diff --git a/.github/workflows/generate-chart-readme.yml b/.github/workflows/generate-chart-readme.yml index 269cffef5..0d3487592 100644 --- a/.github/workflows/generate-chart-readme.yml +++ b/.github/workflows/generate-chart-readme.yml @@ -6,6 +6,9 @@ on: - master paths: - 'bitnami/airflow/values.yaml' + - 'bitnami/dokuwiki/values.yaml' + - 'bitnami/drupal/values.yaml' + - 'bitnami/ejbca/values.yaml' jobs: generate-chart-readme: diff --git a/bitnami/dokuwiki/Chart.yaml b/bitnami/dokuwiki/Chart.yaml index b13b9538e..1c6181f03 100644 --- a/bitnami/dokuwiki/Chart.yaml +++ b/bitnami/dokuwiki/Chart.yaml @@ -24,4 +24,4 @@ name: dokuwiki sources: - https://github.com/bitnami/bitnami-docker-dokuwiki - http://www.dokuwiki.org/ -version: 11.1.14 +version: 11.1.15 diff --git a/bitnami/dokuwiki/README.md b/bitnami/dokuwiki/README.md index 638c3169d..470e3886f 100644 --- a/bitnami/dokuwiki/README.md +++ b/bitnami/dokuwiki/README.md @@ -46,158 +46,162 @@ The command removes all the Kubernetes components associated with the chart and ## Parameters -The following table lists the configurable parameters of the DokuWiki chart and their default values per section/component: - ### Global parameters -| Parameter | Description | Default | -|---------------------------|-------------------------------------------------|---------------------------------------------------------| -| `global.imageRegistry` | Global Docker image registry | `nil` | -| `global.imagePullSecrets` | Global Docker registry secret names as an array | `[]` (does not add image pull secrets to deployed pods) | -| `global.storageClass` | Global storage class for dynamic provisioning | `nil` | +| Name | Description | Value | +| ------------------------- | ----------------------------------------------- | ----- | +| `global.imageRegistry` | Global Docker image registry | `nil` | +| `global.imagePullSecrets` | Global Docker registry secret names as an array | `[]` | +| `global.storageClass` | Global StorageClass for Persistent Volume(s) | `nil` | + ### Common parameters -| Parameter | Description | Default | -|---------------------|-------------------------------------------------------------------------------------------------------|---------------------------------------------------------| -| `commonAnnotations` | Annotations to add to all deployed objects | `[]` | -| `commonLabels` | Labels to add to all deployed objects | `nil` | -| `extraDeploy` | Array of extra objects to deploy with the release (evaluated as a template). | `nil` | -| `fullnameOverride` | String to fully override dokuwiki.fullname template with a string | `nil` | -| `image.pullPolicy` | Image pull policy | `Always` | -| `image.pullSecrets` | Specify docker-registry secret names as an array | `[]` (does not add image pull secrets to deployed pods) | -| `image.registry` | DokuWiki image registry | `docker.io` | -| `image.repository` | DokuWiki image name | `bitnami/dokuwiki` | -| `image.tag` | DokuWiki image tag | `{TAG_NAME}` | -| `image.debug` | Enable image debugging | `false` | -| `nameOverride` | String to partially override dokuwiki.fullname template with a string (will prepend the release name) | `nil` | -| `kubeVersion` | Force target Kubernetes version (using Helm capabilities if not set) | `nil` | +| Name | Description | Value | +| ------------------- | ----------------------------------------------------------------------------------------------------- | ----- | +| `kubeVersion` | Force target Kubernetes version (using Helm capabilities if not set) | `nil` | +| `nameOverride` | String to partially override dokuwiki.fullname template with a string (will prepend the release name) | `nil` | +| `fullnameOverride` | String to fully override dokuwiki.fullname template with a string | `nil` | +| `commonAnnotations` | Annotations to add to all deployed objects | `{}` | +| `commonLabels` | Labels to add to all deployed objects | `{}` | +| `extraDeploy` | Array of extra objects to deploy with the release (evaluated as a template). | `[]` | + ### Dokuwiki parameters -| Parameter | Description | Default | -|--------------------------------------|-----------------------------------------------------------------------------------------------------------------------|---------------------------------------------| -| `dokuwikiUsername` | User of the application | `user` | -| `dokuwikiFullName` | User's full name | `User Name` | -| `dokuwikiPassword` | Application password | _random 10 character alphanumeric string_ | -| `dokuwikiEmail` | User email | `user@example.com` | -| `dokuwikiWikiName` | Wiki name | `My Wiki` | -| `hostAliases` | Add deployment host aliases | `Check values.yaml` | -| `args` | Override default container args (useful when using custom images) | `nil` | -| `command` | Override default container command (useful when using custom images) | `nil` | -| `existingSecret` | Name of a secret with the application password | `nil` | -| `podLabels` | Add additional labels to the pod (evaluated as a template) | `nil` | -| `sidecars` | Attach additional containers to the pod (evaluated as a template) | `nil` | -| `podSecurityContext.enabled` | Enable securityContext on for DokuWiki deployment | `true` | -| `podSecurityContext.fsGroup` | Group to configure permissions for volumes | `1001` | -| `containerSecurityContext.enabled` | Enable securityContext on for DokuWiki deployment | `true` | -| `containerSecurityContext.runAsUser` | User for the securityContext | `1001` | -| `persistence.enabled` | Enable persistence using PVC | `true` | -| `persistence.storageClass` | PVC Storage Class for DokuWiki volume | `nil` (uses alpha storage class annotation) | -| `persistence.accessMode` | PVC Access Mode for DokuWiki volume | `ReadWriteOnce` | -| `persistence.size` | PVC Storage Request for DokuWiki volume | `8Gi` | -| `resources` | CPU/Memory resource requests/limits | Memory: `512Mi`, CPU: `300m` | -| `livenessProbe.enabled` | Enable/disable the liveness probe | `true` | -| `livenessProbe.initialDelaySeconds` | Delay before liveness probe is initiated | 120 | -| `livenessProbe.periodSeconds` | How often to perform the probe | 10 | -| `livenessProbe.timeoutSeconds` | When the probe times out | 5 | -| `livenessProbe.failureThreshold` | Minimum consecutive failures to be considered failed | 6 | -| `livenessProbe.successThreshold` | Minimum consecutive successes to be considered successful | 1 | -| `readinessProbe.enabled` | Enable/disable the readiness probe | `true` | -| `readinessProbe.initialDelaySeconds` | Delay before readinessProbe is initiated | 30 | -| `readinessProbe.periodSeconds ` | How often to perform the probe | 10 | -| `readinessProbe.timeoutSeconds` | When the probe times out | 5 | -| `readinessProbe.failureThreshold` | Minimum consecutive failures to be considered failed | 6 | -| `readinessProbe.successThreshold` | Minimum consecutive successes to be considered successful | 1 | -| `podAnnotations` | Pod annotations | `{}` | -| `podAffinityPreset` | Pod affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `""` | -| `podAntiAffinityPreset` | Pod anti-affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `soft` | -| `nodeAffinityPreset.type` | Node affinity preset type. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `""` | -| `nodeAffinityPreset.key` | Node label key to match Ignored if `affinity` is set. | `""` | -| `nodeAffinityPreset.values` | Node label values to match. Ignored if `affinity` is set. | `[]` | -| `affinity` | Affinity for pod assignment | `{}` (evaluated as a template) | -| `nodeSelector` | Node labels for pod assignment | `{}` (evaluated as a template) | -| `tolerations` | Tolerations for pod assignment | `[]` (evaluated as a template) | -| `customLivenessProbe` | Override default liveness probe | `nil` | -| `customReadinessProbe` | Override default readiness probe | `nil` | -| `extraVolumeMounts` | Array of extra volume mounts to be added to the container (evaluated as template). Normally used with `extraVolumes`. | `nil` | -| `extraVolumes` | Array of extra volumes to be added to the deployment (evaluated as template). Requires setting `extraVolumeMounts` | `nil` | -| `lifecycleHooks` | LifecycleHook to set additional configuration at startup Evaluated as a template | `` | -| `extraEnvVarsCM` | ConfigMap containing extra env vars | `nil` | -| `extraEnvVarsSecret` | Secret containing extra env vars (in case of sensitive data) | `nil` | +| Name | Description | Value | +| ------------------------------------ | --------------------------------------------------------------------------------------------------------------------- | ----------------------------- | +| `image.registry` | DokuWiki image registry | `docker.io` | +| `image.repository` | DokuWiki image repository | `bitnami/dokuwiki` | +| `image.tag` | DokuWiki image tag | `20200729.0.0-debian-10-r283` | +| `image.pullPolicy` | Image pull policy | `IfNotPresent` | +| `image.pullSecrets` | Image pull policy | `[]` | +| `image.debug` | Enable image debugging | `false` | +| `hostAliases` | Add deployment host aliases | `[]` | +| `dokuwikiUsername` | User of the application | `user` | +| `dokuwikiPassword` | Application password | `""` | +| `existingSecret` | Use an existing secret with the dokuwiki password | `""` | +| `dokuwikiEmail` | Admin email | `user@example.com` | +| `dokuwikiFullName` | User's Full Name | `User Name` | +| `dokuwikiWikiName` | Wiki name | `My Wiki` | +| `persistence.enabled` | Enable persistence using PVC | `true` | +| `persistence.storageClass` | PVC Storage Class for DokuWiki volume | `nil` | +| `persistence.accessMode` | PVC Access Mode for DokuWiki volume | `ReadWriteOnce` | +| `persistence.size` | PVC Storage Request for DokuWiki volume | `8Gi` | +| `podSecurityContext.enabled` | Enable securityContext on for DokuWiki deployment | `true` | +| `podSecurityContext.fsGroup` | Group to configure permissions for volumes | `1001` | +| `containerSecurityContext.enabled` | Enable securityContext on for DokuWiki deployment | `true` | +| `containerSecurityContext.runAsUser` | User for the securityContext | `1001` | +| `resources.requests` | The requested resources for the container | `{}` | +| `livenessProbe.enabled` | Enable/disable the liveness probe | `true` | +| `livenessProbe.initialDelaySeconds` | Delay before liveness probe is initiated | `120` | +| `livenessProbe.periodSeconds` | How often to perform the probe | `10` | +| `livenessProbe.timeoutSeconds` | When the probe times out | `5` | +| `livenessProbe.failureThreshold` | Minimum consecutive failures to be considered failed | `6` | +| `livenessProbe.successThreshold` | Minimum consecutive successes to be considered successful | `1` | +| `readinessProbe.enabled` | Enable/disable the readiness probe | `true` | +| `readinessProbe.initialDelaySeconds` | Delay before readinessProbe is initiated | `30` | +| `readinessProbe.periodSeconds` | Period seconds for readinessProbe | `10` | +| `readinessProbe.timeoutSeconds` | When the probe times out | `5` | +| `readinessProbe.failureThreshold` | Minimum consecutive failures to be considered failed | `6` | +| `readinessProbe.successThreshold` | Minimum consecutive successes to be considered successful | `1` | +| `podAffinityPreset` | Pod affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `""` | +| `podAntiAffinityPreset` | Pod anti-affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `soft` | +| `nodeAffinityPreset.type` | Node affinity preset type. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `""` | +| `nodeAffinityPreset.key` | Node label key to match Ignored if `affinity` is set. | `""` | +| `nodeAffinityPreset.values` | Node label values to match. Ignored if `affinity` is set. | `[]` | +| `affinity` | Affinity for pod assignment | `{}` | +| `nodeSelector` | Node labels for pod assignment | `{}` | +| `tolerations` | Tolerations for pod assignment | `[]` | +| `command` | Override default container command (useful when using custom images) | `nil` | +| `args` | Override default container args (useful when using custom images) | `nil` | +| `extraEnvVars` | An array to add extra env vars | `[]` | +| `extraEnvVarsCM` | ConfigMap containing extra env vars | `nil` | +| `extraEnvVarsSecret` | Secret containing extra env vars (in case of sensitive data) | `nil` | +| `podAnnotations` | Pod annotations | `{}` | +| `customLivenessProbe` | Override default liveness probe | `{}` | +| `customReadinessProbe` | Override default readiness probe | `{}` | +| `extraVolumes` | Array of extra volumes to be added to the deployment (evaluated as template). Requires setting `extraVolumeMounts` | `[]` | +| `extraVolumeMounts` | Array of extra volume mounts to be added to the container (evaluated as template). Normally used with `extraVolumes`. | `[]` | +| `lifecycleHooks` | LifecycleHook to set additional configuration at startup. Evaluated as a template | `nil` | +| `podLabels` | Add additional labels to the pod (evaluated as a template) | `{}` | +| `sidecars` | Attach additional containers to the pod (evaluated as a template) | `[]` | + ### Traffic Exposure Parameters -| Parameter | Description | Default | -|----------------------------------|----------------------------------------------------------|--------------------------------| -| `service.type` | Kubernetes Service type | `LoadBalancer` | -| `service.port` | Service HTTP port | `80` | -| `service.httpsPort` | Service HTTPS port | `443` | -| `service.loadBalancerIP` | Kubernetes LoadBalancerIP to request | `nil` | -| `service.externalTrafficPolicy` | Enable client source IP preservation | `Cluster` | -| `service.nodePorts.http` | Kubernetes http node port | `""` | -| `service.nodePorts.https` | Kubernetes https node port | `""` | -| `ingress.enabled` | Enable ingress controller resource | `false` | -| `ingress.certManager` | Add annotations for cert-manager | `false` | -| `ingress.hostname` | Default host for the ingress resource | `dokuwiki.local` | -| `ingress.path` | Default path for the ingress resource | `/` | -| `ingress.tls` | Create TLS Secret | `false` | -| `ingress.annotations` | Ingress annotations | `[]` (evaluated as a template) | -| `ingress.extraHosts[0].name` | Additional hostnames to be covered | `nil` | -| `ingress.extraHosts[0].path` | Additional hostnames to be covered | `nil` | -| `ingress.extraPaths` | Additional arbitrary path/backend objects | `nil` | -| `ingress.extraTls[0].hosts[0]` | TLS configuration for additional hostnames to be covered | `nil` | -| `ingress.extraTls[0].secretName` | TLS configuration for additional hostnames to be covered | `nil` | -| `ingress.secrets[0].name` | TLS Secret Name | `nil` | -| `ingress.secrets[0].certificate` | TLS Secret Certificate | `nil` | -| `ingress.secrets[0].key` | TLS Secret Key | `nil` | +| Name | Description | Value | +| ------------------------------- | --------------------------------------------------------------------------------------------- | ------------------------ | +| `service.type` | Kubernetes Service type | `LoadBalancer` | +| `service.loadBalancerIP` | Use serviceLoadBalancerIP to request a specific static IP, otherwise leave blank | `nil` | +| `service.port` | Service HTTP port | `80` | +| `service.httpsPort` | Service HTTPS port | `443` | +| `service.nodePorts` | Use nodePorts to request some specific ports when using NodePort | `{}` | +| `service.externalTrafficPolicy` | Enable client source IP preservation | `Cluster` | +| `ingress.enabled` | Set to true to enable ingress record generation | `false` | +| `ingress.certManager` | Set this to true in order to add the corresponding annotations for cert-manager | `false` | +| `ingress.pathType` | Ingress Path type | `ImplementationSpecific` | +| `ingress.apiVersion` | Override API Version (automatically detected if not set) | `nil` | +| `ingress.hostname` | When the ingress is enabled, a host pointing to this will be created | `dokuwiki.local` | +| `ingress.path` | The Path to Dokuwiki. You may need to set this to '/*' in order to use this | `ImplementationSpecific` | +| `ingress.annotations` | Ingress annotations done as key:value pairs | `{}` | +| `ingress.tls` | Enable TLS configuration for the hostname defined at ingress.hostname parameter | `false` | +| `ingress.extraHosts` | The list of additional hostnames to be covered with this ingress record. | `[]` | +| `ingress.extraPaths` | Any additional arbitrary paths that may need to be added to the ingress under the main host. | `[]` | +| `ingress.extraTls` | The tls configuration for additional hostnames to be covered with this ingress record. | `[]` | +| `ingress.secrets` | If you're providing your own certificates, please use this to add the certificates as secrets | `[]` | + ### Volume Permissions parameters -| Parameter | Description | Default | -|---------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------| -| `volumePermissions.enabled` | Enable init container that changes volume permissions in the data directory (for cases where the default k8s `runAsUser` and `fsUser` values do not work) | `false` | -| `volumePermissions.image.registry` | Init container volume-permissions image registry | `docker.io` | -| `volumePermissions.image.repository` | Init container volume-permissions image name | `bitnami/bitnami-shell` | -| `volumePermissions.image.tag` | Init container volume-permissions image tag | `"10"` | -| `volumePermissions.image.pullSecrets` | Specify docker-registry