880 lines
32 KiB
Cheetah
880 lines
32 KiB
Cheetah
- name: vault
|
|
namespace: secrets-storage
|
|
create_namespace: true
|
|
chart_ref: {{ .Modules.SecretsStorage.ChartRef }}
|
|
chart_version: {{ .Modules.SecretsStorage.ChartVersion }}
|
|
{{- if .Modules.SecretsStorage.Enabled }}
|
|
release_state: "present"
|
|
{{- else }}
|
|
release_state: "absent"
|
|
{{- end }}
|
|
values:
|
|
global:
|
|
enabled: true
|
|
|
|
imagePullSecrets: []
|
|
tlsDisable: true
|
|
|
|
externalVaultAddr: ""
|
|
|
|
openshift: false
|
|
|
|
# Create PodSecurityPolicy for pods
|
|
psp:
|
|
enable: false
|
|
# Annotation for PodSecurityPolicy.
|
|
# This is a multi-line templated string map, and can also be set as YAML.
|
|
annotations: |
|
|
seccomp.security.alpha.kubernetes.io/allowedProfileNames: docker/default,runtime/default
|
|
apparmor.security.beta.kubernetes.io/allowedProfileNames: runtime/default
|
|
seccomp.security.alpha.kubernetes.io/defaultProfileName: runtime/default
|
|
apparmor.security.beta.kubernetes.io/defaultProfileName: runtime/default
|
|
|
|
serverTelemetry:
|
|
# Enable integration with the Prometheus Operator
|
|
# See the top level serverTelemetry section below before enabling this feature.
|
|
prometheusOperator: false
|
|
|
|
injector:
|
|
enabled: true
|
|
|
|
replicas: 1
|
|
|
|
# Configures the port the injector should listen on
|
|
port: 8080
|
|
|
|
# If multiple replicas are specified, by default a leader will be determined
|
|
# so that only one injector attempts to create TLS certificates.
|
|
leaderElector:
|
|
enabled: true
|
|
|
|
# If true, will enable a node exporter metrics endpoint at /metrics.
|
|
metrics:
|
|
enabled: false
|
|
|
|
# Deprecated: Please use global.externalVaultAddr instead.
|
|
externalVaultAddr: ""
|
|
|
|
# image sets the repo and tag of the vault-k8s image to use for the injector.
|
|
image:
|
|
repository: "{{ .Modules.SecretsStorage.Injector.Image }}"
|
|
tag: "{{ .Modules.SecretsStorage.Injector.Tag }}"
|
|
pullPolicy: IfNotPresent
|
|
|
|
# agentImage sets the repo and tag of the Vault image to use for the Vault Agent
|
|
# containers. This should be set to the official Vault image. Vault 1.3.1+ is
|
|
# required.
|
|
agentImage:
|
|
repository: "{{ .Modules.SecretsStorage.Agent.Image }}"
|
|
tag: "{{ .Modules.SecretsStorage.Agent.Tag }}"
|
|
agentDefaults:
|
|
cpuLimit: "500m"
|
|
cpuRequest: "250m"
|
|
memLimit: "128Mi"
|
|
memRequest: "64Mi"
|
|
# ephemeralLimit: "128Mi"
|
|
# ephemeralRequest: "64Mi"
|
|
|
|
# Default template type for secrets when no custom template is specified.
|
|
# Possible values include: "json" and "map".
|
|
template: "map"
|
|
|
|
# Default values within Agent's template_config stanza.
|
|
templateConfig:
|
|
exitOnRetryFailure: true
|
|
staticSecretRenderInterval: ""
|
|
|
|
# Used to define custom livenessProbe settings
|
|
livenessProbe:
|
|
# When a probe fails, Kubernetes will try failureThreshold times before giving up
|
|
failureThreshold: 2
|
|
# Number of seconds after the container has started before probe initiates
|
|
initialDelaySeconds: 5
|
|
# How often (in seconds) to perform the probe
|
|
periodSeconds: 2
|
|
# Minimum consecutive successes for the probe to be considered successful after having failed
|
|
successThreshold: 1
|
|
# Number of seconds after which the probe times out.
|
|
timeoutSeconds: 5
|
|
# Used to define custom readinessProbe settings
|
|
readinessProbe:
