-line templated string map of the annotations to apply # to the service. annotations: {} dataStorage: enabled: true size: {{ .Modules.SecretsStorage.Server.Persistence.DataStorage.Size }} mountPath: "/vault/data" storageClass: {{ .Modules.SecretsStorage.Server.Persistence.DataStorage.StorageClass }} accessMode: ReadWriteOnce annotations: {} labels: {} persistentVolumeClaimRetentionPolicy: {} # required for ha installation auditStorage: enabled: false # Size of the PVC created size: {{ .Modules.SecretsStorage.Server.Persistence.AuditStorage.Size }} # Location where the PVC will be mounted. mountPath: "/vault/audit" # Name of the storage class to use. If null it will use the # configured default Storage Class. storageClass: {{ .Modules.SecretsStorage.Server.Persistence.AuditStorage.StorageClass }} # Access Mode of the storage device being used for the PVC accessMode: ReadWriteOnce # Annotations to apply to the PVC annotations: {} # Labels to apply to the PVC labels: {} dev: enabled: false # Set VAULT_DEV_ROOT_TOKEN_ID value devRootToken: "root" # Run Vault in "standalone" mode. This is the default mode that will deploy if # no arguments are given to helm. This requires a PVC for data storage to use # the "file" backend. This mode is not highly available and should not be scaled # past a single replica. standalone: enabled: "-" # config is a raw string of default configuration when using a Stateful # deployment. Default is to use a PersistentVolumeClaim mounted at /vault/data # and store data there. This is only used when using a Replica count of 1, and # using a stateful set. This should be HCL. # Note: Configuration files are stored in ConfigMaps so sensitive data # such as passwords should be either mounted through extraSecretEnvironmentVars # or through a Kube secret. For more information see: # https://developer.hashicorp.com/vault/docs/platform/k8s/helm/run#protecting-sensitive-vault-configurations config: | ui = true listener "tcp" { tls_disable = 1 address = "[::]:8200" cluster_address = "[::]:8201" {{- if and .Modules.Observability.Enabled .Modules.Observability.Monitoring.Enabled }} telemetry { unauthenticated_metrics_access = "true" } {{- end }} } storage "file" { path = "/vault/data" } {{- if and .Modules.Observability.Enabled .Modules.Observability.Monitoring.Enabled }} telemetry { prometheus_retention_time = "30s" disable_hostname = true } {{- end }} # Run Vault in "HA" mode. There are no storage requirements unless the audit log # persistence is required. In HA mode Vault will configure itself to use Consul # for its storage backend. The default configuration provided will work the Consul # Helm project by default. It is possible to manually configure Vault to use a # different HA backend. ha: enabled: false replicas: 3 # Set the api_addr configuration for Vault HA # See https://developer.hashicorp.com/vault/docs/configuration#api_addr # If set to null, this will be set to the Pod IP Address apiAddr: null # Set the cluster_addr confuguration for Vault HA # See https://developer.hashicorp.com/vault/docs/configuration#cluster_addr clusterAddr: null # Enables Vault's integrated Raft storage. Unlike the typical HA modes where # Vault's persistence is external (such as Consul), enabling Raft mode will create # persistent volumes for Vault to store data according to the configuration under server.dataStorage. # The Vault cluster will coordinate leader elections and failovers internally. raft: # Enables Raft integrated storage enabled: false # Set the Node Raft ID to the name of the pod setNodeId: false config: | ui = true listener "tcp" { tls_disable = 1 address = "[::]:8200" cluster_address = "[::]:8201" {{- if and .Modules.Observability.Enabled .Modules.Observability.Monitoring.Enabled }} telemetry { unauthenticated_metrics_access = "true" } {{- end }} } storage "raft" { path = "/vault/data" } service_registration "kubernetes" {} # config is a raw string of default configuration when using a Stateful # deployment. Default is to use a Consul for its HA storage backend. # This should be HCL. # Note: Configuration files are stored in ConfigMaps so sensitive data # such as passwords should be either mounted through extraSecretEnvironmentVars # or through a Kube secret. For more information see: # https://developer.hashicorp.com/vault/docs/platform/k8s/helm/run#protecting-sensitive-vault-configurations config: | ui = true listener "tcp" { tls_disable = 1 address = "[::]:8200" cluster_address = "[::]:8201" {{- if and .Modules.Observability.Enabled .Modules.Observability.Monitoring.Enabled }} telemetry { unauthenticated_metrics_access = "true" } {{- end }} } storage "consul" { path = "vault" address = "HOST_IP:8500" } service_registration "kubernetes" {} # Example configuration for using auto-unseal, using Google Cloud KMS. The # GKMS keys must already exist, and the cluster must have a service account # that is authorized to access GCP KMS. #seal "gcpckms" { # project = "vault-helm-dev-246514" # region = "global" # key_ring = "vault-helm-unseal-kr" # crypto_key = "vault-helm-unseal-key" #} {{- if and .Modules.Observability.Enabled .Modules.Observability.Monitoring.Enabled }} telemetry { prometheus_retention_time = "30s" disable_hostname = true } {{- end }} # A disruption budget limits the number of pods of a replicated application # that are down simultaneously from voluntary disruptions disruptionBudget: enabled: true # maxUnavailable will default to (n/2)-1 where n is the number of # replicas. If you'd like a custom value, you can specify an override here. maxUnavailable: null serviceAccount: create: true name: "" createSecret: false annotations: {} extraLabels: {} serviceDiscovery: enabled: true statefulSet: annotations: {} securityContext: pod: {} container: {} hostNetwork: false # Vault UI ui: enabled: true domain: {{ .Modules.SecretsStorage.Expose.Domain }} path: {{ .Modules.SecretsStorage.Expose.Path }} publishNotReadyAddresses: true # The service should only contain selectors for active Vault pod activeVaultPodOnly: false {{- if eq .Modules.SecretsStorage.Expose.Type "NodePort" }} serviceType: "NodePort" serviceNodePort: {{ .Modules.SecretsStorage.Expose.NodePort }} {{- else }} serviceType: "ClusterIP" serviceNodePort: null {{- end }} externalPort: 8200 targetPort: 8200 serviceIPFamilyPolicy: "" serviceIPFamilies: [] externalTrafficPolicy: Cluster #loadBalancerSourceRanges: # - 10.0.0.0/16 # - 1.78.23.3/32 # loadBalancerIP: annotations: {} csi: # True if you want to install a secrets-store-csi-driver-provider-vault daemonset. # # Requires installing the secrets-store-csi-driver separately, see: # https://github.com/kubernetes-sigs/secrets-store-csi-driver#install-the-secrets-store-csi-driver # # With the driver and provider installed, you can mount Vault secrets into volumes # similar to the Vault Agent injector, and you can also sync those secrets into # Kubernetes secrets. enabled: {{ .Modules.SecretsStorage.CsiIntegration.Enabled }} image: repository: "{{ .Modules.SecretsStorage.CsiIntegration.Image }}" tag: "{{ .Modules.SecretsStorage.CsiIntegration.Tag }}" pullPolicy: IfNotPresent volumes: null volumeMounts: null resources: {} # Override the default secret name for the CSI Provider's HMAC key used for # generating secret versions. hmacSecretName: "" daemonSet: updateStrategy: type: RollingUpdate maxUnavailable: "" # Extra annotations for the daemonSet. This can either be YAML or a # YAML-formatted multi-line templated string map of the annotations to apply # to the daemonSet. annotations: {} # Provider host path (must match the CSI provider's path) providersDir: "/etc/kubernetes/secrets-store-csi-providers" # Kubelet host path kubeletRootDir: "/var/lib/kubelet" # Extra labels to attach to the vault-csi-provider daemonSet # This should be a YAML map of the labels to apply to the csi provider daemonSet extraLabels: {} # security context for the pod template and container in the csi provider daemonSet securityContext: pod: {} container: {} pod: annotations: {} tolerations: - key: node-role.kubernetes.io/master effect: NoSchedule - key: node-role.kubernetes.io/control-plane effect: NoSchedule nodeSelector: {} affinity: {} extraLabels: {} agent: enabled: true extraArgs: [] image: repository: "{{ .Modules.SecretsStorage.Agent.Image }}" tag: "{{ .Modules.SecretsStorage.Agent.Tag }}" pullPolicy: IfNotPresent logFormat: standard logLevel: info resources: {} priorityClassName: "" serviceAccount: annotations: {} extraLabels: {} readinessProbe: enabled: true failureThreshold: 2 initialDelaySeconds: 5 periodSeconds: 5 successThreshold: 1 timeoutSeconds: 3 livenessProbe: failureThreshold: 2 initialDelaySeconds: 5 periodSeconds: 5 successThreshold: 1 timeoutSeconds: 3 debug: false extraArgs: [] serverTelemetry: # Enable support for the Prometheus Operator. Currently, this chart does not support # authenticating to Vault's metrics endpoint, so the following `telemetry{}` must be included # in the `listener "tcp"{}` stanza # telemetry { # unauthenticated_metrics_access = "true" # } # # See the `standalone.config` for a more complete example of this. # # In addition, a top level `telemetry{}` stanza must also be included in the Vault configuration: # # example: # telemetry { # prometheus_retention_time = "30s" # disable_hostname = true # } # # Configuration for monitoring the Vault server. serviceMonitor: enabled: {{ and .Modules.Observability.Enabled .Modules.Observability.Monitoring.Enabled }} selectors: {} interval: 30s scrapeTimeout: 10s prometheusRules: enabled: {{ and .Modules.Observability.Enabled .Modules.Observability.Monitoring.Enabled }} selectors: {} rules: [] ingress: {{- if eq .Modules.SecretsStorage.Expose.Type "ingress" }} enabled: true {{- end }} accountEmail: {{ .Modules.Additional.CertManager.AccountEmail }} class: {{ .Modules.Additional.Ingress.Type }} annotations: {{- if eq .Modules.Additional.Ingress.Type "nginx" }} nginx.ingress.kubernetes.io/proxy-buffer-size: "128k" nginx.ingress.kubernetes.io/proxy-buffers: "4 256k" nginx.ingress.kubernetes.io/proxy-busy-buffers-size: "256k" {{- end }} tls: {{- if .Modules.SecretsStorage.Expose.Tls.Enabled }} enabled: true {{- end }} hosts: - host: {{ .Modules.SecretsStorage.Expose.Domain }} secretName: vault-tls