secret names as an array | `[]` (does not add image pull secrets to deployed pods) | -| `volumePermissions.image.pullPolicy` | Init container volume-permissions image pull policy | `Always` | -| `volumePermissions.resources` | Init container resource requests/limit | `nil` | +| Name | Description | Value | +| -------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------- | +| `volumePermissions.enabled` | Enable init container that changes volume permissions in the data directory (for cases where the default k8s `runAsUser` and `fsUser` values do not work) | `false` | +| `volumePermissions.image.registry` | Init container volume-permissions image registry | `docker.io` | +| `volumePermissions.image.repository` | Init container volume-permissions image name | `bitnami/bitnami-shell` | +| `volumePermissions.image.tag` | Init container volume-permissions image tag | `10-debian-10-r112` | +| `volumePermissions.image.pullPolicy` | Init container volume-permissions image pull policy | `Always` | +| `volumePermissions.image.pullSecrets` | Specify docker-registry secret names as an array | `[]` | +| `volumePermissions.resources.limits` | The resources limits for the container | `{}` | +| `volumePermissions.resources.requests` | The requested resources for the container | `{}` | + ### Metrics parameters -| Parameter | Description | Default | -|-----------------------------|--------------------------------------------------|--------------------------------------------------------------| -| `metrics.enabled` | Start a side-car prometheus exporter | `false` | -| `metrics.image.registry` | Apache exporter image registry | `docker.io` | -| `metrics.image.repository` | Apache exporter image name | `bitnami/apache-exporter` | -| `metrics.image.tag` | Apache exporter image tag | `{TAG_NAME}` | -| `metrics.image.pullPolicy` | Image pull policy | `IfNotPresent` | -| `metrics.image.pullSecrets` | Specify docker-registry secret names as an array | `[]` (does not add image pull secrets to deployed pods) | -| `metrics.podAnnotations` | Additional annotations for Metrics exporter pod | `{prometheus.io/scrape: "true", prometheus.io/port: "9117"}` | -| `metrics.resources` | Exporter resource requests/limit | {} | +| Name | Description | Value | +| --------------------------- | ------------------------------------------------ | ------------------------- | +| `metrics.enabled` | Start a exporter side-car | `false` | +| `metrics.image.registry` | Apache exporter image registry | `docker.io` | +| `metrics.image.repository` | Apache exporter image name | `bitnami/apache-exporter` | +| `metrics.image.tag` | Apache exporter image tag | `0.9.0-debian-10-r11` | +| `metrics.image.pullPolicy` | Image pull policy | `IfNotPresent` | +| `metrics.image.pullSecrets` | Specify docker-registry secret names as an array | `[]` | +| `metrics.podAnnotations` | Additional annotations for Metrics exporter pod | `{}` | +| `metrics.resources` | Exporter resource requests/limit | `{}` | + ### Certificate injection parameters -| Parameter | Description | Default | -|------------------------------------------------------|----------------------------------------------------------------------|------------------------------------------| +| Name | Description | Value | +| ---------------------------------------------------- | -------------------------------------------------------------------- | ---------------------------------------- | | `certificates.customCertificate.certificateSecret` | Secret containing the certificate and key to add | `""` | -| `certificates.customCertificate.chainSecret.name` | Name of the secret containing the certificate chain | `""` | -| `certificates.customCertificate.chainSecret.key` | Key of the certificate chain file inside the secret | `""` | +| `certificates.customCertificate.chainSecret.name` | Name of the secret containing the certificate chain | `nil` | +| `certificates.customCertificate.chainSecret.key` | Key of the certificate chain file inside the secret | `nil` | | `certificates.customCertificate.certificateLocation` | Location in the container to store the certificate | `/etc/ssl/certs/ssl-cert-snakeoil.pem` | | `certificates.customCertificate.keyLocation` | Location in the container to store the private key | `/etc/ssl/private/ssl-cert-snakeoil.key` | -| `certificates.customCertificate.chainLocation` | Location in the container to store the certificate chain | `/etc/ssl/certs/chain.pem` | +| `certificates.customCertificate.chainLocation` | Location in the container to store the certificate chain | `/etc/ssl/certs/mychain.pem` | | `certificates.customCAs` | Defines a list of secrets to import into the container trust store | `[]` | -| `certificates.image.registry` | Container sidecar registry | `docker.io` | -| `certificates.image.repository` | Container sidecar image | `bitnami/bitnami-shell` | -| `certificates.image.tag` | Container sidecar image tag | `"10"` | -| `certificates.image.pullPolicy` | Container sidecar image pull policy | `IfNotPresent` | -| `certificates.image.pullSecrets` | Container sidecar image pull secrets | `image.pullSecrets` | -| `certificates.args` | Override default container args (useful when using custom images) | `nil` | | `certificates.command` | Override default container command (useful when using custom images) | `nil` | +| `certificates.args` | Override default container args (useful when using custom images) | `nil` | | `certificates.extraEnvVars` | Container sidecar extra environment variables (eg proxy) | `[]` | | `certificates.extraEnvVarsCM` | ConfigMap containing extra env vars | `nil` | | `certificates.extraEnvVarsSecret` | Secret containing extra env vars (in case of sensitive data) | `nil` | +| `certificates.image.registry` | Container sidecar registry | `docker.io` | +| `certificates.image.repository` | Container sidecar image | `bitnami/bitnami-shell` | +| `certificates.image.tag` | Container sidecar image tag | `10-debian-10-r112` | +| `certificates.image.pullPolicy` | Container sidecar image pull policy | `IfNotPresent` | +| `certificates.image.pullSecrets` | Container sidecar image pull secrets | `[]` | + The above parameters map to the env variables defined in [bitnami/dokuwiki](http://github.com/bitnami/bitnami-docker-dokuwiki). For more information please refer to the [bitnami/dokuwiki](http://github.com/bitnami/bitnami-docker-dokuwiki) image documentation. diff --git a/bitnami/dokuwiki/values.yaml b/bitnami/dokuwiki/values.yaml index 0a7163518..a42afef70 100644 --- a/bitnami/dokuwiki/values.yaml +++ b/bitnami/dokuwiki/values.yaml @@ -1,15 +1,52 @@ +## @section Global parameters ## Global Docker image parameters ## Please, note that this will override the image parameters, including dependencies, configured to use the global value -## Current available global Docker image parameters: imageRegistry and imagePullSecrets +## Current available global Docker image parameters: imageRegistry, imagePullSecrets and storageClass + +## @param global.imageRegistry Global Docker image registry +## @param global.imagePullSecrets Global Docker registry secret names as an array +## @param global.storageClass Global StorageClass for Persistent Volume(s) ## -# global: -# imageRegistry: myRegistryName -# imagePullSecrets: -# - myRegistryKeySecretName -# storageClass: myStorageClass +global: + imageRegistry: + ## E.g. + ## imagePullSecrets: + ## - myRegistryKeySecretName + ## + imagePullSecrets: [] + storageClass: + +## @section Common parameters + +## @param kubeVersion Force target Kubernetes version (using Helm capabilities if not set) +## +kubeVersion: +## @param nameOverride String to partially override dokuwiki.fullname template with a string (will prepend the release name) +## +nameOverride: +## @param fullnameOverride String to fully override dokuwiki.fullname template with a string +## +fullnameOverride: +## @param commonAnnotations Annotations to add to all deployed objects +## +commonAnnotations: {} +## @param commonLabels Labels to add to all deployed objects +## +commonLabels: {} +## @param extraDeploy Array of extra objects to deploy with the release (evaluated as a template). +## +extraDeploy: [] + +## @section Dokuwiki parameters ## Bitnami DokuWiki image version ## ref: https://hub.docker.com/r/bitnami/dokuwiki/tags/ +## @param image.registry DokuWiki image registry +## @param image.repository DokuWiki image repository +## @param image.tag DokuWiki image tag +## @param image.pullPolicy Image pull policy +## @param image.pullSecrets Image pull policy +## @param image.debug Enable image debugging ## image: registry: docker.io @@ -23,180 +60,54 @@ image: ## Optionally specify an array of imagePullSecrets. ## Secrets must be manually created in the namespace. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ + ## e.g: + ## pullSecrets: + ## - myRegistryKeySecretName ## - # pullSecrets: - # - myRegistryKeySecretName - + pullSecrets: [] ## Set to true if you would like to see extra information on logs ## It turns BASH and/or NAMI debugging in the image ## debug: false - -## Force target Kubernetes version (using Helm capabilites if not set) -## -kubeVersion: - -## String to partially override dokuwiki.fullname template (will maintain the release name) -## -nameOverride: - -## String to fully override dokuwiki.fullname template -## -fullnameOverride: - -## Deployment pod host aliases +## @param hostAliases [array] Add deployment host aliases ## https://kubernetes.io/docs/concepts/services-networking/add-entries-to-pod-etc-hosts-with-host-aliases/ ## hostAliases: - # Necessary for apache-exporter to work + ## Necessary for apache-exporter to work + ## - ip: "127.0.0.1" hostnames: - "status.localhost" - -## User of the application +## @param dokuwikiUsername User of the application ## ref: https://github.com/bitnami/bitnami-docker-dokuwiki#environment-variables ## dokuwikiUsername: user - -## Application password +## @param dokuwikiPassword Application password ## Defaults to a random 10-character alphanumeric string if not set ## ref: https://github.com/bitnami/bitnami-docker-dokuwiki#environment-variables ## dokuwikiPassword: "" - -## Use an existing secret with the dokuwiki password +## @param existingSecret Use an existing secret with the dokuwiki password ## existingSecret: "" - -## Admin email +## @param dokuwikiEmail Admin email ## ref: https://github.com/bitnami/bitnami-docker-dokuwiki#environment-variables ## dokuwikiEmail: user@example.com - -## User's Full Name +## @param dokuwikiFullName User's Full Name ## ref: https://github.com/bitnami/bitnami-docker-dokuwiki#environment-variables ## dokuwikiFullName: User Name - -## Name of the Wiki +## @param dokuwikiWikiName Wiki name ## ref: https://github.com/bitnami/bitnami-docker-dokuwiki#environment-variables ## dokuwikiWikiName: My Wiki - -## Kubernetes svc configuration -## -service: - ## Kubernetes svc type - ## For minikube, set this to NodePort, elsewhere use LoadBalancer - ## - type: LoadBalancer - ## Use serviceLoadBalancerIP to request a specific static IP, - ## otherwise leave blank - ## - loadBalancerIP: - # HTTP Port - port: 80 - # HTTPS Port - httpsPort: 443 - ## Use nodePorts to requets some specific ports when using NodePort - ## nodePorts: - ## http: - ## https: - ## - nodePorts: - http: "" - https: "" - ## Enable client source IP preservation - ## ref http://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip - ## - externalTrafficPolicy: Cluster - -## Configure the ingress resource that allows you to access the -## Dokuwiki installation. Set up the URL -## ref: http://kubernetes.io/docs/user-guide/ingress/ -## -ingress: - ## Set to true to enable ingress record generation - ## - enabled: false - - ## Set this to true in order to add the corresponding annotations for cert-manager - ## - certManager: false - - ## Ingress Path type - ## - pathType: ImplementationSpecific - - ## Override API Version (automatically detected if not set) - ## - apiVersion: - - ## When the ingress is enabled, a host pointing to this will be created - ## - hostname: dokuwiki.local - - ## The Path to Dokuwiki. You may need to set this to '/*' in order to use this - ## with ALB ingress controllers. - ## - path: / - - ## Ingress annotations done as key:value pairs - ## For a full list of possible ingress annotations, please see - ## ref: https://github.com/kubernetes/ingress-nginx/blob/master/docs/user-guide/nginx-configuration/annotations.md - ## - ## If certManager is set to true, annotation kubernetes.io/tls-acme: "true" will automatically be set - ## - annotations: {} - - ## Enable TLS configuration for the hostname defined at ingress.hostname parameter - ## TLS certificates will be retrieved from a TLS secret with name: {{- printf "%s-tls" .Values.ingress.hostname }} - ## You can use the ingress.secrets parameter to create this TLS secret or relay on cert-manager to create it - ## - tls: false - - ## The list of additional hostnames to be covered with this ingress record. - ## Most likely the hostname above will be enough, but in the event more hosts are needed, this is an array - ## extraHosts: - ## - name: dokuwiki.local - ## path: / - ## - - ## Any additional arbitrary paths that may need to be added to the ingress under the main host. - ## For example: The ALB ingress controller requires a special rule for handling SSL redirection. - ## extraPaths: - ## - path: /* - ## backend: - ## serviceName: ssl-redirect - ## servicePort: use-annotation - ## - - ## The tls configuration for additional hostnames to be covered with this ingress record. - ## see: https://kubernetes.io/docs/concepts/services-networking/ingress/#tls - ## extraTls: - ## - hosts: - ## - dokuwiki.local - ## secretName: dokuwiki.local-tls - ## - - ## If you're providing your own certificates, please use this to add the certificates as secrets - ## key and certificate should start with -----BEGIN CERTIFICATE----- or - ## -----BEGIN RSA PRIVATE KEY----- - ## - ## name should line up with a tlsSecret set further up - ## If you're using cert-manager, this is unneeded, as it will create the secret for you if it is not set - ## - ## It is also possible to create and manage the certificates outside of this helm chart - ## Please see README.md for more information - ## - secrets: [] - ## - name: dokuwiki.local-tls - ## key: - ## certificate: - ## - ## Enable persistence using Persistent Volume Claims ## ref: http://kubernetes.io/docs/user-guide/persistent-volumes/ +## @param persistence.enabled Enable persistence using PVC +## @param persistence.storageClass PVC Storage Class for DokuWiki volume +## @param persistence.accessMode PVC Access Mode for DokuWiki volume +## @param persistence.size PVC Storage Request for DokuWiki volume ## persistence: enabled: true @@ -210,12 +121,258 @@ persistence: storageClass: accessMode: ReadWriteOnce size: 8Gi +## @param podSecurityContext.enabled Enable securityContext on for DokuWiki deployment +## @param podSecurityContext.fsGroup Group to configure permissions for volumes +## +podSecurityContext: + enabled: true + fsGroup: 1001 +## SecurityContext configuration for the container +## @param containerSecurityContext.enabled Enable securityContext on for DokuWiki deployment +## @param containerSecurityContext.runAsUser User for the securityContext +## +containerSecurityContext: + enabled: true + runAsUser: 1001 +## Configure resource requests and limits +## ref: http://kubernetes.io/docs/user-guide/compute-resources/ +## @param resources.requests [object] The requested resources for the container +## +resources: + requests: + memory: 512Mi + cpu: 300m +## Configure extra options for liveness and readiness probes +## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/#configure-probes) +## @param livenessProbe.enabled Enable/disable the liveness probe +## @param livenessProbe.initialDelaySeconds Delay before liveness probe is initiated +## @param livenessProbe.periodSeconds How often to perform the probe +## @param livenessProbe.timeoutSeconds When the probe times out +## @param livenessProbe.failureThreshold Minimum consecutive failures to be considered failed +## @param livenessProbe.successThreshold Minimum consecutive successes to be considered successful +## +livenessProbe: + enabled: true + initialDelaySeconds: 120 + periodSeconds: 10 + timeoutSeconds: 5 + failureThreshold: 6 + successThreshold: 1 +## Configure extra options for liveness and readiness probes +## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/#configure-probes) +## @param readinessProbe.enabled Enable/disable the readiness probe +## @param readinessProbe.initialDelaySeconds Delay before readinessProbe is initiated +## @param readinessProbe.periodSeconds Period seconds for readinessProbe +## @param readinessProbe.timeoutSeconds When the probe times out +## @param readinessProbe.failureThreshold Minimum consecutive failures to be considered failed +## @param readinessProbe.successThreshold Minimum consecutive successes to be considered successful +## +readinessProbe: + enabled: true + initialDelaySeconds: 30 + periodSeconds: 10 + timeoutSeconds: 5 + failureThreshold: 6 + successThreshold: 1 +## @param podAffinityPreset Pod affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` +## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity +## +podAffinityPreset: "" +## @param podAntiAffinityPreset Pod anti-affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` +## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity +## +podAntiAffinityPreset: soft +## Node affinity preset +## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity +## @param nodeAffinityPreset.type Node affinity preset type. Ignored if `affinity` is set. Allowed values: `soft` or `hard` +## @param nodeAffinityPreset.key Node label key to match Ignored if `affinity` is set. +## @param nodeAffinityPreset.values Node label values to match. Ignored if `affinity` is set. +## +nodeAffinityPreset: + type: "" + ## E.g. + ## key: "kubernetes.io/e2e-az-name" + ## + key: "" + ## E.g. + ## values: + ## - e2e-az1 + ## - e2e-az2 + ## + values: [] +## @param affinity Affinity for pod assignment +## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity +## Note: podAffinityPreset, podAntiAffinityPreset, and nodeAffinityPreset will be ignored when it's set +## +affinity: {} +## @param nodeSelector Node labels for pod assignment +## Ref: https://kubernetes.io/docs/user-guide/node-selection/ +## +nodeSelector: {} +## @param tolerations Tolerations for pod assignment +## Ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/ +## +tolerations: [] +## @param command Override default container command (useful when using custom images) +## +command: +## @param args Override default container args (useful when using custom images) +## +args: +## @param extraEnvVars An array to add extra env vars +## +extraEnvVars: [] +## @param extraEnvVarsCM ConfigMap containing extra env vars +## +extraEnvVarsCM: +## @param extraEnvVarsSecret Secret containing extra env vars (in case of sensitive data) +## +extraEnvVarsSecret: +## @param podAnnotations Pod annotations +## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/ +## +podAnnotations: {} +## @param customLivenessProbe Override default liveness probe +## +customLivenessProbe: {} +## @param customReadinessProbe Override default readiness probe +## +customReadinessProbe: {} +## @param extraVolumes Array of extra volumes to be added to the deployment (evaluated as template). Requires setting `extraVolumeMounts` +## +extraVolumes: [] +## @param extraVolumeMounts Array of extra volume mounts to be added to the container (evaluated as template). Normally used with `extraVolumes`. +## +extraVolumeMounts: [] +## @param lifecycleHooks LifecycleHook to set additional configuration at startup. Evaluated as a template +## +lifecycleHooks: +## @param podLabels Add additional labels to the pod (evaluated as a template) +## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/ +## +podLabels: {} +## @param sidecars Attach additional containers to the pod (evaluated as a template) +## +sidecars: [] + +## @section Traffic Exposure Parameters + +## Kubernetes svc configuration +## +service: + ## @param service.type Kubernetes Service type + ## For minikube, set this to NodePort, elsewhere use LoadBalancer + ## + type: LoadBalancer + ## @param service.loadBalancerIP Use serviceLoadBalancerIP to request a specific static IP, otherwise leave blank + ## + loadBalancerIP: + ## @param service.port Service HTTP port + ## + port: 80 + ## @param service.httpsPort Service HTTPS port + ## + httpsPort: 443 + ## @param service.nodePorts [object] Use nodePorts to request some specific ports when using NodePort + ## nodePorts: + ## http: + ## https: + ## + nodePorts: + http: "" + https: "" + ## @param service.externalTrafficPolicy Enable client source IP preservation + ## ref http://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip + ## + externalTrafficPolicy: Cluster +## Configure the ingress resource that allows you to access the +## Dokuwiki installation. Set up the URL +## ref: http://kubernetes.io/docs/user-guide/ingress/ +## +ingress: + ## @param ingress.enabled Set to true to enable ingress record generation + ## + enabled: false + ## @param ingress.certManager Set this to true in order to add the corresponding annotations for cert-manager + ## + certManager: false + ## @param ingress.pathType Ingress Path type + ## + pathType: ImplementationSpecific + ## @param ingress.apiVersion Override API Version (automatically detected if not set) + ## + apiVersion: + ## @param ingress.hostname When the ingress is enabled, a host pointing to this will be created + ## + hostname: dokuwiki.local + ## @param ingress.path The Path to Dokuwiki. You may need to set this to '/*' in order to use this + ## with ALB ingress controllers. + ## + path: / + ## @param ingress.annotations Ingress annotations done as key:value pairs + ## For a full list of possible ingress annotations, please see + ## ref: https://github.com/kubernetes/ingress-nginx/blob/master/docs/user-guide/nginx-configuration/annotations.md + ## + ## If certManager is set to true, annotation kubernetes.io/tls-acme: "true" will automatically be set + ## + annotations: {} + ## @param ingress.tls Enable TLS configuration for the hostname defined at ingress.hostname parameter + ## TLS certificates will be retrieved from a TLS secret with name: {{- printf "%s-tls" .Values.ingress.hostname }} + ## You can use the ingress.secrets parameter to create this TLS secret or relay on cert-manager to create it + ## + tls: false + ## @param ingress.extraHosts The list of additional hostnames to be covered with this ingress record. + ## Most likely the hostname above will be enough, but in the event more hosts are needed, this is an array + ## extraHosts: + ## - name: dokuwiki.local + ## path: / + extraHosts: [] + ## @param ingress.extraPaths Any additional arbitrary paths that may need to be added to the ingress under the main host. + ## For example: The ALB ingress controller requires a special rule for handling SSL redirection. + ## extraPaths: + ## - path: /* + ## backend: + ## serviceName: ssl-redirect + ## servicePort: use-annotation + extraPaths: [] + ## @param ingress.extraTls The tls configuration for additional hostnames to be covered with this ingress record. + ## see: https://kubernetes.io/docs/concepts/services-networking/ingress/#tls + ## extraTls: + ## - hosts: + ## - dokuwiki.local + ## secretName: dokuwiki.local-tls + extraTls: [] + ## @param ingress.secrets If you're providing your own certificates, please use this to add the certificates as secrets + ## key and certificate should start with -----BEGIN CERTIFICATE----- or + ## -----BEGIN RSA PRIVATE KEY----- + ## + ## name should line up with a tlsSecret set further up + ## If you're using cert-manager, this is unneeded, as it will create the secret for you if it is not set + ## + ## It is also possible to create and manage the certificates outside of this helm chart + ## Please see README.md for more information + ## Example: + ## - name: dokuwiki.local-tls + ## key: + ## certificate: + ## + secrets: [] + +## @section Volume Permissions parameters ## Init containers parameters: ## volumePermissions: Change the owner and group of the persistent volume mountpoint to runAsUser:fsGroup values from the securityContext section. ## volumePermissions: + ## @param volumePermissions.enabled Enable init container that changes volume permissions in the data directory (for cases where the default k8s `runAsUser` and `fsUser` values do not work) + ## enabled: false + ## @param volumePermissions.image.registry Init container volume-permissions image registry + ## @param volumePermissions.image.repository Init container volume-permissions image name + ## @param volumePermissions.image.tag Init container volume-permissions image tag + ## @param volumePermissions.image.pullPolicy Init container volume-permissions image pull policy + ## @param volumePermissions.image.pullSecrets Specify docker-registry secret names as an array + ## image: registry: docker.io repository: bitnami/bitnami-shell @@ -229,176 +386,39 @@ volumePermissions: ## - myRegistryKeySecretName ## Init containers' resource requests and limits ## ref: http://kubernetes.io/docs/user-guide/compute-resources/ + ## We usually recommend not to specify default resources and to leave this as a conscious + ## choice for the user. This also increases chances charts run on environments with little + ## resources, such as Minikube. If you do want to specify resources, uncomment the following + ## lines, adjust them as necessary, and remove the curly braces after 'resources:'. + ## @param volumePermissions.resources.limits The resources limits for the container + ## @param volumePermissions.resources.requests The requested resources for the container ## resources: - ## We usually recommend not to specify default resources and to leave this as a conscious - ## choice for the user. This also increases chances charts run on environments with little - ## resources, such as Minikube. If you do want to specify resources, uncomment the following - ## lines, adjust them as necessary, and remove the curly braces after 'resources:'. - ## + ## Example: + ## limits: + ## cpu: 100m + ## memory: 128Mi limits: {} - ## cpu: 100m - ## memory: 128Mi - ## + ## Examples: + ## requests: + ## cpu: 100m + ## memory: 128Mi requests: {} - ## cpu: 100m - ## memory: 128Mi - ## -## SecurityContext configuration for the pods -## -podSecurityContext: - enabled: true - fsGroup: 1001 - -## SecurityContext configuration for the container -## -containerSecurityContext: - enabled: true - runAsUser: 1001 - -## Configure resource requests and limits -## ref: http://kubernetes.io/docs/user-guide/compute-resources/ -## -resources: - requests: - memory: 512Mi - cpu: 300m - -## Configure extra options for liveness and readiness probes -## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/#configure-probes) -## -livenessProbe: - enabled: true - initialDelaySeconds: 120 - periodSeconds: 10 - timeoutSeconds: 5 - failureThreshold: 6 - successThreshold: 1 -readinessProbe: - enabled: true - initialDelaySeconds: 30 - periodSeconds: 10 - timeoutSeconds: 5 - failureThreshold: 6 - successThreshold: 1 - -## Pod affinity preset -## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity -## Allowed values: soft, hard -## -podAffinityPreset: "" - -## Pod anti-affinity preset -## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity -## Allowed values: soft, hard -## -podAntiAffinityPreset: soft - -## Node affinity preset -## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity -## Allowed values: soft, hard -## -nodeAffinityPreset: - ## Node affinity type - ## Allowed values: soft, hard - ## - type: "" - ## Node label key to match - ## E.g. - ## key: "kubernetes.io/e2e-az-name" - ## - key: "" - ## Node label values to match - ## E.g. - ## values: - ## - e2e-az1 - ## - e2e-az2 - ## - values: [] - -## Affinity for pod assignment -## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity -## Note: podAffinityPreset, podAntiAffinityPreset, and nodeAffinityPreset will be ignored when it's set -## -affinity: {} - -## Node labels for pod assignment -## Ref: https://kubernetes.io/docs/user-guide/node-selection/ -## -nodeSelector: {} - -## Tolerations for pod assignment -## Ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/ -## -tolerations: [] - -## Override container command -## -command: - -## Override container args -## -args: - -## An array to add extra env vars -## -extraEnvVars: [] - -## ConfigMap with extra environment variables -## -extraEnvVarsCM: - -## Secret with extra environment variables -## -extraEnvVarsSecret: - -## Pod annotations -## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/ -## -podAnnotations: {} - -## Common annotations to add to all Harbor resources (sub-charts are not considered). Evaluated as a template -## -commonAnnotations: {} - -## Common labels to add to all Harbor resources (sub-charts are not considered). Evaluated as a template -## -commonLabels: {} - -## Custom Liveness probe -## -customLivenessProbe: {} - -## Custom Rediness probe -## -customReadinessProbe: {} - -## Extra volumes to add to the deployment -## -extraVolumes: [] - -## Extra volume mounts to add to the container -## -extraVolumeMounts: [] - -## lifecycleHooks for the container to automate configuration before or after startup. -## -lifecycleHooks: - -## Pod extra labels -## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/ -## -podLabels: {} - -## Extra sidecar containers to add to the deployment -## -sidecars: [] +## @section Metrics parameters ## Prometheus Exporter / Metrics ## metrics: + ## @param metrics.enabled Start a exporter side-car + ## enabled: false + ## @param metrics.image.registry Apache exporter image registry + ## @param metrics.image.repository Apache exporter image name + ## @param metrics.image.tag Apache exporter image tag + ## @param metrics.image.pullPolicy Image pull policy + ## @param metrics.image.pullSecrets Specify docker-registry secret names as an array + ## image: registry: docker.io repository: bitnami/apache-exporter @@ -407,50 +427,68 @@ metrics: ## Optionally specify an array of imagePullSecrets. ## Secrets must be manually created in the namespace. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ + ## e.g: + ## pullSecrets: + ## - myRegistryKeySecretName ## pullSecrets: [] - # - myRegistryKeySecretName - ## Metrics exporter pod Annotation and Labels + ## @param metrics.podAnnotations [object] Additional annotations for Metrics exporter pod ## podAnnotations: prometheus.io/scrape: "true" prometheus.io/port: "9117" - ## Metrics exporter resource requests and limits - ## ref: http://kubernetes.io/docs/user-guide/compute-resources/ - ## + ## @param metrics.resources Exporter resource requests/limit + ## ref: http://kubernetes.io/docs/user-guide/compute-resources/ + ## resources: {} -# Add custom certificates and certificate authorities to redmine container +## @section Certificate injection parameters + +## Add custom certificates and certificate authorities to redmine container +## certificates: + ## @param certificates.customCertificate.certificateSecret Secret containing the certificate and key to add + ## @param certificates.customCertificate.chainSecret.name Name of the secret containing the certificate chain + ## @param certificates.customCertificate.chainSecret.key Key of the certificate chain file inside the secret + ## @param certificates.customCertificate.certificateLocation Location in the container to store the certificate + ## @param certificates.customCertificate.keyLocation Location in the container to store the private key + ## @param certificates.customCertificate.chainLocation Location in the container to store the certificate chain + ## customCertificate: certificateSecret: "" - chainSecret: {} - # name: secret-name - # key: secret-key + chainSecret: + name: + key: certificateLocation: /etc/ssl/certs/ssl-cert-snakeoil.pem keyLocation: /etc/ssl/private/ssl-cert-snakeoil.key chainLocation: /etc/ssl/certs/mychain.pem + ## @param certificates.customCAs Defines a list of secrets to import into the container trust store + ## customCAs: [] - ## Override container command + ## @param certificates.command Override default container command (useful when using custom images) ## command: - ## Override container args + ## @param certificates.args Override default container args (useful when using custom images) + ## args: + ## - secret: custom-CA + ## - secret: more-custom-CAs ## args: - # - secret: custom-CA - # - secret: more-custom-CAs - ## An array to add extra env vars + ## @param certificates.extraEnvVars Container sidecar extra environment variables (eg proxy) ## extraEnvVars: [] - - ## ConfigMap with extra environment variables + ## @param certificates.extraEnvVarsCM ConfigMap containing extra env vars ## extraEnvVarsCM: - - ## Secret with extra environment variables + ## @param certificates.extraEnvVarsSecret Secret containing extra env vars (in case of sensitive data) ## extraEnvVarsSecret: - + ## @param certificates.image.registry Container sidecar registry + ## @param certificates.image.repository Container sidecar image + ## @param certificates.image.tag Container sidecar image tag + ## @param certificates.image.pullPolicy Container sidecar image pull policy + ## @param certificates.image.pullSecrets Container sidecar image pull secrets + ## image: registry: docker.io repository: bitnami/bitnami-shell @@ -460,10 +498,8 @@ certificates: ## ref: http://kubernetes.io/docs/user-guide/images/#pre-pulling-images ## pullPolicy: IfNotPresent - # pullPolicy: + ## e.g: + ## pullSecrets: + ## - myRegistryKeySecretName + ## pullSecrets: [] - # - myRegistryKeySecretName - -## Array with extra yaml to deploy with the chart. Evaluated as a template -## -extraDeploy: [] diff --git a/bitnami/drupal/Chart.yaml b/bitnami/drupal/Chart.yaml index b7d87c29a..dab8ae30e 100644 --- a/bitnami/drupal/Chart.yaml +++ b/bitnami/drupal/Chart.yaml @@ -31,4 +31,4 @@ name: drupal sources: - https://github.com/bitnami/bitnami-docker-drupal - http://www.drupal.org/ -version: 10.2.24 +version: 10.2.25 diff --git a/bitnami/drupal/README.md b/bitnami/drupal/README.md index 049dedb83..9b7cc9e4e 100644 --- a/bitnami/drupal/README.md +++ b/bitnami/drupal/README.md @@ -48,183 +48,201 @@ The command removes all the Kubernetes components associated with the chart and ## Parameters -The following table lists the configurable parameters of the Drupal chart and their default values per section/component: - ### Global parameters -| Parameter | Description | Default | -|---------------------------|-------------------------------------------------|---------------------------------------------------------| -| `global.imageRegistry` | Global