|
|
# When a probe fails, Kubernetes will try failureThreshold times before giving up
|
|
failureThreshold: 2
|
|
# Number of seconds after the container has started before probe initiates
|
|
initialDelaySeconds: 5
|
|
# How often (in seconds) to perform the probe
|
|
periodSeconds: 2
|
|
# Minimum consecutive successes for the probe to be considered successful after having failed
|
|
successThreshold: 1
|
|
# Number of seconds after which the probe times out.
|
|
timeoutSeconds: 5
|
|
# Used to define custom startupProbe settings
|
|
startupProbe:
|
|
# When a probe fails, Kubernetes will try failureThreshold times before giving up
|
|
failureThreshold: 12
|
|
# Number of seconds after the container has started before probe initiates
|
|
initialDelaySeconds: 5
|
|
# How often (in seconds) to perform the probe
|
|
periodSeconds: 5
|
|
# Minimum consecutive successes for the probe to be considered successful after having failed
|
|
successThreshold: 1
|
|
# Number of seconds after which the probe times out.
|
|
timeoutSeconds: 5
|
|
|
|
# Mount Path of the Vault Kubernetes Auth Method.
|
|
authPath: "auth/kubernetes"
|
|
|
|
# Configures the log verbosity of the injector.
|
|
# Supported log levels include: trace, debug, info, warn, error
|
|
logLevel: "info"
|
|
|
|
# Configures the log format of the injector. Supported log formats: "standard", "json".
|
|
logFormat: "standard"
|
|
|
|
# Configures all Vault Agent sidecars to revoke their token when shutting down
|
|
revokeOnShutdown: false
|
|
|
|
webhook:
|
|
# Configures failurePolicy of the webhook. The "unspecified" default behaviour depends on the
|
|
# API Tag of the WebHook.
|
|
# To block pod creation while the webhook is unavailable, set the policy to `Fail` below.
|
|
# See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#failure-policy
|
|
#
|
|
failurePolicy: Ignore
|
|
|
|
# matchPolicy specifies the approach to accepting changes based on the rules of
|
|
# the MutatingWebhookConfiguration.
|
|
# See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#matching-requests-matchpolicy
|
|
# for more details.
|
|
#
|
|
matchPolicy: Exact
|
|
|
|
# timeoutSeconds is the amount of seconds before the webhook request will be ignored
|
|
# or fails.
|
|
# If it is ignored or fails depends on the failurePolicy
|
|
# See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#timeouts
|
|
# for more details.
|
|
#
|
|
timeoutSeconds: 30
|
|
|
|
# namespaceSelector is the selector for restricting the webhook to only
|
|
# specific namespaces.
|
|
# See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#matching-requests-namespaceselector
|
|
# for more details.
|
|
# Example:
|
|
# namespaceSelector:
|
|
# matchLabels:
|
|
# sidecar-injector: enabled
|
|
namespaceSelector: {}
|
|
|
|
# objectSelector is the selector for restricting the webhook to only
|
|
# specific labels.
|
|
# See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#matching-requests-objectselector
|
|
# for more details.
|
|
# Example:
|
|
# objectSelector:
|
|
# matchLabels:
|
|
# vault-sidecar-injector: enabled
|
|
|
|
# Extra annotations to attach to the webhook
|
|
annotations: {}
|
|
|
|
# Deprecated: please use 'webhook.failurePolicy' instead
|
|
# Configures failurePolicy of the webhook. The "unspecified" default behaviour depends on the
|
|
# API Tag of the WebHook.
|
|
# To block pod creation while webhook is unavailable, set the policy to `Fail` below.
|
|
# See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#failure-policy
|
|
#
|
|
failurePolicy: Ignore
|
|
|
|
# Deprecated: please use 'webhook.namespaceSelector' instead
|
|
# namespaceSelector is the selector for restricting the webhook to only
|
|
# specific namespaces.
|
|
# See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#matching-requests-namespaceselector
|
|
# for more details.
|
|
# Example:
|
|
# namespaceSelector:
|
|
# matchLabels:
|
|
# sidecar-injector: enabled
|
|
namespaceSelector: {}
|
|
|
|
# Deprecated: please use 'webhook.objectSelector' instead
|
|
# objectSelector is the selector for restricting the webhook to only
|
|
# specific labels.
|
|
# See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#matching-requests-objectselector
|
|
# for more details.
|
|
# Example:
|
|
# objectSelector:
|
|
# matchLabels:
|
|
# vault-sidecar-injector: enabled
|
|
objectSelector: {}
|
|
|
|
# Deprecated: please use 'webhook.annotations' instead
|
|
# Extra annotations to attach to the webhook
|
|
webhookAnnotations: {}
|
|
|
|
certs:
|
|
# secretName is the name of the secret that has the TLS certificate and
|
|
# private key to serve the injector webhook. If this is null, then the
|
|
# injector will default to its automatic management mode that will assign
|
|
# a service account to the injector to generate its own certificates.
|
|
secretName: null
|
|
|
|
# caBundle is a base64-encoded PEM-encoded certificate bundle for the CA
|
|
# that signed the TLS certificate that the webhook serves. This must be set
|
|
# if secretName is non-null unless an external service like cert-manager is
|
|
# keeping the caBundle updated.
|
|
caBundle: ""
|
|
|
|
# certName and keyName are the names of the files within the secret for
|
|
# the TLS cert and private key, respectively. These have reasonable
|
|
# defaults but can be customized if necessary.
|
|
certName: tls.crt
|
|
keyName: tls.key
|
|
|
|
securityContext:
|
|
pod: {}
|
|
container: {}
|
|
|
|
resources: {}
|
|
|
|
# extraEnvironmentVars is a list of extra environment variables to set in the
|
|
# injector deployment.
|
|
extraEnvironmentVars: {}
|
|
# KUBERNETES_SERVICE_HOST: kubernetes.default.svc
|
|
|
|
topologySpreadConstraints: []
|
|
|
|
tolerations: []
|
|
|
|
nodeSelector: {}
|
|
|
|
priorityClassName: ""
|
|
|
|
annotations: {}
|
|
|
|
extraLabels: {}
|
|
|
|
hostNetwork: false
|
|
|
|
|
|
service:
|
|
# Extra annotations to attach to the injector service
|
|
annotations: {}
|
|
|
|
# Injector serviceAccount specific config
|
|
serviceAccount:
|
|
# Extra annotations to attach to the injector serviceAccount
|
|
annotations: {}
|
|
|
|
# A disruption budget limits the number of pods of a replicated application
|
|
# that are down simultaneously from voluntary disruptions
|
|
podDisruptionBudget: {}
|
|
# podDisruptionBudget:
|
|
# maxUnavailable: 1
|
|
|
|
# strategy for updating the deployment. This can be a multi-line string or a
|
|
# YAML map.
|
|
strategy: {}
|
|
# strategy: |
|
|
# rollingUpdate:
|
|
# maxSurge: 25%
|
|
# maxUnavailable: 25%
|
|
# type: RollingUpdate
|
|
|
|
server:
|
|
enabled: true
|
|
enterpriseLicense:
|
|
# The name of the Kubernetes secret that holds the enterprise license. The
|
|
# secret must be in the same namespace that Vault is installed into.
|
|
secretName: ""
|
|
# The key within the Kubernetes secret that holds the enterprise license.
|
|
secretKey: "license"
|
|
|
|
image:
|
|
repository: "{{ .Modules.SecretsStorage.Server.Image }}"
|
|
tag: "{{ .Modules.SecretsStorage.Server.Tag }}"
|
|
# Overrides the default Image Pull Policy
|
|
pullPolicy: IfNotPresent
|
|
|
|
updateStrategyType: "RollingUpdate"
|
|
|
|
# Supported log levels include: trace, debug, info, warn, error
|
|
logLevel: ""
|
|
|
|
# Supported log formats include: standard, json
|
|
logFormat: ""
|
|
|
|
resources: {}
|
|
|
|
hostAliases: []
|
|
# - ip: 127.0.0.1
|
|
# hostnames:
|
|
# - chart-example.local
|
|
|
|
route:
|
|
enabled: false
|
|
|
|
# When HA mode is enabled and K8s service registration is being used,
|
|
# configure the route to point to the Vault active service.
|
|
activeService: true
|
|
|
|
labels: {}
|
|
annotations: {}
|
|
host: chart-example.local
|
|
# tls will be passed directly to the route's TLS config, which
|
|
# can be used to configure other termination methods that terminate
|
|
# TLS at the router
|
|
tls:
|
|
termination: passthrough
|
|
|
|
# authDelegator enables a cluster role binding to be attached to the service
|
|
# account. This cluster role binding can be used to setup Kubernetes auth
|
|
# method. See https://developer.hashicorp.com/vault/docs/auth/kubernetes
|
|
authDelegator:
|
|
enabled: true
|
|
|
|
extraInitContainers: null
|
|
extraContainers: null
|
|
shareProcessNamespace: false
|
|
extraArgs: ""
|
|
|
|
extraPorts: null
|
|
# - containerPort: 8300
|
|
# name: http-monitoring
|
|
|
|
readinessProbe:
|
|
enabled: false
|
|
# If you need to use a http path instead of the default exec
|
|
# path: /v1/sys/health?standbyok=true
|
|
|
|
# Port number on which readinessProbe will be checked.
|
|
port: 8200
|
|
# When a probe fails, Kubernetes will try failureThreshold times before giving up
|
|
failureThreshold: 2
|
|
# Number of seconds after the container has started before probe initiates
|
|
initialDelaySeconds: 5
|
|
# How often (in seconds) to perform the probe
|
|
periodSeconds: 5
|
|
# Minimum consecutive successes for the probe to be considered successful after having failed
|
|
successThreshold: 1
|
|
# Number of seconds after which the probe times out.
|
|
timeoutSeconds: 3
|
|
# Used to enable a livenessProbe for the pods
|
|
livenessProbe:
|
|
enabled: false
|
|
# Used to define a liveness exec command. If provided, exec is preferred to httpGet (path) as the livenessProbe handler.
|
|
execCommand: []
|
|
# - /bin/sh
|
|
# - -c
|
|
# - /vault/userconfig/mylivenessscript/run.sh
|
|
# Path for the livenessProbe to use httpGet as the livenessProbe handler
|
|
path: "/v1/sys/health?standbyok=true"
|
|
# Port number on which livenessProbe will be checked if httpGet is used as the livenessProbe handler
|
|
port: 8200
|
|
# When a probe fails, Kubernetes will try failureThreshold times before giving up
|
|
failureThreshold: 2
|
|
# Number of seconds after the container has started before probe initiates
|
|
initialDelaySeconds: 60
|
|
# How often (in seconds) to perform the probe
|
|
periodSeconds: 5
|
|
# Minimum consecutive successes for the probe to be considered successful after having failed
|
|
successThreshold: 1
|
|
# Number of seconds after which the probe times out.
|
|
timeoutSeconds: 3
|
|
|
|
terminationGracePeriodSeconds: 10
|
|
|
|
# Used to set the sleep time during the preStop step
|
|
preStopSleepSeconds: 5
|
|
|
|
extraEnvironmentVars: {}
|
|
|
|
extraSecretEnvironmentVars: []
|
|
|
|
extraVolumes: []
|
|
|
|
volumes: null
|
|
|
|
volumeMounts: null
|
|
|
|
topologySpreadConstraints: []
|
|
|
|
tolerations: []
|
|
nodeSelector: {}
|
|
|
|
# Enables network policy for server pods
|
|
networkPolicy:
|
|
enabled: false
|
|
egress: []
|
|
# egress:
|
|
# - to:
|
|
# - ipBlock:
|
|
# cidr: 10.0.0.0/24
|
|
# ports:
|
|
# - protocol: TCP
|
|
# port: 443
|
|
ingress:
|
|
- from:
|
|
- namespaceSelector: {}
|
|
ports:
|
|
- port: 8200
|
|
protocol: TCP
|
|
- port: 8201
|
|
protocol: TCP
|
|
|
|
priorityClassName: ""
|
|
extraLabels: {}
|
|
|
|
annotations: {}
|
|
|
|
service:
|
|
enabled: true
|
|
# Enable or disable the vault-active service, which selects Vault pods that
|
|
# have labeled themselves as the cluster leader with `vault-active: "true"`.
|
|
active:
|
|
enabled: true
|
|
# Extra annotations for the service definition. This can either be YAML or a
|
|
# YAML-formatted multi-line templated string map of the annotations to apply
|
|
# to the active service.
|
|
annotations: {}
|
|
# Enable or disable the vault-standby service, which selects Vault pods that
|
|
# have labeled themselves as a cluster follower with `vault-active: "false"`.
|
|
standby:
|
|
enabled: true
|
|
# Extra annotations for the service definition. This can either be YAML or a
|
|
# YAML-formatted multi-line templated string map of the annotations to apply
|
|
# to the standby service.
|
|
annotations: {}
|
|
# When disabled, services may select Vault pods not deployed from the chart.
|
|
# Does not affect the headless vault-internal service with `ClusterIP: None`
|
|
instanceSelector:
|
|
enabled: true
|
|
# clusterIP controls whether a Cluster IP address is attached to the
|
|
# Vault service within Kubernetes. By default, the Vault service will
|
|
# be given a Cluster IP address, set to None to disable. When disabled
|
|
# Kubernetes will create a "headless" service. Headless services can be
|
|
# used to communicate with pods directly through DNS instead of a round-robin
|
|
# load balancer.
|
|
# clusterIP: None
|
|
|
|
# Configures the service type for the main Vault service. Can be ClusterIP
|
|
# or NodePort.
|
|
#type: ClusterIP
|
|
|
|
# The IP family and IP families options are to set the behaviour in a dual-stack environment.
|
|
# Omitting these values will let the service fall back to whatever the CNI dictates the defaults
|
|
# should be.
|
|
# These are only supported for kubernetes versions >=1.23.0
|
|
#
|
|
# Configures the service's supported IP family policy, can be either:
|
|
# SingleStack: Single-stack service. The control plane allocates a cluster IP for the Service, using the first configured service cluster IP range.
|
|
# PreferDualStack: Allocates IPv4 and IPv6 cluster IPs for the Service.
|
|
# RequireDualStack: Allocates Service .spec.ClusterIPs from both IPv4 and IPv6 address ranges.
|
|
ipFamilyPolicy: ""
|
|
|
|
# Sets the families that should be supported and the order in which they should be applied to ClusterIP as well.
|
|
# Can be IPv4 and/or IPv6.
|
|
ipFamilies: []
|
|
|
|
# Do not wait for pods to be ready before including them in the services'
|
|
# targets. Does not apply to the headless service, which is used for
|
|
# cluster-internal communication.
|
|
publishNotReadyAddresses: true
|
|
|
|
# The externalTrafficPolicy can be set to either Cluster or Local
|
|
# and is only valid for LoadBalancer and NodePort service types.
|
|
# The default value is Cluster.
|
|
# ref: https://kubernetes.io/docs/concepts/services-networking/service/#external-traffic-policy
|
|
externalTrafficPolicy: Cluster
|
|
|
|
# If type is set to "NodePort", a specific nodePort value can be configured,
|
|
# will be random if left blank.
|
|
#nodePort: 30000
|
|
|
|
# When HA mode is enabled
|
|
# If type is set to "NodePort", a specific nodePort value can be configured,
|
|
# will be random if left blank.
|
|
#activeNodePort: 30001
|
|
|
|
# When HA mode is enabled
|
|
# If type is set to "NodePort", a specific nodePort value can be configured,
|
|
# will be random if left blank.
|
|
#standbyNodePort: 30002
|
|
|
|
# Port on which Vault server is listening
|
|
port: 8200
|
|
# Target port to which the service should be mapped to
|
|
targetPort: 8200
|
|
# Extra annotations for the service definition. This can either be YAML or a
|
|
# YAML-formatted multi-line templated string map of the annotations to apply
|
|
# to the service.
|
|
annotations: {}
|
|
|
|
dataStorage:
|
|
enabled: true
|
|
size: {{ .Modules.SecretsStorage.Server.Persistence.DataStorage.Size }}
|
|
mountPath: "/vault/data"
|
|
storageClass: {{ .Modules.SecretsStorage.Server.Persistence.DataStorage.StorageClass }}
|
|
accessMode: ReadWriteOnce
|
|
annotations: {}
|
|
labels: {}
|
|
|
|
persistentVolumeClaimRetentionPolicy: {}
|
|
|
|
# required for ha installation
|
|
auditStorage:
|
|
enabled: false
|
|
# Size of the PVC created
|
|
size: {{ .Modules.SecretsStorage.Server.Persistence.AuditStorage.Size }}
|
|
# Location where the PVC will be mounted.
|
|
mountPath: "/vault/audit"
|
|
# Name of the storage class to use. If null it will use the
|
|
# configured default Storage Class.
|
|
storageClass: {{ .Modules.SecretsStorage.Server.Persistence.AuditStorage.StorageClass }}
|
|
# Access Mode of the storage device being used for the PVC
|
|
accessMode: ReadWriteOnce
|
|
# Annotations to apply to the PVC
|
|
annotations: {}
|
|
# Labels to apply to the PVC
|
|
labels: {}
|
|
|
|
dev:
|
|
enabled: false
|
|
|
|
# Set VAULT_DEV_ROOT_TOKEN_ID value
|
|
devRootToken: "root"