Docker image registry | `nil` | -| `global.imagePullSecrets` | Global Docker registry secret names as an array | `[]` (does not add image pull secrets to deployed pods) | -| `global.storageClass` | Global storage class for dynamic provisioning | `nil` | +| Name | Description | Value | +| ------------------------- | ----------------------------------------------- | ----- | +| `global.imageRegistry` | Global Docker image registry | `nil` | +| `global.imagePullSecrets` | Global Docker registry secret names as an array | `[]` | +| `global.storageClass` | Global StorageClass for Persistent Volume(s) | `nil` | + ### Common parameters -| Parameter | Description | Default | -|---------------------|------------------------------------------------------------------------------|---------------------------------------------------------| -| `image.registry` | Drupal image registry | `docker.io` | -| `image.repository` | Drupal Image name | `bitnami/drupal` | -| `image.tag` | Drupal Image tag | `{TAG_NAME}` | -| `image.pullPolicy` | Drupal image pull policy | `IfNotPresent` | -| `image.pullSecrets` | Specify docker-registry secret names as an array | `[]` (does not add image pull secrets to deployed pods) | -| `image.debug` | Specify if debug logs should be enabled | `false` | -| `nameOverride` | String to partially override drupal.fullname template | `nil` | -| `fullnameOverride` | String to fully override drupal.fullname template | `nil` | -| `commonLabels` | Labels to add to all deployed objects | `nil` | -| `commonAnnotations` | Annotations to add to all deployed objects | `[]` | -| `extraDeploy` | Array of extra objects to deploy with the release (evaluated as a template). | `nil` | -| `kubeVersion` | Force target Kubernetes version (using Helm capabilities if not set) | `nil` | +| Name | Description | Value | +| ------------------- | ---------------------------------------------------------------------------------------------------------- | ----- | +| `kubeVersion` | Force target Kubernetes version (using Helm capabilities if not set) | `nil` | +| `nameOverride` | String to partially override drupal.fullname template (will maintain the release name) | `nil` | +| `fullnameOverride` | String to fully override drupal.fullname template | `nil` | +| `commonAnnotations` | Common annotations to add to all Drupal resources (sub-charts are not considered). Evaluated as a template | `{}` | +| `commonLabels` | Common labels to add to all Drupal resources (sub-charts are not considered). Evaluated as a template | `{}` | +| `extraDeploy` | Array of extra objects to deploy with the release (evaluated as a template). | `[]` | + ### Drupal parameters -| Parameter | Description | Default | -|--------------------------------------|-----------------------------------------------------------------------------------------------------------------------|------------------------------------------------| -| `affinity` | Affinity for pod assignment | `{}` (evaluated as a template) | -| `allowEmptyPassword` | Allow DB blank passwords | `yes` | -| `args` | Override default container args (useful when using custom images) | `nil` | -| `command` | Override default container command (useful when using custom images) | `nil` | -| `containerPorts.http` | Sets http port inside Drupal container | `8080` | -| `containerPorts.https` | Sets https port inside Drupal container | `8443` | -| `containerSecurityContext.enabled` | Enable Drupal containers' Security Context | `true` | -| `containerSecurityContext.runAsUser` | Drupal containers' Security Context | `1001` | -| `customLivenessProbe` | Override default liveness probe | `nil` | -| `customReadinessProbe` | Override default readiness probe | `nil` | -| `drupalEmail` | Admin email | `user@example.com` | -| `drupalPassword` | Application password | _random 10 character long alphanumeric string_ | -| `drupalProfile` | Drupal installation profile | `standard` | -| `drupalUsername` | User of the application | `user` | -| `drupalSkipInstall` | Skip Drupal installation wizard | `false` | -| `existingSecret` | Name of a secret with the application password | `nil` | -| `extraEnvVarsCM` | ConfigMap containing extra env vars | `nil` | -| `extraEnvVarsSecret` | Secret containing extra env vars (in case of sensitive data) | `nil` | -| `extraEnvVars` | Extra environment variables | `nil` | -| `extraVolumeMounts` | Array of extra volume mounts to be added to the container (evaluated as template). Normally used with `extraVolumes`. | `nil` | -| `extraVolumes` | Array of extra volumes to be added to the deployment (evaluated as template). Requires setting `extraVolumeMounts` | `nil` | -| `initContainers` | Add additional init containers to the pod (evaluated as a template) | `nil` | -| `lifecycleHooks` | LifecycleHook to set additional configuration at startup Evaluated as a template | `` | -| `livenessProbe` | Liveness probe configuration | `Check values.yaml file` | -| `nodeAffinityPreset.type` | Node affinity preset type. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `""` | -| `nodeAffinityPreset.key` | Node label key to match Ignored if `affinity` is set. | `""` | -| `nodeAffinityPreset.values` | Node label values to match. Ignored if `affinity` is set. | `[]` | -| `nodeSelector` | Node labels for pod assignment | `{}` (evaluated as a template) | -| `persistence.accessMode` | PVC Access Mode for Drupal volume | `ReadWriteOnce` | -| `persistence.enabled` | Enable persistence using PVC | `true` | -| `persistence.existingClaim` | An Existing PVC name | `nil` | -| `persistence.hostPath` | Host mount path for Drupal volume | `nil` (will not mount to a host path) | -| `persistence.size` | PVC Storage Request for Drupal volume | `8Gi` | -| `persistence.storageClass` | PVC Storage Class for Drupal volume | `nil` (uses alpha storage class annotation) | -| `podAffinityPreset` | Pod affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `""` | -| `podAntiAffinityPreset` | Pod anti-affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `soft` | -| `podAnnotations` | Pod annotations | `{}` | -| `hostAliases` | Add deployment host aliases | `Check values.yaml` | -| `podLabels` | Add additional labels to the pod (evaluated as a template) | `nil` | -| `podSecurityContext.enabled` | Enable Drupal pods' Security Context | `true` | -| `podSecurityContext.fsGroup` | Drupal pods' group ID | `1001` | -| `readinessProbe` | Readiness probe configuration | `Check values.yaml file` | -| `replicaCount` | Number of Drupal Pods to run | `1` | -| `resources` | CPU/Memory resource requests/limits | Memory: `512Mi`, CPU: `300m` | -| `sidecars` | Attach additional containers to the pod (evaluated as a template) | `nil` | -| `smtpHost` | SMTP host | `nil` | -| `smtpPort` | SMTP port | `nil` (but prestashop internal default is 25) | -| `smtpProtocol` | SMTP Protocol (options: ssl,tls, nil) | `nil` | -| `smtpUser` | SMTP user | `nil` | -| `smtpPassword` | SMTP password | `nil` | -| `tolerations` | Tolerations for pod assignment | `[]` (evaluated as a template) | -| `updateStrategy` | Deployment update strategy | `nil` | +| Name | Description | Value | +| ------------------------------------ | --------------------------------------------------------------------------------------------------------------------- | -------------------- | +| `image.registry` | Drupal image registry | `docker.io` | +| `image.repository` | Drupal Image name | `bitnami/drupal` | +| `image.tag` | Drupal Image tag | `9.2.0-debian-10-r0` | +| `image.pullPolicy` | Drupal image pull policy | `IfNotPresent` | +| `image.pullSecrets` | Specify docker-registry secret names as an array | `[]` | +| `image.debug` | Specify if debug logs should be enabled | `false` | +| `replicaCount` | Number of Drupal Pods to run (requires ReadWriteMany PVC support) | `1` | +| `drupalProfile` | Drupal installation profile | `standard` | +| `drupalSkipInstall` | Skip Drupal installation wizard. Useful for migrations and restoring from SQL dump | `false` | +| `drupalUsername` | User of the application | `user` | +| `drupalPassword` | Application password | `""` | +| `drupalEmail` | Admin email | `user@example.com` | +| `allowEmptyPassword` | Allow DB blank passwords | `true` | +| `command` | Override default container command (useful when using custom images) | `nil` | +| `args` | Override default container args (useful when using custom images) | `nil` | +| `updateStrategy.type` | Update strategy - only really applicable for deployments with RWO PVs attached | `RollingUpdate` | +| `hostAliases` | Add deployment host aliases | `[]` | +| `extraEnvVars` | Extra environment variables | `[]` | +| `extraEnvVarsCM` | ConfigMap containing extra env vars | `nil` | +| `extraEnvVarsSecret` | Secret containing extra env vars (in case of sensitive data) | `nil` | +| `extraVolumes` | Array of extra volumes to be added to the deployment (evaluated as template). Requires setting `extraVolumeMounts` | `[]` | +| `extraVolumeMounts` | Array of extra volume mounts to be added to the container (evaluated as template). Normally used with `extraVolumes`. | `[]` | +| `initContainers` | Add additional init containers to the pod (evaluated as a template) | `[]` | +| `sidecars` | Attach additional containers to the pod (evaluated as a template) | `[]` | +| `tolerations` | Tolerations for pod assignment | `[]` | +| `existingSecret` | Name of a secret with the application password | `nil` | +| `smtpHost` | SMTP host | `nil` | +| `smtpPort` | SMTP port | `nil` | +| `smtpUser` | SMTP user | `nil` | +| `smtpPassword` | SMTP password | `nil` | +| `smtpProtocol` | SMTP Protocol (options: ssl,tls, nil) | `nil` | +| `containerPorts` | Container ports | `{}` | +| `sessionAffinity` | Control where client requests go, to the same pod or round-robin. Values: ClientIP or None | `None` | +| `persistence.enabled` | Enable persistence using PVC | `true` | +| `persistence.storageClass` | PVC Storage Class for Drupal volume | `nil` | +| `persistence.accessMode` | PVC Access Mode for Drupal volume | `ReadWriteOnce` | +| `persistence.size` | PVC Storage Request for Drupal volume | `8Gi` | +| `persistence.existingClaim` | A manually managed Persistent Volume Claim | `nil` | +| `persistence.hostPath` | If defined, the drupal-data volume will mount to the specified hostPath. | `nil` | +| `podAffinityPreset` | Pod affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `""` | +| `podAntiAffinityPreset` | Pod anti-affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `soft` | +| `nodeAffinityPreset.type` | Node affinity preset type. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `""` | +| `nodeAffinityPreset.key` | Node label key to match Ignored if `affinity` is set. | `""` | +| `nodeAffinityPreset.values` | Node label values to match. Ignored if `affinity` is set. | `[]` | +| `affinity` | Affinity for pod assignment | `{}` | +| `nodeSelector` | Node labels for pod assignment. Evaluated as a template. | `{}` | +| `resources` | CPU/Memory resource requests/limits | `{}` | +| `podSecurityContext.enabled` | Enable Drupal pods' Security Context | `true` | +| `podSecurityContext.fsGroup` | Drupal pods' group ID | `1001` | +| `containerSecurityContext.enabled` | Enable Drupal containers' Security Context | `true` | +| `containerSecurityContext.runAsUser` | Drupal containers' Security Context | `1001` | +| `livenessProbe.enabled` | Enable livenessProbe | `true` | +| `livenessProbe.path` | Request path for livenessProbe | `/user/login` | +| `livenessProbe.initialDelaySeconds` | Initial delay seconds for livenessProbe | `600` | +| `livenessProbe.periodSeconds` | Period seconds for livenessProbe | `10` | +| `livenessProbe.timeoutSeconds` | Timeout seconds for livenessProbe | `5` | +| `livenessProbe.failureThreshold` | Failure threshold for livenessProbe | `5` | +| `livenessProbe.successThreshold` | Success threshold for livenessProbe | `1` | +| `readinessProbe.enabled` | Enable readinessProbe | `true` | +| `readinessProbe.path` | Request path for readinessProbe | `/user/login` | +| `readinessProbe.initialDelaySeconds` | Initial delay seconds for readinessProbe | `30` | +| `readinessProbe.periodSeconds` | Period seconds for readinessProbe | `5` | +| `readinessProbe.timeoutSeconds` | Timeout seconds for readinessProbe | `1` | +| `readinessProbe.failureThreshold` | Failure threshold for readinessProbe | `5` | +| `readinessProbe.successThreshold` | Success threshold for readinessProbe | `1` | +| `customLivenessProbe` | Override default liveness probe | `{}` | +| `customReadinessProbe` | Override default readiness probe | `{}` | +| `lifecycleHooks` | LifecycleHook to set additional configuration at startup Evaluated as a template | `nil` | +| `podAnnotations` | Pod annotations | `{}` | +| `podLabels` | Add additional labels to the pod (evaluated as a template) | `{}` | + ### Traffic Exposure Parameters -| Parameter | Description | Default | -|----------------------------------|----------------------------------------------------------|--------------------------------| -| `service.type` | Kubernetes Service type | `LoadBalancer` | -| `service.port` | Service HTTP port | `80` | -| `service.httpsPort` | Service HTTPS port | `443` | -| `service.externalTrafficPolicy` | Enable client source IP preservation | `Cluster` | -| `service.nodePorts.http` | Kubernetes http node port | `""` | -| `service.nodePorts.https` | Kubernetes https node port | `""` | -| `ingress.enabled` | Enable ingress controller resource | `false` | -| `ingress.certManager` | Add annotations for cert-manager | `false` | -| `ingress.hostname` | Default host for the ingress resource | `drupal.local` | -| `ingress.path` | Default path for the ingress resource | `/` | -| `ingress.tls` | Create TLS Secret | `false` | -| `ingress.annotations` | Ingress annotations | `[]` (evaluated as a template) | -| `ingress.extraHosts[0].name` | Additional hostnames to be covered | `nil` | -| `ingress.extraHosts[0].path` | Additional hostnames to be covered | `nil` | -| `ingress.extraPaths` | Additional arbitrary path/backend objects | `nil` | -| `ingress.extraTls[0].hosts[0]` | TLS configuration for additional hostnames to be covered | `nil` | -| `ingress.extraTls[0].secretName` | TLS configuration for additional hostnames to be covered | `nil` | -| `ingress.secrets[0].name` | TLS Secret Name | `nil` | -| `ingress.secrets[0].certificate` | TLS Secret Certificate | `nil` | -| `ingress.secrets[0].key` | TLS Secret Key | `nil` | +| Name | Description | Value | +| ---------------------------------- | --------------------------------------------------------------------------------------------- | ------------------------ | +| `service.type` | Kubernetes Service type | `LoadBalancer` | +| `service.port` | Service HTTP port | `80` | +| `service.httpsPort` | Service HTTPS port | `443` | +| `service.loadBalancerSourceRanges` | Restricts access for LoadBalancer (only with `service.type: LoadBalancer`) | `[]` | +| `service.loadBalancerIP` | loadBalancerIP for the Drupal Service (optional, cloud specific) | `nil` | +| `service.nodePorts` | Kubernetes node port | `{}` | +| `service.externalTrafficPolicy` | Enable client source IP preservation | `Cluster` | +| `ingress.enabled` | Enable ingress controller resource | `false` | +| `ingress.certManager` | Add annotations for cert-manager | `false` | +| `ingress.pathType` | Ingress Path type | `ImplementationSpecific` | +| `ingress.apiVersion` | Override API Version (automatically detected if not set) | `nil` | +| `ingress.hostname` | Default host for the ingress resource | `drupal.local` | +| `ingress.path` | The Path to Drupal. You may need to set this to '/*' in order to use this | `ImplementationSpecific` | +| `ingress.annotations` | Ingress annotations done as key:value pairs | `{}` | +| `ingress.tls` | Enable TLS configuration for the hostname defined at ingress.hostname parameter | `false` | +| `ingress.extraHosts` | The list of additional hostnames to be covered with this ingress record. | `[]` | +| `ingress.extraPaths` | Any additional arbitrary paths that may need to be added to the ingress under the main host. | `[]` | +| `ingress.extraTls` | The tls configuration for additional hostnames to be covered with this ingress record. | `[]` | +| `ingress.secrets` | If you're providing your own certificates, please use this to add the certificates as secrets | `[]` | + ### Database parameters -| Parameter | Description | Default | -|---------------------------------------------|------------------------------------------------------------------------------------------|------------------------------------------------| -| `mariadb.enabled` | Whether to use the MariaDB chart | `true` | -| `mariadb.architecture` | MariaDB architecture (`standalone` or `replication`) | `standalone` | -| `mariadb.auth.rootPassword` | Password for the MariaDB `root` user | _random 10 character alphanumeric string_ | -| `mariadb.auth.database` | Database name to create | `bitnami_drupal` | -| `mariadb.auth.username` | Database user to create | `bn_drupal` | -| `mariadb.auth.password` | Password for the database | _random 10 character long alphanumeric string_ | -| `mariadb.primary.persistence.enabled` | Enable database persistence using PVC | `true` | -| `mariadb.primary.persistence.existingClaim` | Name of an existing `PersistentVolumeClaim` for MariaDB primary replicas | `nil` | -| `mariadb.primary.persistence.accessModes` | Database