|
|
|
|
# Run Vault in "standalone" mode. This is the default mode that will deploy if
|
|
# no arguments are given to helm. This requires a PVC for data storage to use
|
|
# the "file" backend. This mode is not highly available and should not be scaled
|
|
# past a single replica.
|
|
standalone:
|
|
enabled: "-"
|
|
|
|
# config is a raw string of default configuration when using a Stateful
|
|
# deployment. Default is to use a PersistentVolumeClaim mounted at /vault/data
|
|
# and store data there. This is only used when using a Replica count of 1, and
|
|
# using a stateful set. This should be HCL.
|
|
|
|
# Note: Configuration files are stored in ConfigMaps so sensitive data
|
|
# such as passwords should be either mounted through extraSecretEnvironmentVars
|
|
# or through a Kube secret. For more information see:
|
|
# https://developer.hashicorp.com/vault/docs/platform/k8s/helm/run#protecting-sensitive-vault-configurations
|
|
config: |
|
|
ui = true
|
|
|
|
listener "tcp" {
|
|
tls_disable = 1
|
|
address = "[::]:8200"
|
|
cluster_address = "[::]:8201"
|
|
|
|
{{- if and .Modules.Observability.Enabled .Modules.Observability.Monitoring.Enabled }}
|
|
telemetry {
|
|
unauthenticated_metrics_access = "true"
|
|
}
|
|
{{- end }}
|
|
}
|
|
storage "file" {
|
|
path = "/vault/data"
|
|
}
|
|
|
|
{{- if and .Modules.Observability.Enabled .Modules.Observability.Monitoring.Enabled }}
|
|
telemetry {
|
|
prometheus_retention_time = "30s"
|
|
disable_hostname = true
|
|
}
|
|
{{- end }}
|
|
|
|
# Run Vault in "HA" mode. There are no storage requirements unless the audit log
|
|
# persistence is required. In HA mode Vault will configure itself to use Consul
|
|
# for its storage backend. The default configuration provided will work the Consul
|
|
# Helm project by default. It is possible to manually configure Vault to use a
|
|
# different HA backend.
|
|
ha:
|
|
enabled: false
|
|
replicas: 3
|
|
|
|
# Set the api_addr configuration for Vault HA
|
|
# See https://developer.hashicorp.com/vault/docs/configuration#api_addr
|
|
# If set to null, this will be set to the Pod IP Address
|
|
apiAddr: null
|
|
|
|
# Set the cluster_addr confuguration for Vault HA
|
|
# See https://developer.hashicorp.com/vault/docs/configuration#cluster_addr
|
|
clusterAddr: null
|
|
|
|
# Enables Vault's integrated Raft storage. Unlike the typical HA modes where
|
|
# Vault's persistence is external (such as Consul), enabling Raft mode will create
|
|
# persistent volumes for Vault to store data according to the configuration under server.dataStorage.
|
|
# The Vault cluster will coordinate leader elections and failovers internally.
|
|
raft:
|
|
# Enables Raft integrated storage
|
|
enabled: false
|
|
# Set the Node Raft ID to the name of the pod
|
|
setNodeId: false
|
|
|
|
config: |
|
|
ui = true
|
|
|
|
listener "tcp" {
|
|
tls_disable = 1
|
|
address = "[::]:8200"
|
|
cluster_address = "[::]:8201"
|
|
|
|
{{- if and .Modules.Observability.Enabled .Modules.Observability.Monitoring.Enabled }}
|
|
telemetry {
|
|
unauthenticated_metrics_access = "true"
|
|
}
|
|
{{- end }}
|
|
}
|
|
|
|
storage "raft" {
|
|
path = "/vault/data"
|
|
}
|
|
|
|
service_registration "kubernetes" {}
|
|
|
|
# config is a raw string of default configuration when using a Stateful
|
|
# deployment. Default is to use a Consul for its HA storage backend.
|
|
# This should be HCL.
|
|
|
|
# Note: Configuration files are stored in ConfigMaps so sensitive data
|
|
# such as passwords should be either mounted through extraSecretEnvironmentVars
|
|
# or through a Kube secret. For more information see:
|
|
# https://developer.hashicorp.com/vault/docs/platform/k8s/helm/run#protecting-sensitive-vault-configurations
|
|
config: |
|
|
ui = true
|
|
|
|
listener "tcp" {
|
|
tls_disable = 1
|
|
address = "[::]:8200"
|
|
cluster_address = "[::]:8201"
|
|
{{- if and .Modules.Observability.Enabled .Modules.Observability.Monitoring.Enabled }}
|
|
telemetry {
|
|
unauthenticated_metrics_access = "true"
|
|
}
|
|
{{- end }}
|
|
}
|
|
storage "consul" {
|
|
path = "vault"
|
|
address = "HOST_IP:8500"
|
|
}
|
|
|
|
service_registration "kubernetes" {}
|
|
|
|
# Example configuration for using auto-unseal, using Google Cloud KMS. The
|
|
# GKMS keys must already exist, and the cluster must have a service account
|
|
# that is authorized to access GCP KMS.
|
|
#seal "gcpckms" {
|
|
# project = "vault-helm-dev-246514"
|
|
# region = "global"
|
|
# key_ring = "vault-helm-unseal-kr"
|
|
# crypto_key = "vault-helm-unseal-key"
|
|
#}
|
|
|
|
{{- if and .Modules.Observability.Enabled .Modules.Observability.Monitoring.Enabled }}
|
|
telemetry {
|
|
prometheus_retention_time = "30s"
|
|
disable_hostname = true
|
|
}
|
|
{{- end }}
|
|
|
|
# A disruption budget limits the number of pods of a replicated application
|
|
# that are down simultaneously from voluntary disruptions
|
|
disruptionBudget:
|
|
enabled: true
|
|
|
|
# maxUnavailable will default to (n/2)-1 where n is the number of
|
|
# replicas. If you'd like a custom value, you can specify an override here.
|
|
maxUnavailable: null
|
|
|
|
serviceAccount:
|
|
create: true
|
|
name: ""
|
|
createSecret: false
|
|
annotations: {}
|
|
extraLabels: {}
|
|
serviceDiscovery:
|
|
enabled: true
|
|
|
|
statefulSet:
|
|
annotations: {}
|
|
securityContext:
|
|
pod: {}
|
|
container: {}
|
|
|
|
hostNetwork: false
|
|
|
|
# Vault UI
|
|
ui:
|
|
enabled: true
|
|
domain: {{ .Modules.SecretsStorage.Expose.Domain }}
|
|
publishNotReadyAddresses: true
|
|
# The service should only contain selectors for active Vault pod
|
|
activeVaultPodOnly: false
|
|
{{- if eq .Modules.SecretsStorage.Expose.Type "NodePort" }}
|
|
serviceType: "NodePort"
|
|
serviceNodePort: {{ .Modules.SecretsStorage.Expose.NodePort }}
|
|
{{- else }}
|
|
serviceType: "ClusterIP"
|
|
serviceNodePort: null
|
|
{{- end }}
|
|
externalPort: 8200
|
|
targetPort: 8200
|
|
|
|
serviceIPFamilyPolicy: ""
|
|
|
|
serviceIPFamilies: []
|
|
|
|
externalTrafficPolicy: Cluster
|
|
|
|
#loadBalancerSourceRanges:
|
|
# - 10.0.0.0/16
|
|
# - 1.78.23.3/32
|
|
|
|
# loadBalancerIP:
|
|
|
|
annotations: {}
|
|
|
|
csi:
|
|
# True if you want to install a secrets-store-csi-driver-provider-vault daemonset.
|
|
#
|
|
# Requires installing the secrets-store-csi-driver separately, see:
|
|
# https://github.com/kubernetes-sigs/secrets-store-csi-driver#install-the-secrets-store-csi-driver
|
|
#
|
|
# With the driver and provider installed, you can mount Vault secrets into volumes
|
|
# similar to the Vault Agent injector, and you can also sync those secrets into
|
|
# Kubernetes secrets.
|
|
enabled: {{ .Modules.SecretsStorage.CsiIntegration.Enabled }}
|
|
|
|
image:
|
|
repository: "{{ .Modules.SecretsStorage.CsiIntegration.Image }}"
|
|
tag: "{{ .Modules.SecretsStorage.CsiIntegration.Tag }}"
|
|
pullPolicy: IfNotPresent
|
|
|
|
volumes: null
|
|
|
|
volumeMounts: null
|
|
|
|
resources: {}
|
|
|
|
# Override the default secret name for the CSI Provider's HMAC key used for
|
|
# generating secret versions.
|
|
hmacSecretName: ""
|
|
|
|
daemonSet:
|
|
updateStrategy:
|
|
type: RollingUpdate
|
|
maxUnavailable: ""
|
|
# Extra annotations for the daemonSet. This can either be YAML or a
|
|
# YAML-formatted multi-line templated string map of the annotations to apply
|
|
# to the daemonSet.
|
|
annotations: {}
|
|
# Provider host path (must match the CSI provider's path)
|
|
providersDir: "/etc/kubernetes/secrets-store-csi-providers"
|
|
# Kubelet host path
|
|
kubeletRootDir: "/var/lib/kubelet"
|
|
# Extra labels to attach to the vault-csi-provider daemonSet
|
|
# This should be a YAML map of the labels to apply to the csi provider daemonSet
|
|
extraLabels: {}
|
|
# security context for the pod template and container in the csi provider daemonSet
|
|
securityContext:
|
|
pod: {}
|
|
container: {}
|
|
|
|
pod:
|
|
annotations: {}
|
|
tolerations: []
|
|
nodeSelector: {}
|
|
affinity: {}
|
|
extraLabels: {}
|
|
|
|
agent:
|
|
enabled: true
|
|
extraArgs: []
|
|
|
|
image:
|
|
repository: "{{ .Modules.SecretsStorage.Agent.Image }}"
|
|
tag: "{{ .Modules.SecretsStorage.Agent.Tag }}"
|
|
pullPolicy: IfNotPresent
|
|
|
|
logFormat: standard
|
|
logLevel: info
|
|
|
|
resources: {}
|
|
|
|
priorityClassName: ""
|
|
|
|
serviceAccount:
|
|
annotations: {}
|
|
extraLabels: {}
|
|
|
|
readinessProbe:
|
|
enabled: true
|
|
failureThreshold: 2
|
|
initialDelaySeconds: 5
|
|
periodSeconds: 5
|
|
successThreshold: 1
|
|
timeoutSeconds: 3
|
|
|
|
livenessProbe:
|
|
failureThreshold: 2
|
|
initialDelaySeconds: 5
|
|
periodSeconds: 5
|
|
successThreshold: 1
|
|
timeoutSeconds: 3
|
|
|
|
debug: false
|
|
extraArgs: []
|
|
|
|
serverTelemetry:
|
|
# Enable support for the Prometheus Operator. Currently, this chart does not support
|
|
# authenticating to Vault's metrics endpoint, so the following `telemetry{}` must be included
|
|
# in the `listener "tcp"{}` stanza
|
|
# telemetry {
|
|
# unauthenticated_metrics_access = "true"
|
|
# }
|
|
#
|
|
# See the `standalone.config` for a more complete example of this.
|
|
#
|
|
# In addition, a top level `telemetry{}` stanza must also be included in the Vault configuration:
|
|
#
|
|
# example:
|
|
# telemetry {
|
|
# prometheus_retention_time = "30s"
|
|
# disable_hostname = true
|
|
# }
|
|
#
|
|
# Configuration for monitoring the Vault server.
|
|
serviceMonitor:
|
|
enabled: {{ and .Modules.Observability.Enabled .Modules.Observability.Monitoring.Enabled }}
|
|
selectors: {}
|
|
interval: 30s
|
|
scrapeTimeout: 10s
|
|
|
|
prometheusRules:
|
|
enabled: {{ and .Modules.Observability.Enabled .Modules.Observability.Monitoring.Enabled }}
|
|
selectors: {}
|
|
rules: []
|
|
|
|
ingress:
|
|
{{- if eq .Modules.SecretsStorage.Expose.Type "ingress" }}
|
|
enabled: true
|
|
{{- end }}
|
|
accountEmail: {{ .Modules.Additional.CertManager.AccountEmail }}
|
|
class: {{ .Modules.Additional.Ingress.Type }}
|
|
annotations:
|
|
{{- if eq .Modules.Additional.Ingress.Type "nginx" }}
|
|
nginx.ingress.kubernetes.io/proxy-buffer-size: "128k"
|
|
nginx.ingress.kubernetes.io/proxy-buffers: "4 256k"
|
|
nginx.ingress.kubernetes.io/proxy-busy-buffers-size: "256k"
|
|
{{- end }}
|
|
tls:
|
|
{{- if .Modules.SecretsStorage.Expose.Tls.Enabled }}
|
|
enabled: true
|
|
{{- end }}
|
|
hosts:
|
|
- host: {{ .Modules.SecretsStorage.Expose.Domain }}
|
|
secretName: vault-tls
|