Persistent Volume Access Modes | `[ReadWriteOnce]` | -| `mariadb.primary.persistence.size` | Database Persistent Volume Size | `8Gi` | -| `mariadb.primary.persistence.hostPath` | Set path in case you want to use local host path volumes (not recommended in production) | `nil` | -| `mariadb.primary.persistence.storageClass` | MariaDB primary persistent volume storage Class | `nil` | -| `externalDatabase.user` | Existing username in the external db | `bn_drupal` | -| `externalDatabase.password` | Password for the above username | `""` | -| `externalDatabase.database` | Name of the existing database | `bitnami_drupal` | -| `externalDatabase.host` | Host of the existing database | `nil` | -| `externalDatabase.port` | Port of the existing database | `3306` | +| Name | Description | Value | +| ------------------------------------------- | ---------------------------------------------------------------------------------------- | ---------------- | +| `mariadb.enabled` | Whether to deploy a mariadb server to satisfy the applications database requirements | `true` | +| `mariadb.architecture` | MariaDB architecture (`standalone` or `replication`) | `standalone` | +| `mariadb.auth.rootPassword` | Password for the MariaDB `root` user | `""` | +| `mariadb.auth.database` | Database name to create | `bitnami_drupal` | +| `mariadb.auth.username` | Database user to create | `bn_drupal` | +| `mariadb.auth.password` | Password for the database | `""` | +| `mariadb.primary.persistence.enabled` | Enable database persistence using PVC | `true` | +| `mariadb.primary.persistence.storageClass` | MariaDB primary persistent volume storage Class | `nil` | +| `mariadb.primary.persistence.accessModes` | Database Persistent Volume Access Modes | `[]` | +| `mariadb.primary.persistence.size` | Database Persistent Volume Size | `8Gi` | +| `mariadb.primary.persistence.hostPath` | Set path in case you want to use local host path volumes (not recommended in production) | `nil` | +| `mariadb.primary.persistence.existingClaim` | Name of an existing `PersistentVolumeClaim` for MariaDB primary replicas | `nil` | +| `externalDatabase.host` | Host of the existing database | `""` | +| `externalDatabase.port` | Port of the existing database | `3306` | +| `externalDatabase.user` | Existing username in the external db | `bn_drupal` | +| `externalDatabase.password` | Password for the above username | `""` | +| `externalDatabase.database` | Name of the existing database | `bitnami_drupal` | + ### Volume Permissions parameters -| Parameter | Description | Default | -|---------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------| -| `volumePermissions.enabled` | Enable init container that changes volume permissions in the data directory (for cases where the default k8s `runAsUser` and `fsUser` values do not work) | `false` | -| `volumePermissions.image.registry` | Init container volume-permissions image registry | `docker.io` | -| `volumePermissions.image.repository` | Init container volume-permissions image name | `bitnami/bitnami-shell` | -| `volumePermissions.image.tag` | Init container volume-permissions image tag | `"10"` | -| `volumePermissions.image.pullSecrets` | Specify docker-registry secret names as an array | `[]` (does not add image pull secrets to deployed pods) | -| `volumePermissions.image.pullPolicy` | Init container volume-permissions image pull policy | `Always` | -| `volumePermissions.resources` | Init container resource requests/limit | `nil` | +| Name | Description | Value | +| -------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------- | +| `volumePermissions.enabled` | Enable init container that changes volume permissions in the data directory (for cases where the default k8s `runAsUser` and `fsUser` values do not work) | `false` | +| `volumePermissions.image.registry` | Init container volume-permissions image registry | `docker.io` | +| `volumePermissions.image.repository` | Init container volume-permissions image name | `bitnami/bitnami-shell` | +| `volumePermissions.image.tag` | Init container volume-permissions image tag | `10-debian-10-r111` | +| `volumePermissions.image.pullPolicy` | Init container volume-permissions image pull policy | `Always` | +| `volumePermissions.image.pullSecrets` | Specify docker-registry secret names as an array | `[]` | +| `volumePermissions.resources.limits` | The resources limits for the container | `{}` | +| `volumePermissions.resources.requests` | The requested resources for the container | `{}` | + ### Metrics parameters -| Parameter | Description | Default | -|-----------------------------|--------------------------------------------------|--------------------------------------------------------------| -| `metrics.enabled` | Start a side-car prometheus exporter | `false` | -| `metrics.image.registry` | Apache exporter image registry | `docker.io` | -| `metrics.image.repository` | Apache exporter image name | `bitnami/apache-exporter` | -| `metrics.image.tag` | Apache exporter image tag | `{TAG_NAME}` | -| `metrics.image.pullPolicy` | Image pull policy | `IfNotPresent` | -| `metrics.image.pullSecrets` | Specify docker-registry secret names as an array | `[]` (does not add image pull secrets to deployed pods) | -| `metrics.podAnnotations` | Additional annotations for Metrics exporter pod | `{prometheus.io/scrape: "true", prometheus.io/port: "9117"}` | -| `metrics.resources` | Exporter resource requests/limit | {} | +| Name | Description | Value | +| --------------------------- | ------------------------------------------------ | ------------------------- | +| `metrics.enabled` | Start a exporter side-car | `false` | +| `metrics.image.registry` | Apache exporter image registry | `docker.io` | +| `metrics.image.repository` | Apache exporter image repository | `bitnami/apache-exporter` | +| `metrics.image.tag` | Apache exporter image tag | `0.9.0-debian-10-r9` | +| `metrics.image.pullPolicy` | Image pull policy | `IfNotPresent` | +| `metrics.image.pullSecrets` | Specify docker-registry secret names as an array | `[]` | +| `metrics.resources` | Metrics exporter resource requests and limits | `{}` | +| `metrics.podAnnotations` | Additional annotations for Metrics exporter pod | `{}` | + ### Certificate injection parameters -| Parameter | Description | Default | -|------------------------------------------------------|----------------------------------------------------------------------|------------------------------------------| +| Name | Description | Value | +| ---------------------------------------------------- | -------------------------------------------------------------------- | ---------------------------------------- | | `certificates.customCertificate.certificateSecret` | Secret containing the certificate and key to add | `""` | -| `certificates.customCertificate.chainSecret.name` | Name of the secret containing the certificate chain | `""` | -| `certificates.customCertificate.chainSecret.key` | Key of the certificate chain file inside the secret | `""` | +| `certificates.customCertificate.chainSecret.name` | Name of the secret containing the certificate chain | `secret-name` | +| `certificates.customCertificate.chainSecret.key` | Key of the certificate chain file inside the secret | `secret-key` | | `certificates.customCertificate.certificateLocation` | Location in the container to store the certificate | `/etc/ssl/certs/ssl-cert-snakeoil.pem` | | `certificates.customCertificate.keyLocation` | Location in the container to store the private key | `/etc/ssl/private/ssl-cert-snakeoil.key` | -| `certificates.customCertificate.chainLocation` | Location in the container to store the certificate chain | `/etc/ssl/certs/chain.pem` | +| `certificates.customCertificate.chainLocation` | Location in the container to store the certificate chain | `/etc/ssl/certs/mychain.pem` | | `certificates.customCAs` | Defines a list of secrets to import into the container trust store | `[]` | -| `certificates.image.registry` | Container sidecar registry | `docker.io` | -| `certificates.image.repository` | Container sidecar image | `bitnami/bitnami-shell` | -| `certificates.image.tag` | Container sidecar image tag | `"10"` | -| `certificates.image.pullPolicy` | Container sidecar image pull policy | `IfNotPresent` | -| `certificates.image.pullSecrets` | Container sidecar image pull secrets | `image.pullSecrets` | -| `certificates.args` | Override default container args (useful when using custom images) | `nil` | | `certificates.command` | Override default container command (useful when using custom images) | `nil` | +| `certificates.args` | Override default container args (useful when using custom images) | `nil` | | `certificates.extraEnvVars` | Container sidecar extra environment variables (eg proxy) | `[]` | | `certificates.extraEnvVarsCM` | ConfigMap containing extra env vars | `nil` | | `certificates.extraEnvVarsSecret` | Secret containing extra env vars (in case of sensitive data) | `nil` | +| `certificates.image.registry` | Container sidecar registry | `docker.io` | +| `certificates.image.repository` | Container sidecar image | `bitnami/bitnami-shell` | +| `certificates.image.tag` | Container sidecar image tag | `10-debian-10-r111` | +| `certificates.image.pullPolicy` | Container sidecar image pull policy | `IfNotPresent` | +| `certificates.image.pullSecrets` | Container sidecar image pull secrets | `[]` | + The above parameters map to the env variables defined in [bitnami/drupal](http://github.com/bitnami/bitnami-docker-drupal). For more information please refer to the [bitnami/drupal](http://github.com/bitnami/bitnami-docker-drupal) image documentation. diff --git a/bitnami/drupal/values.yaml b/bitnami/drupal/values.yaml index b899c4d3a..ed172dd8a 100644 --- a/bitnami/drupal/values.yaml +++ b/bitnami/drupal/values.yaml @@ -1,15 +1,52 @@ +## @section Global parameters ## Global Docker image parameters ## Please, note that this will override the image parameters, including dependencies, configured to use the global value -## Current available global Docker image parameters: imageRegistry and imagePullSecrets +## Current available global Docker image parameters: imageRegistry, imagePullSecrets and storageClass + +## @param global.imageRegistry Global Docker image registry +## @param global.imagePullSecrets Global Docker registry secret names as an array +## @param global.storageClass Global StorageClass for Persistent Volume(s) ## -# global: -# imageRegistry: myRegistryName -# imagePullSecrets: -# - myRegistryKeySecretName -# storageClass: myStorageClass +global: + imageRegistry: + ## E.g. + ## imagePullSecrets: + ## - myRegistryKeySecretName + ## + imagePullSecrets: [] + storageClass: + +## @section Common parameters + +## @param kubeVersion Force target Kubernetes version (using Helm capabilities if not set) +## +kubeVersion: +## @param nameOverride String to partially override drupal.fullname template (will maintain the release name) +## +nameOverride: +## @param fullnameOverride String to fully override drupal.fullname template +## +fullnameOverride: +## @param commonAnnotations Common annotations to add to all Drupal resources (sub-charts are not considered). Evaluated as a template +## +commonAnnotations: {} +## @param commonLabels Common labels to add to all Drupal resources (sub-charts are not considered). Evaluated as a template +## +commonLabels: {} +## @param extraDeploy Array of extra objects to deploy with the release (evaluated as a template). +## +extraDeploy: [] + +## @section Drupal parameters ## Bitnami Drupal image version ## ref: https://hub.docker.com/r/bitnami/drupal/tags/ +## @param image.registry Drupal image registry +## @param image.repository Drupal Image name +## @param image.tag Drupal Image tag +## @param image.pullPolicy Drupal image pull policy +## @param image.pullSecrets Specify docker-registry secret names as an array +## @param image.debug Specify if debug logs should be enabled ## image: registry: docker.io @@ -23,197 +60,418 @@ image: ## Optionally specify an array of imagePullSecrets. ## Secrets must be manually created in the namespace. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ + ## e.g: + ## pullSecrets: + ## - myRegistryKeySecretName ## - pullSecrets: - # - myRegistryKeySecretName + pullSecrets: [] ## Set to true if you would like to see extra information on logs ## debug: false - -## Force target Kubernetes version (using Helm capabilites if not set) -## -kubeVersion: - -## String to partially override drupal.fullname template (will maintain the release name) -## -nameOverride: - -## Deployment pod host aliases -## https://kubernetes.io/docs/concepts/services-networking/add-entries-to-pod-etc-hosts-with-host-aliases/ -## -hostAliases: - # Necessary for apache-exporter to work - - ip: "127.0.0.1" - hostnames: - - "status.localhost" - -## String to fully override drupal.fullname template -## -fullnameOverride: - -## Number of replicas (requires ReadWriteMany PVC support) +## @param replicaCount Number of Drupal Pods to run (requires ReadWriteMany PVC support) ## replicaCount: 1 - -## Installation Profile +## @param drupalProfile Drupal installation profile ## ref: https://github.com/bitnami/bitnami-docker-drupal#configuration ## drupalProfile: standard - -## Skip Drupal installation wizard. Useful for migrations and restoring from SQL dump +## @param drupalSkipInstall Skip Drupal installation wizard. Useful for migrations and restoring from SQL dump ## ref: https://github.com/bitnami/bitnami-docker-drupal#configuration ## drupalSkipInstall: false - -## User of the application +## @param drupalUsername User of the application ## ref: https://github.com/bitnami/bitnami-docker-drupal#configuration ## drupalUsername: user - -## Application password +## @param drupalPassword Application password ## Defaults to a random 10-character alphanumeric string if not set ## ref: https://github.com/bitnami/bitnami-docker-drupal#configuration ## drupalPassword: "" - -## Admin email +## @param drupalEmail Admin email ## ref: https://github.com/bitnami/bitnami-docker-drupal#configuration ## drupalEmail: user@example.com - -## Set to `yes` to allow the container to be started with blank passwords +## @param allowEmptyPassword Allow DB blank passwords ## ref: https://github.com/bitnami/bitnami-docker-drupal#environment-variables ## allowEmptyPassword: true - -## Container command (using container default if not set) +## @param command Override default container command (useful when using custom images) ## command: -## Container args (using container default if not set) +## @param args Override default container args (useful when using custom images) ## args: - -## Common annotations to add to all Drupal resources (sub-charts are not considered). Evaluated as a template -## -commonAnnotations: {} - -## Common labels to add to all Drupal resources (sub-charts are not considered). Evaluated as a template -## -commonLabels: {} - -## Update strategy - only really applicable for deployments with RWO PVs attached +## @param updateStrategy.type Update strategy - only really applicable for deployments with RWO PVs attached ## If replicas = 1, an update can get "stuck", as the previous pod remains attached to the ## PV, and the "incoming" pod can never start. Changing the strategy to "Recreate" will ## terminate the single previous pod, so that the new, incoming pod can attach to the PV ## updateStrategy: type: RollingUpdate - -## An array to add extra env vars +## @param hostAliases [array] Add deployment host aliases +## https://kubernetes.io/docs/concepts/services-networking/add-entries-to-pod-etc-hosts-with-host-aliases/ +## +hostAliases: + ## Necessary for apache-exporter to work + ## + - ip: "127.0.0.1" + hostnames: + - "status.localhost" +## @param extraEnvVars Extra environment variables ## For example: ## extraEnvVars: [] # - name: BEARER_AUTH # value: true - -## ConfigMap with extra environment variables +## @param extraEnvVarsCM ConfigMap containing extra env vars ## extraEnvVarsCM: - -## Secret with extra environment variables +## @param extraEnvVarsSecret Secret containing extra env vars (in case of sensitive data) ## extraEnvVarsSecret: - -## Extra volumes to add to the deployment +## @param extraVolumes Array of extra volumes to be added to the deployment (evaluated as template). Requires setting `extraVolumeMounts` ## extraVolumes: [] - -## Extra volume mounts to add to the container +## @param extraVolumeMounts Array of extra volume mounts to be added to the container (evaluated as template). Normally used with `extraVolumes`. ## extraVolumeMounts: [] - -## Extra init containers to add to the deployment +## @param initContainers Add additional init containers to the pod (evaluated as a template) ## initContainers: [] - -## Extra sidecar containers to add to the deployment +## @param sidecars Attach additional containers to the pod (evaluated as a template) ## sidecars: [] - -## Tolerations for pod assignment. Evaluated as a template. +## @param tolerations Tolerations for pod assignment ## Ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/ ## tolerations: [] - -## Use existing secret for the application password +## @param existingSecret Name of a secret with the application password ## existingSecret: - -## -## External database configuration -## -externalDatabase: - ## Database host - ## - host: "" - - ## Database host - ## - port: 3306 - - ## Database user - ## - user: bn_drupal - - ## Database password - ## - password: "" - - ## Database name - ## - database: bitnami_drupal - ## SMTP mail delivery configuration ## ref: https://github.com/bitnami/bitnami-docker-drupal/#smtp-configuration +## @param smtpHost SMTP host +## @param smtpPort SMTP port +## @param smtpUser SMTP user +## @param smtpPassword SMTP password +## @param smtpProtocol SMTP Protocol (options: ssl,tls, nil) ## smtpHost: smtpPort: smtpUser: smtpPassword: smtpProtocol: +## @param containerPorts [object] Container ports +## +containerPorts: + http: 8080 + https: 8443 +## @param sessionAffinity Control where client requests go, to the same pod or round-robin. Values: ClientIP or None +## ref: https://kubernetes.io/docs/user-guide/services/ +## +sessionAffinity: "None" +## Enable persistence using Persistent Volume Claims +## ref: http://kubernetes.io/docs/user-guide/persistent-volumes/ +## +persistence: + ## @param persistence.enabled Enable persistence using PVC + ## + enabled: true + ## @param persistence.storageClass PVC Storage Class for Drupal volume + ## If defined, storageClassName: + ## If set to "-", storageClassName: "", which disables dynamic provisioning + ## If undefined (the default) or set to null, no storageClassName spec is + ## set, choosing the default provisioner. (gp2 on AWS, standard on + ## GKE, AWS & OpenStack) + ## + storageClass: + ## @param persistence.accessMode PVC Access Mode for Drupal volume + ## Requires persistence.enabled: true + ## If defined, PVC must be created manually before volume will be bound + ## + accessMode: ReadWriteOnce + ## @param persistence.size PVC Storage Request for Drupal volume + ## + size: 8Gi + ## @param persistence.existingClaim A manually managed Persistent Volume Claim + ## Requires persistence.enabled: true + ## If defined, PVC must be created manually before volume will be bound + ## + existingClaim: + ## @param persistence.hostPath If defined, the drupal-data volume will mount to the specified hostPath. + ## Requires persistence.enabled: true + ## Requires persistence.existingClaim: nil|false + ## Default: nil. + ## + hostPath: +## @param podAffinityPreset Pod affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` +## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity +## +podAffinityPreset: "" +## @param podAntiAffinityPreset Pod anti-affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` +## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity +## +podAntiAffinityPreset: soft +## Node affinity preset +## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity +## @param nodeAffinityPreset.type Node affinity preset type. Ignored if `affinity` is set. Allowed values: `soft` or `hard` +## @param nodeAffinityPreset.key Node label key to match Ignored if `affinity` is set. +## @param nodeAffinityPreset.values Node label values to match. Ignored if `affinity` is set. +## +nodeAffinityPreset: + type: "" + ## E.g. + ## key: "kubernetes.io/e2e-az-name" + ## + key: "" + ## E.g. + ## values: + ## - e2e-az1 + ## - e2e-az2 + ## + values: [] +## @param affinity Affinity for pod assignment +## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity +## Note: podAffinityPreset, podAntiAffinityPreset, and nodeAffinityPreset will be ignored when it's set +## +affinity: {} +## @param nodeSelector Node labels for pod assignment. Evaluated as a template. +## ref: https://kubernetes.io/docs/user-guide/node-selection/ +## +nodeSelector: {} +## @param resources [object] CPU/Memory resource requests/limits +## ref: http://kubernetes.io/docs/user-guide/compute-resources/ +## +resources: + requests: + memory: 512Mi + cpu: 300m +## Configure Pods Security Context +## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod +## @param podSecurityContext.enabled Enable Drupal pods' Security Context +## @param podSecurityContext.fsGroup Drupal pods' group ID +## +podSecurityContext: + enabled: true + fsGroup: 1001 +## Configure Container Security Context (only main container) +## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container +## @param containerSecurityContext.enabled Enable Drupal containers' Security Context +## @param containerSecurityContext.runAsUser Drupal containers' Security Context +## +containerSecurityContext: + enabled: true + runAsUser: 1001 +## Configure extra options for liveness probe +## Drupal core exposes /user/login to unauthenticated requests, making it a good +## default liveness and readiness path. However, that may not always be the +## case. For example, if the image value is overridden to an image containing a +## module that alters that route, or an image that does not auto-install Drupal. +## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/#configure-probes +## @param livenessProbe.enabled Enable livenessProbe +## @param livenessProbe.path Request path for livenessProbe +## @param livenessProbe.initialDelaySeconds Initial delay seconds for livenessProbe +## @param livenessProbe.periodSeconds Period seconds for livenessProbe +## @param livenessProbe.timeoutSeconds Timeout seconds for livenessProbe +## @param livenessProbe.failureThreshold Failure threshold for livenessProbe +## @param livenessProbe.successThreshold Success threshold for livenessProbe +## +livenessProbe: + enabled: true + path: /user/login + initialDelaySeconds: 600 + periodSeconds: 10 + timeoutSeconds: 5 + failureThreshold: 5 + successThreshold: 1 +## Configure extra options for readiness probe +## Drupal core exposes /user/login to unauthenticated requests, making it a good +## default liveness and readiness path. However, that may not always be the +## case. For example, if the image value is overridden to an image containing a +## module that alters that route, or an image that does not auto-install Drupal. +## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/#configure-probes +## @param readinessProbe.enabled Enable readinessProbe +## @param readinessProbe.path Request path for readinessProbe +## @param readinessProbe.initialDelaySeconds Initial delay seconds for readinessProbe +## @param readinessProbe.periodSeconds Period seconds for readinessProbe +## @param readinessProbe.timeoutSeconds Timeout seconds for readinessProbe +## @param readinessProbe.failureThreshold Failure threshold for readinessProbe +## @param readinessProbe.successThreshold Success threshold for readinessProbe +## +readinessProbe: + enabled: true + path: /user/login + initialDelaySeconds: 30 + periodSeconds: 5 + timeoutSeconds: 1 + failureThreshold: 5 + successThreshold: 1 +## @param customLivenessProbe Override default liveness probe +## +customLivenessProbe: {} +## @param customReadinessProbe Override default readiness probe +## +customReadinessProbe: {} +## @param lifecycleHooks LifecycleHook to set additional configuration at startup Evaluated as a template +## +lifecycleHooks: +## @param podAnnotations Pod annotations +## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/ +## +podAnnotations: {} +## @param podLabels Add additional labels to the pod (evaluated as a template) +## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/ +## +podLabels: {} +## @section Traffic Exposure Parameters + +## Kubernetes configuration. For minikube, set this to NodePort, elsewhere use LoadBalancer ## +service: + ## @param service.type Kubernetes Service type + ## + type: LoadBalancer + ## @param service.port Service HTTP port + ## + port: 80 + ## @param service.httpsPort Service HTTPS port + ## + httpsPort: 443 + ## @param service.loadBalancerSourceRanges Restricts access for LoadBalancer (only with `service.type: LoadBalancer`) + ## e.g: + ## loadBalancerSourceRanges: + ## - 0.0.0.0/0 + ## + loadBalancerSourceRanges: [] + ## @param service.loadBalancerIP loadBalancerIP for the Drupal Service (optional, cloud specific) + ## ref: http://kubernetes.io/docs/user-guide/services/#type-loadbalancer + loadBalancerIP: + ## @param service.nodePorts [object] Kubernetes node port + ## nodePorts: + ## http: + ## https: + ## + nodePorts: + http: "" + https: "" + ## @param service.externalTrafficPolicy Enable client source IP preservation + ## ref http://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip + ## + externalTrafficPolicy: Cluster +## Configure the ingress resource that allows you to access the +## Drupal installation. Set up the URL +## ref: http://kubernetes.io/docs/user-guide/ingress/ +## +ingress: + ## @param ingress.enabled Enable ingress controller resource + ## + enabled: false + ## @param ingress.certManager Add annotations for cert-manager + ## + certManager: false + ## @param ingress.pathType Ingress Path type + ## + pathType: ImplementationSpecific + ## @param ingress.apiVersion Override API Version (automatically detected if not set) + ## + apiVersion: + ## @param ingress.hostname Default host for the ingress resource + ## + hostname: drupal.local + ## @param ingress.path The Path to Drupal. You may need to set this to '/*' in order to use this + ## with ALB ingress controllers. + ## + path: / + ## @param ingress.annotations Ingress annotations done as key:value pairs + ## For a full list of possible ingress annotations, please see + ## ref: https://github.com/kubernetes/ingress-nginx/blob/master/docs/user-guide/nginx-configuration/annotations.md + ## + ## If certManager is set to true, annotation kubernetes.io/tls-acme: "true" will automatically be set + ## + annotations: {} + ## @param ingress.tls Enable TLS configuration for the hostname defined at ingress.hostname parameter + ## TLS certificates will be retrieved from a TLS secret with name: {{- printf "%s-tls" .Values.ingress.hostname }} + ## You can use the ingress.secrets parameter to create this TLS secret or relay on cert-manager to create it + ## + tls: false + ## @param ingress.extraHosts The list of additional hostnames to be covered with this ingress record. + ## Most likely the hostname above will be enough, but in the event more hosts are needed, this is an array + ## extraHosts: + ## - name: drupal.local + ## path: / + extraHosts: [] + ## @param ingress.extraPaths Any additional arbitrary paths that may need to be added to the ingress under the main host. + ## For example: The ALB ingress controller requires a special rule for handling SSL redirection. + ## extraPaths: + ## - path: /* + ## backend: + ## serviceName: ssl-redirect + ## servicePort: use-annotation + extraPaths: [] + ## @param ingress.extraTls The tls configuration for additional hostnames to be covered with this ingress record. + ## see: https://kubernetes.io/docs/concepts/services-networking/ingress/#tls + ## extraTls: + ## - hosts: + ## - drupal.local + ## secretName: drupal.local-tls + extraTls: [] + ## @param ingress.secrets If you're providing your own certificates, please use this to add the certificates as secrets + ## key and certificate should start with -----BEGIN CERTIFICATE----- or + ## -----BEGIN RSA PRIVATE KEY----- + ## + ## name should line up with a tlsSecret set further up + ## If you're using cert-manager, this is unneeded, as it will create the secret for you if it is not set + ## + ## It is also possible to create and manage the certificates outside of this helm chart + ## Please see README.md for more information + ## Example: + ## - name: drupal.local-tls + ## key: + ## certificate: + ## + secrets: [] + +## @section Database parameters + ## MariaDB chart configuration -## ## https://github.com/bitnami/charts/blob/master/bitnami/mariadb/values.yaml ## mariadb: - ## Whether to deploy a mariadb server to satisfy the applications database requirements. To use an external database set this to false and configure the externalDatabase parameters + ## @param mariadb.enabled Whether to deploy a mariadb server to satisfy the applications database requirements + ## To use an external database set this to false and configure the externalDatabase parameters ## enabled: true - - ## MariaDB architecture. Allowed values: standalone or replication + ## @param mariadb.architecture MariaDB architecture (`standalone` or `replication`) ## architecture: standalone - ## MariaDB Authentication parameters + ## @param mariadb.auth.rootPassword Password for the MariaDB `root` user + ## @param mariadb.auth.database Database name to create + ## @param mariadb.auth.username Database user to create + ## @param mariadb.auth.password Password for the database ## auth: - ## MariaDB root password ## ref: https://github.com/bitnami/bitnami-docker-mariadb#setting-the-root-password-on-first-run ## rootPassword: "" - ## MariaDB custom user and database ## ref: https://github.com/bitnami/bitnami-docker-mariadb/blob/master/README.md#creating-a-database-on-first-run - ## ref: https://github.com/bitnami/bitnami-docker-mariadb/blob/master/README.md#creating-a-database-user-on-first-run ## database: bitnami_drupal + ## ref: https://github.com/bitnami/bitnami-docker-mariadb/blob/master/README.md#creating-a-database-user-on-first-run + ## username: bn_drupal password: "" - primary: ## Enable persistence using Persistent Volume Claims ## ref: http://kubernetes.io/docs/user-guide/persistent-volumes/ + ## @param mariadb.primary.persistence.enabled Enable database persistence using PVC + ## @param mariadb.primary.persistence.storageClass MariaDB primary persistent volume storage Class + ## @param mariadb.primary.persistence.accessModes Database Persistent Volume Access Modes + ## @param mariadb.primary.persistence.size Database Persistent Volume Size + ## @param mariadb.primary.persistence.hostPath Set path in case you want to use local host path volumes (not recommended in production) + ## @param mariadb.primary.persistence.existingClaim Name of an existing `PersistentVolumeClaim` for MariaDB primary replicas ## persistence: enabled: true @@ -228,230 +486,37 @@ mariadb: accessModes: - ReadWriteOnce size: 8Gi - ## Set path in case you want to use local host path volumes (not recommended in production) - ## hostPath: - ## Use an existing PVC - ## existingClaim: - -## Container ports +## External database configuration +## @param externalDatabase.host Host of the existing database +## @param externalDatabase.port Port of the existing database +## @param externalDatabase.user Existing username in the external db +## @param externalDatabase.password Password for the above username +## @param externalDatabase.database Name of the existing database ## -containerPorts: - http: 8080 - https: 8443 +externalDatabase: + host: "" + port: 3306 + user: bn_drupal + password: "" + database: bitnami_drupal -## Kubernetes configuration -## For minikube, set this to NodePort, elsewhere use LoadBalancer -## -service: - type: LoadBalancer - # HTTP Port - port: 80 - # HTTPS Port - httpsPort: 443 - ## clusterIP: "" - ## Control hosts connecting to "LoadBalancer" only - ## loadBalancerSourceRanges: - ## - 0.0.0.0/0 - ## loadBalancerIP for the Drupal Service (optional, cloud specific) - ## ref: http://kubernetes.io/docs/user-guide/services/#type-loadbalancer - ## loadBalancerIP: - ## - ## nodePorts: - ## http: - ## https: - ## - nodePorts: - http: "" - https: "" - ## Enable client source IP preservation - ## ref http://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip - ## - externalTrafficPolicy: Cluster - -## Configure the ingress resource that allows you to access the -## Drupal installation. Set up the URL -## ref: http://kubernetes.io/docs/user-guide/ingress/ -## -ingress: - ## Set to true to enable ingress record generation - ## - enabled: false - - ## Set this to true in order to add the corresponding annotations for cert-manager - ## - certManager: false - - ## Ingress Path type - ## - pathType: ImplementationSpecific - - ## Override API Version (automatically detected if not set) - ## - apiVersion: - - ## When the ingress is enabled, a host pointing to this will be created - ## - hostname: drupal.local - - ## The Path to Drupal. You may need to set this to '/*' in order to use this - ## with ALB ingress controllers. - ## - path: / - - ## Ingress annotations done as key:value pairs - ## For a full list of possible ingress annotations, please see - ## ref: https://github.com/kubernetes/ingress-nginx/blob/master/docs/user-guide/nginx-configuration/annotations.md - ## - ## If certManager is set to true, annotation kubernetes.io/tls-acme: "true" will automatically be set - ## - annotations: {} - - ## Enable TLS configuration for the hostname defined at ingress.hostname parameter - ## TLS certificates will be retrieved from a TLS secret with name: {{- printf "%s-tls" .Values.ingress.hostname }} - ## You can use the ingress.secrets parameter to create this TLS secret or relay on cert-manager to create it - ## - tls: false - - ## The list of additional hostnames to be covered with this ingress record. - ## Most likely the hostname above will be enough, but in the event more hosts are needed, this is an array - ## extraHosts: - ## - name: drupal.local - ## path: / - ## - - ## Any additional arbitrary paths that may need to be added to the ingress under the main host. - ## For example: The ALB ingress controller requires a special rule for handling SSL redirection. - ## extraPaths: - ## - path: /* - ## backend: - ## serviceName: ssl-redirect - ## servicePort: use-annotation - ## - - ## The tls configuration for additional hostnames to be covered with this ingress record. - ## see: https://kubernetes.io/docs/concepts/services-networking/ingress/#tls - ## extraTls: - ## - hosts: - ## - drupal.local - ## secretName: drupal.local-tls - ## - - ## If you're providing your own certificates, please use this to add the certificates as secrets - ## key and certificate should start with -----BEGIN CERTIFICATE----- or - ## -----BEGIN RSA PRIVATE KEY----- - ## - ## name should line up with a tlsSecret set further up - ## If you're using cert-manager, this is unneeded, as it will create the secret for you if it is not set - ## - ## It is also possible to create and manage the certificates outside of this helm chart - ## Please see README.md for more information - ## - secrets: [] - ## - name: drupal.local-tls - ## key: - ## certificate: - ## - -## Control where client requests go, to the same pod or round-robin -## Values: ClientIP or None -## ref: https://kubernetes.io/docs/user-guide/services/ -## -sessionAffinity: "None" - -## Enable persistence using Persistent Volume Claims -## ref: http://kubernetes.io/docs/user-guide/persistent-volumes/ -## -persistence: - enabled: true - ## Drupal Data Persistent Volume Storage Class - ## If defined, storageClassName: - ## If set to "-", storageClassName: "", which disables dynamic provisioning - ## If undefined (the default) or set to null, no storageClassName spec is - ## set, choosing the default provisioner. (gp2 on AWS, standard on - ## GKE, AWS & OpenStack) - ## - # storageClass: "-" - - ## A manually managed Persistent Volume and Claim - ## Requires persistence.enabled: true - ## If defined, PVC must be created manually before volume will be bound - ## - accessMode: ReadWriteOnce - size: 8Gi - - ## A manually managed Persistent Volume Claim - ## Requires persistence.enabled: true - ## If defined, PVC must be created manually before volume will be bound - ## - # existingClaim: - - ## If defined, the drupal-data volume will mount to the specified hostPath. - ## Requires persistence.enabled: true - ## Requires persistence.existingClaim: nil|false - ## Default: nil. - ## - hostPath: - -## Pod affinity preset -## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity -## Allowed values: soft, hard -## -podAffinityPreset: "" - -## Pod anti-affinity preset -## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity -## Allowed values: soft, hard -## -podAntiAffinityPreset: soft - -## Node affinity preset -## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity -## Allowed values: soft, hard -## -nodeAffinityPreset: - ## Node affinity type - ## Allowed values: soft, hard - ## - type: "" - ## Node label key to match - ## E.g. - ## key: "kubernetes.io/e2e-az-name" - ## - key: "" - ## Node label values to match - ## E.g. - ## values: - ## - e2e-az1 - ## - e2e-az2 - ## - values: [] - -## Affinity for pod assignment -## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity -## Note: podAffinityPreset, podAntiAffinityPreset, and nodeAffinityPreset will be ignored when it's set -## -affinity: {} - -## Node labels for pod assignment. Evaluated as a template. -## ref: https://kubernetes.io/docs/user-guide/node-selection/ -## -nodeSelector: {} - -## Configure resource requests and limits -## ref: http://kubernetes.io/docs/user-guide/compute-resources/ -## -resources: - requests: - memory: 512Mi - cpu: 300m +## @section Volume Permissions parameters ## Init containers parameters: ## volumePermissions: Change the owner and group of the persistent volume mountpoint to runAsUser:fsGroup values from the securityContext section. ## volumePermissions: + ## @param volumePermissions.enabled Enable init container that changes volume permissions in the data directory (for cases where the default k8s `runAsUser` and `fsUser` values do not work) + ## enabled: false + ## @param volumePermissions.image.registry Init container volume-permissions image registry + ## @param volumePermissions.image.repository Init container volume-permissions image name + ## @param volumePermissions.image.tag Init container volume-permissions image tag + ## @param volumePermissions.image.pullPolicy Init container volume-permissions image pull policy + ## @param volumePermissions.image.pullSecrets Specify docker-registry secret names as an array + ## image: registry: docker.io repository: bitnami/bitnami-shell @@ -460,91 +525,46 @@ volumePermissions: ## Optionally specify an array of imagePullSecrets. ## Secrets must be manually created in the namespace. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ + ## e.g: + ## pullSecrets: + ## - myRegistryKeySecretName ## pullSecrets: [] - ## - myRegistryKeySecretName ## Init containers' resource requests and limits ## ref: http://kubernetes.io/docs/user-guide/compute-resources/ + ## We usually recommend not to specify default resources and to leave this as a conscious + ## choice for the user. This also increases chances charts run on environments with little + ## resources, such as Minikube. If you do want to specify resources, uncomment the following + ## lines, adjust them as necessary, and remove the curly braces after 'resources:'. + ## @param volumePermissions.resources.limits The resources limits for the container + ## @param volumePermissions.resources.requests The requested resources for the container ## resources: - ## We usually recommend not to specify default resources and to leave this as a conscious - ## choice for the user. This also increases chances charts run on environments with little - ## resources, such as Minikube. If you do want to specify resources, uncomment the following - ## lines, adjust them as necessary, and remove the curly braces after 'resources:'. - ## + ## Example: + ## limits: + ## cpu: 100m + ## memory: 128Mi limits: {} - ## cpu: 100m - ## memory: 128Mi - ## + ## Examples: + ## requests: + ## cpu: 100m + ## memory: 128Mi requests: {} - ## cpu: 100m - ## memory: 128Mi - ## -## Configure Pods Security Context -## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod -## -podSecurityContext: - enabled: true - fsGroup: 1001 - -## Configure Container Security Context (only main container) -## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container -## -containerSecurityContext: - enabled: true - runAsUser: 1001 - -## Configure extra options for liveness and readiness probes -## Drupal core exposes /user/login to unauthenticated requests, making it a good -## default liveness and readiness path. However, that may not always be the -## case. For example, if the image value is overridden to an image containing a -## module that alters that route, or an image that does not auto-install Drupal. -## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/#configure-probes -## -livenessProbe: - enabled: true - path: /user/login - initialDelaySeconds: 600 - periodSeconds: 10 - timeoutSeconds: 5 - failureThreshold: 5 - successThreshold: 1 -readinessProbe: - enabled: true - path: /user/login - initialDelaySeconds: 30 - periodSeconds: 5 - timeoutSeconds: 1 - failureThreshold: 5 - successThreshold: 1 - -## Custom Liveness probe -## -customLivenessProbe: {} - -## Custom Readiness probe -## -customReadinessProbe: {} - -## lifecycleHooks for the container to automate configuration before or after startup. -## -lifecycleHooks: - -## Pod annotations -## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/ -## -podAnnotations: {} - -## Pod extra labels -## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/ -## -podLabels: {} +## @section Metrics parameters ## Prometheus Exporter / Metrics ## metrics: + ## @param metrics.enabled Start a exporter side-car + ## enabled: false + ## @param metrics.image.registry Apache exporter image registry + ## @param metrics.image.repository Apache exporter image repository + ## @param metrics.image.tag Apache exporter image tag + ## @param metrics.image.pullPolicy Image pull policy + ## @param metrics.image.pullSecrets Specify docker-registry secret names as an array + ## image: registry: docker.io repository: bitnami/apache-exporter @@ -553,50 +573,66 @@ metrics: ## Optionally specify an array of imagePullSecrets. ## Secrets must be manually created in the namespace. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ + ## e.g: + ## pullSecrets: + ## - myRegistryKeySecretName ## - pullSecrets: - # - myRegistryKeySecretName - ## Metrics exporter resource requests and limits + pullSecrets: [] + ## @param metrics.resources Metrics exporter resource requests and limits ## ref: http://kubernetes.io/docs/user-guide/compute-resources/ ## - # resources: {} - ## Metrics exporter pod Annotation and Labels + resources: {} + ## + ## @param metrics.podAnnotations [object] Additional annotations for Metrics exporter pod ## podAnnotations: prometheus.io/scrape: "true" prometheus.io/port: "9117" -# Add custom certificates and certificate authorities to redmine container +## @section Certificate injection parameters + +## Add custom certificates and certificate authorities to redmine container +## certificates: + ## @param certificates.customCertificate.certificateSecret Secret containing the certificate and key to add + ## @param certificates.customCertificate.chainSecret.name Name of the secret containing the certificate chain + ## @param certificates.customCertificate.chainSecret.key Key of the certificate chain file inside the secret + ## @param certificates.customCertificate.certificateLocation Location in the container to store the certificate + ## @param certificates.customCertificate.keyLocation Location in the container to store the private key + ## @param certificates.customCertificate.chainLocation Location in the container to store the certificate chain + ## customCertificate: certificateSecret: "" - chainSecret: {} - # name: secret-name - # key: secret-key + chainSecret: + name: secret-name + key: secret-key certificateLocation: /etc/ssl/certs/ssl-cert-snakeoil.pem keyLocation: /etc/ssl/private/ssl-cert-snakeoil.key chainLocation: /etc/ssl/certs/mychain.pem + ## @param certificates.customCAs Defines a list of secrets to import into the container trust store + ## customCAs: [] - ## Override container command + ## @param certificates.command Override default container command (useful when using custom images) ## command: - ## Override container args + ## @param certificates.args Override default container args (useful when using custom images) ## args: - # - secret: custom-CA - # - secret: more-custom-CAs - ## An array to add extra env vars + ## @param certificates.extraEnvVars Container sidecar extra environment variables (eg proxy) ## extraEnvVars: [] - - ## ConfigMap with extra environment variables + ## @param certificates.extraEnvVarsCM ConfigMap containing extra env vars ## extraEnvVarsCM: - - ## Secret with extra environment variables + ## @param certificates.extraEnvVarsSecret Secret containing extra env vars (in case of sensitive data) ## extraEnvVarsSecret: - + ## @param certificates.image.registry Container sidecar registry + ## @param certificates.image.repository Container sidecar image + ## @param certificates.image.tag Container sidecar image tag + ## @param certificates.image.pullPolicy Container sidecar image pull policy + ## @param certificates.image.pullSecrets Container sidecar image pull secrets + ## image: registry: docker.io repository: bitnami/bitnami-shell @@ -606,10 +642,8 @@ certificates: ## ref: http://kubernetes.io/docs/user-guide/images/#pre-pulling-images ## pullPolicy: IfNotPresent - # pullPolicy: + ## e.g: + ## pullSecrets: + ## - myRegistryKeySecretName + ## pullSecrets: [] - # - myRegistryKeySecretName - -## Array with extra yaml to deploy with the chart. Evaluated as a template -## -extraDeploy: [] diff --git a/bitnami/ejbca/Chart.yaml b/bitnami/ejbca/Chart.yaml index bc511b979..5c993b2bf 100644 --- a/bitnami/ejbca/Chart.yaml +++ b/bitnami/ejbca/Chart.yaml @@ -30,4 +30,4 @@ name: ejbca sources: - https://github.com/bitnami/bitnami-docker-ejbca - https://www.ejbca.org/ -version: 2.2.5 +version: 2.2.6 diff --git a/bitnami/ejbca/README.md b/bitnami/ejbca/README.md index 59dea6afa..837a03887 100644 --- a/bitnami/ejbca/README.md +++ b/bitnami/ejbca/README.md @@ -47,144 +47,146 @@ The command removes all the Kubernetes components associated with the chart and ## Parameters -The following table lists the configurable parameters of the EJBCA chart and their default values. +### Global parameters -| Parameter | Description | Default | -|---------------------------|-------------------------------------------------|---------------------------------------------------------| -| `global.imageRegistry` | Global Docker image registry | `nil` | -| `global.imagePullSecrets` | Global Docker registry secret names as an array | `[]` (does not add image pull secrets to deployed pods) | -| `global.storageClass` | Global storage class for dynamic provisioning | `nil` | +| Name | Description | Value | +| ------------------------- | ----------------------------------------------- | ----- | +| `global.imageRegistry` | Global Docker image registry | `nil` | +| `global.imagePullSecrets` | Global Docker registry secret names as an array | `[]` | +| `global.storageClass` | Global StorageClass for Persistent Volume(s) | `nil` | -### Common & Pod-specific parameters -| Parameter | Description | Default | -|------------------------------|-------------------------------------------------------------------------------------------|---------------------------------------------------------| -| `image.registry` | EJBCA image registry | `docker.io` | -| `image.repository` | EJBCA image name | `bitnami/ejbca` | -| `image.tag` | EJBCA image tag | `{TAG_NAME}` | -| `image.pullPolicy` | EJBCA image pull policy | `IfNotPresent` | -| `image.pullSecrets` | Specify docker-registry secret names as an array | `[]` (does not add image pull secrets to deployed pods) | -| `nameOverride` | String to partially override discourse.fullname | `nil` | -| `fullnameOverride` | String to fully override discourse.fullname | `nil` | -| `replicaCount` | Number of EJBCA replicas | `1` | -| `extraVolumes` | Array of extra volumes to be added deployment. Requires setting `extraVolumeMounts` | `[]` (evaluated as a template) | -| `podAnnotations` | Additional pod annotations | `{}` | -| `podLabels` | Additional pod labels | `{}` (evaluated as a template) | -| `commonAnnotations` | Annotations to be added to all deployed resources | `{}` (evaluated as a template) | -| `podSecurityContext.enabled` | Enable security context for EJBCA pods | `true` | -| `podSecurityContext.fsGroup` | Group ID for the volumes of the pod | `1001` | -| `podAffinityPreset` | Pod affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `""` | -| `podAntiAffinityPreset` | Pod anti-affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `soft` | -| `nodeAffinityPreset.type` | Node affinity preset type. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `""` | -| `nodeAffinityPreset.key` | Node label key to match Ignored if `affinity` is set. | `""` | -| `nodeAffinityPreset.values` | Node label values to match. Ignored if `affinity` is set. | `[]` | -| `affinity` | Affinity for pod assignment | `{}` (evaluated as a template) | -| `nodeSelector` | Node labels for pod assignment | `{}` (evaluated as a template) | -| `tolerations` | Tolerations for pod assignment | `[]` (evaluated as a template) | -| `sidecars` | Attach additional sidecar containers to the pod | `[]` (evaluated as a template) | -| `initContainers` | Additional init containers to add to the pods | `[]` (evaluated as a template) | -| `persistence.enabled` | Whether to enable persistence based on Persistent Volume Claims | `true` | -| `persistence.storageClass` | PVC Storage Class | `nil` | -| `persistence.existingClaim` | Name of an existing PVC to reuse | `nil` | -| `persistence.accessMode` | PVC Access Mode (RWO, ROX, RWX) | `ReadWriteOnce` | -| `persistence.size` | Size of the PVC to request | `2Gi` | -| `kubeVersion` | Force target Kubernetes version (using Helm capabilities if not set) | `nil` | +### Common parameters -### Service parameters +| Name | Description | Value | +| ------------------- | ------------------------------------------------------------------------------------- | ----- | +| `kubeVersion` | Force target Kubernetes version (using Helm capabilities if not set) | `nil` | +| `nameOverride` | String to partially override ebjca.fullname template (will maintain the release name) | `nil` | +| `fullnameOverride` | String to fully override ebjca.fullname template | `nil` | +| `commonLabels` | Add labels to all the deployed resources | `{}` | +| `commonAnnotations` | Annotations to be added to all deployed resources | `{}` | -| Parameter | Description | Default | -|------------------------------------|-------------------------------------------------------------------------------|--------------------------------| -| `service.type` | Kubernetes Service type | `LoadBalancer` | -| `service.port` | Service HTTP port | `8080` | -| `service.httpsPort` | Service HTTPS port | `8443` | -| `service.advertisedHttpsPort` | Port used for the administration's urls | `443` | -| `service.httpsTargetPort` | Service Target HTTPS port | `https` | -| `service.nodePorts.http` | Kubernetes http node port | `""` | -| `service.nodePorts.https` | Kubernetes https node port | `""` | -| `service.externalTrafficPolicy` | Enable client source IP preservation | `Cluster` | -| `service.annotations` | Service annotations | `{}` (evaluated as a template) | -| `service.loadBalancerSourceRanges` | Restricts access for LoadBalancer (only with `service.type: LoadBalancer`) | `[]` | -| `service.extraPorts` | Extra ports to expose in the service (normally used with the `sidecar` value) | `nil` | ### EJBCA parameters -| Parameter | Description | Default | -|--------------------------------------|-----------------------------------------------------------------------------------------|------------------------------------------------| -| `ejbcaAdminUsername` | EJBCA administrator username | `bitnami` | -| `ejbcaAdminPassword` | EJBCA administrator password | _random 10 character long alphanumeric string_ | -| `existingSecret` | Name of an existing secret containing EJBCA admin password ('ejbca-admin-password' key) | `nil` | -| `ejbcaJavaOpts` | Options used to launch the WildFly server | `nil` | -| `ejbcaCA.name` | Name of the CA EJBCA will instantiate by default | `ManagementCA` | -| `ejbcaCA.baseDN` | Base DomainName of the CA EJBCA will instantiate by default | `nil` | -| `ejbcaKeystoreExistingSecret` | Existing Secret containing a Keystore to be imported by EBJCA | `nil` | -| `extraEnvVars` | An array to add extra env vars | `[]` (evaluated as a template) | -| `command` | Custom command to override image cmd | `nil` (evaluated as a template) | -| `args` | Custom args for the custom command | `nil` (evaluated as a template) | -| `extraVolumeMounts` | Additional volume mounts (used along with `extraVolumes`) | `[]` (evaluated as a template) | -| `resources` | EJBCA container's resource requests and limits | `{}` | -| `podSecurityContext.enabled` | Enable security context for EJBCA container | `true` | -| `podSecurityContext.runAsUser` | User ID for the EJBCA container | `1001` | -| `hostAliases` | Add deployment host aliases | `[]` | -| `livenessProbe.enabled` | Enable/disable livenessProbe | `true` | -| `livenessProbe.initialDelaySeconds` | Delay before liveness probe is initiated | `500` | -| `livenessProbe.periodSeconds` | How often to perform the probe | `10` | -| `livenessProbe.timeoutSeconds` | When the probe times out | `5` | -| `livenessProbe.failureThreshold` | Minimum consecutive failures for the probe | `6` | -| `livenessProbe.successThreshold` | Minimum consecutive successes for the probe | `1` | -| `readinessProbe.enabled` | Enable/disable readinessProbe | `true` | -| `readinessProbe.initialDelaySeconds` | Delay before readiness probe is initiated | `500` | -| `readinessProbe.periodSeconds` | How often to perform the probe | `10` | -| `readinessProbe.timeoutSeconds` | When the probe times out | `5` | -| `readinessProbe.failureThreshold` | Minimum consecutive failures for the probe | `6` | -| `readinessProbe.successThreshold` | Minimum consecutive successes for the probe | `1` | -| `customLivenessProbe` | Custom liveness probe to execute (when the main one is disabled) | `{}` (evaluated as a template) | -| `customReadinessProbe` | Custom readiness probe to execute (when the main one is disabled) | `{}` (evaluated as a template) | -| `containerPorts.http` | Port to open for HTTP traffic in EJBCA | `8080` | -| `containerPorts.https` | Port to open for HTTPS traffic in EJBCA | `8443` | -| `extraEnvVarsCM` | Array to add extra configmaps | `[]` | -| `extraEnvVarsSecret` | Array to add extra environment from a Secret | `nil` | +| Name | Description | Value | +| ------------------------------------ | ----------------------------------------------------------------------------------------- | ------------------------- | +| `image.registry` | EJBCA image registry | `docker.io` | +| `image.repository` | EJBCA image name | `bitnami/ejbca` | +| `image.tag` | EJBCA image tag | `6.15.2-6-debian-10-r271` | +| `image.pullPolicy` | EJBCA image pull policy | `IfNotPresent` | +| `image.pullSecrets` | Specify docker-registry secret names as an array | `[]` | +| `replicaCount` | Number of EJBCA replicas to deploy | `1` | +| `extraVolumeMounts` | Additional volume mounts (used along with `extraVolumes`) | `[]` | +| `extraVolumes` | Array of extra volumes to be added deployment. Requires setting `extraVolumeMounts` | `[]` | +| `podAnnotations` | Additional pod annotations | `{}` | +| `podLabels` | Additional pod labels | `{}` | +| `podSecurityContext.enabled` | Enable security context for EJBCA container | `true` | +| `podSecurityContext.fsGroup` | Group ID for the volumes of the pod | `1001` | +| `podAffinityPreset` | Pod affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `""` | +| `podAntiAffinityPreset` | Pod anti-affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `soft` | +| `nodeAffinityPreset.type` | Node affinity preset type. Ignored if `affinity` is set. Allowed values: `soft` or `hard` | `""` | +| `nodeAffinityPreset.key` | Node label key to match Ignored if `affinity` is set. | `""` | +| `nodeAffinityPreset.values` | Node label values to match. Ignored if `affinity` is set. | `[]` | +| `affinity` | Affinity for pod assignment | `{}` | +| `nodeSelector` | Node labels for pod assignment | `{}` | +| `tolerations` | Tolerations for pod assignment | `[]` | +| `persistence.enabled` | Whether to enable persistence based on Persistent Volume Claims | `true` | +| `persistence.accessMode` | PVC Access Mode (RWO, ROX, RWX) | `ReadWriteOnce` | +| `persistence.size` | Size of the PVC to request | `2Gi` | +| `persistence.storageClass` | PVC Storage Class | `nil` | +| `persistence.existingClaim` | Name of an existing PVC to reuse | `nil` | +| `sidecars` | Attach additional sidecar containers to the pod | `{}` | +| `initContainers` | Additional init containers to add to the pods | `{}` | +| `hostAliases` | Add deployment host aliases | `[]` | +| `ejbcaAdminUsername` | EJBCA administrator username | `bitnami` | +| `ejbcaAdminPassword` | Password for the administrator account | `nil` | +| `existingSecret` | Alternatively, you can provide the name of an existing secret containing | `nil` | +| `ejbcaJavaOpts` | Options used to launch the WildFly server | `nil` | +| `ejbcaCA.name` | Name of the CA EJBCA will instantiate by default | `ManagementCA` | +| `ejbcaCA.baseDN` | Base DomainName of the CA EJBCA will instantiate by default | `nil` | +| `ejbcaKeystoreExistingSecret` | Name of an existing Secret containing a Keystore object | `nil` | +| `extraEnv` | Additional container environment variables | `[]` | +| `command` | Custom command to override image cmd | `[]` | +| `args` | Custom args for the custom command | `[]` | +| `resources.limits` | The resources limits for the container | `{}` | +| `resources.requests` | The requested resources for the container | `{}` | +| `containerSecurityContext.enabled` | Enabled EJBCA containers' Security Context | `true` | +| `containerSecurityContext.runAsUser` | Set EJBCA containers' Security Context runAsUser | `1001` | +| `livenessProbe.enabled` | Enable/disable livenessProbe | `true` | +| `livenessProbe.initialDelaySeconds` | Delay before liveness probe is initiated | `500` | +| `livenessProbe.periodSeconds` | How often to perform the probe | `10` | +| `livenessProbe.timeoutSeconds` | When the probe times out | `5` | +| `livenessProbe.failureThreshold` | Minimum consecutive failures for the probe | `6` | +| `livenessProbe.successThreshold` | Minimum consecutive successes for the probe | `1` | +| `readinessProbe.enabled` | Enable/disable readinessProbe | `true` | +| `readinessProbe.initialDelaySeconds` | Delay before readiness probe is initiated | `500` | +| `readinessProbe.periodSeconds` | How often to perform the probe | `10` | +| `readinessProbe.timeoutSeconds` | When the probe times out | `5` | +| `readinessProbe.failureThreshold` | Minimum consecutive failures for the probe | `6` | +| `readinessProbe.successThreshold` | Minimum consecutive successes for the probe | `1` | +| `customLivenessProbe` | Custom liveness probe to execute (when the main one is disabled) | `{}` | +| `customReadinessProbe` | Custom readiness probe to execute (when the main one is disabled) | `{}` | +| `containerPorts` | EJBCA Container ports to open | `{}` | + + +### Service parameters + +| Name | Description | Value | +| ---------------------------------- | ----------------------------------------------------------------------------- | -------------- | +| `service.type` | Kubernetes Service type | `LoadBalancer` | +| `service.port` | Service HTTP port | `8080` | +| `service.httpsPort` | Service HTTPS port | `8443` | +| `service.advertisedHttpsPort` | Port used for the administration | `443` | +| `service.httpsTargetPort` | Service Target HTTPS port | `https` | +| `service.nodePorts` | Node Ports to expose | `{}` | +| `service.externalTrafficPolicy` | Enable client source IP preservation | `Cluster` | +| `service.annotations` | Service annotations | `{}` | +| `service.loadBalancerSourceRanges` | Limits which cidr blocks can connect to service's load balancer | `[]` | +| `service.extraPorts` | Extra ports to expose in the service (normally used with the `sidecar` value) | `nil` | + ### Ingress parameters -| Parameter | Description | Default | -|----------------------------------|----------------------------------------------------------|--------------------------------| -| `ingress.enabled` | Enable ingress controller resource | `false` | -| `ingress.certManager` | Add annotations for cert-manager | `false` | -| `ingress.hostname` | Default host for the ingress resource | `ejbca.local` | -| `ingress.path` | Default path for the ingress resource | `/` | -| `ingress.tls` | Create TLS Secret | `false` | -| `ingress.annotations` | Ingress annotations | `[]` (evaluated as a template) | -| `ingress.extraHosts[0].name` | Additional hostnames to be covered | `nil` | -| `ingress.extraHosts[0].path` | Additional hostnames to be covered | `nil` | -| `ingress.extraPaths` | Additional arbitrary path/backend objects | `nil` | -| `ingress.extraTls[0].hosts[0]` | TLS configuration for additional hostnames to be covered | `nil` | -| `ingress.extraTls[0].secretName` | TLS configuration for additional hostnames to be covered | `nil` | -| `ingress.secrets[0].name` | TLS Secret Name | `nil` | -| `ingress.secrets[0].certificate` | TLS Secret Certificate | `nil` | -| `ingress.secrets[0].key` | TLS Secret Key | `nil` | +| Name | Description | Value | +| --------------------- | --------------------------------------------------------------------------------------------- | ------------------------ | +| `ingress.enabled` | Enable ingress controller resource | `false` | +| `ingress.certManager` | Add annotations for cert-manager | `false` | +| `ingress.pathType` | Ingress Path type | `ImplementationSpecific` | +| `ingress.apiVersion` | Override API Version (automatically detected if not set) | `nil` | +| `ingress.hostname` | Default host for the ingress resource | `ejbca.local` | +| `ingress.path` | The Path to EJBCA. You may need to set this to '/*' in order to use this | `ImplementationSpecific` | +| `ingress.annotations` | Ingress annotations done as key:value pairs | `{}` | +| `ingress.tls` | Enable TLS configuration for the hostname defined at ingress.hostname parameter | `false` | +| `ingress.extraHosts` | The list of additional hostnames to be covered with this ingress record. | `[]` | +| `ingress.extraPaths` | Any additional arbitrary paths that may need to be added to the ingress under the main host. | `[]` | +| `ingress.extraTls` | The tls configuration for additional hostnames to be covered with this ingress record. | `[]` | +| `ingress.secrets` | If you're providing your own certificates, please use this to add the certificates as secrets | `[]` | + ### Database parameters -| Parameter | Description | Default | -|---------------------------------------------|--------------------------------------------------------------------------------------------|------------------------------------------------| -| `mariadb.enabled` | Deploy MariaDB container(s) | `true` | -| `mariadb.architecture` | MariaDB architecture (`standalone` or `replication`) | `standalone` | -| `mariadb.auth.rootPassword` | Password for the MariaDB `root` user | _random 10 character alphanumeric string_ | -| `mariadb.auth.database` | Database name to create | `bitnami_ejbca` | -| `mariadb.auth.username` | Database user to create | `bn_ejbca` | -| `mariadb.auth.password` | Password for the database | _random 10 character long alphanumeric string_ | -| `mariadb.primary.persistence.enabled` | Enable database persistence using PVC | `true` | -| `mariadb.primary.persistence.existingClaim` | Name of an existing `PersistentVolumeClaim` for MariaDB primary replicas | `nil` | -| `mariadb.primary.persistence.accessModes` | Database Persistent Volume Access Modes | `[ReadWriteOnce]` | -| `mariadb.primary.persistence.size` | Database Persistent Volume Size | `8Gi` | -| `mariadb.primary.persistence.hostPath` | Set path in case you want to use local host path volumes (not recommended in production) | `nil` | -| `mariadb.primary.persistence.storageClass` | MariaDB primary persistent volume storage Class | `nil` | -| `externalDatabase.host` | Host of the external database | `localhost` | -| `externalDatabase.username` | Existing username in the external db | `bn_ejbca` | -| `externalDatabase.password` | Password for the above username | `nil` | -| `externalDatabase.existingSecret` | Name of an existing secret resource containing the DB password in a 'mariadb-password' key | `nil` | -| `externalDatabase.database` | Name of the existing database | `bitnami_ejbca` | -| `externalDatabase.port` | Database port number | `3306` | +| Name | Description | Value | +| ------------------------------------------- | ------------------------------------------------------------------------------------------ | --------------- | +| `mariadb.enabled` | Whether to deploy a mariadb server to satisfy the applications database requirements. | `true` | +| `mariadb.architecture` | MariaDB architecture (`standalone` or `replication`) | `standalone` | +| `mariadb.auth.rootPassword` | Password for the MariaDB `root` user | `""` | +| `mariadb.auth.database` | Database name to create | `bitnami_ejbca` | +| `mariadb.auth.username` | Database user to create | `bn_ejbca` | +| `mariadb.auth.password` | Password for the database | `""` | +| `mariadb.primary.persistence.enabled` | Enable database persistence using PVC | `true` | +| `mariadb.primary.persistence.storageClass` | MariaDB primary persistent volume storage Class | `nil` | +| `mariadb.primary.persistence.accessMode` | Persistent Volume access mode | `ReadWriteOnce` | +| `mariadb.primary.persistence.size` | Database Persistent Volume Size | `8Gi` | +| `mariadb.primary.persistence.hostPath` | Set path in case you want to use local host path volumes (not recommended in production) | `nil` | +| `mariadb.primary.persistence.existingClaim` | Name of an existing `PersistentVolumeClaim` for MariaDB primary replicas | `nil` | +| `externalDatabase.host` | Host of the external database | `localhost` | +| `externalDatabase.user` | non-root Username for EJBCA Database | `bn_ejbca` | +| `externalDatabase.password` | Password for the above username | `""` | +| `externalDatabase.existingSecret` | Name of an existing secret resource containing the DB password in a 'mariadb-password' key | `""` | +| `externalDatabase.database` | Name of the existing database | `bitnami_ejbca` | +| `externalDatabase.port` | Database port number | `3306` | + The above parameters map to the env variables defined in [bitnami/ejbca](http://github.com/bitnami/bitnami-docker-ejbca). For more information please refer to the [bitnami/ejbca](http://github.com/bitnami/bitnami-docker-ejbca) image documentation. diff --git a/bitnami/ejbca/values.yaml b/bitnami/ejbca/values.yaml index cc7646d27..4df16fdc3 100644 --- a/bitnami/ejbca/values.yaml +++ b/bitnami/ejbca/values.yaml @@ -1,15 +1,48 @@ +## @section Global parameters ## Global Docker image parameters ## Please, note that this will override the image parameters, including dependencies, configured to use the global value -## Current available global Docker image parameters: imageRegistry and imagePullSecrets +## Current available global Docker image parameters: imageRegistry, imagePullSecrets and storageClass + +## @param global.imageRegistry Global Docker image registry +## @param global.imagePullSecrets Global Docker registry secret names as an array +## @param global.storageClass Global StorageClass for Persistent Volume(s) ## -# global: -# imageRegistry: myRegistryName -# imagePullSecrets: -# - myRegistryKeySecretName -# storageClass: myStorageClass +global: + imageRegistry: + ## E.g. + ## imagePullSecrets: + ## - myRegistryKeySecretName + ## + imagePullSecrets: [] + storageClass: + +## @section Common parameters + +## @param kubeVersion Force target Kubernetes version (using Helm capabilities if not set) +## +kubeVersion: +## @param nameOverride String to partially override ebjca.fullname template (will maintain the release name) +## +nameOverride: +## @param fullnameOverride String to fully override ebjca.fullname template +## +fullnameOverride: +## @param commonLabels Add labels to all the deployed resources +## +commonLabels: {} +## @param commonAnnotations Annotations to be added to all deployed resources +## +commonAnnotations: {} + +## @section EJBCA parameters ## Bitnami EJBCA image version ## ref: https://hub.docker.com/r/bitnami/ejbca/tags/ +## @param image.registry EJBCA image registry +## @param image.repository EJBCA image name +## @param image.tag EJBCA image tag +## @param image.pullPolicy EJBCA image pull policy +## @param image.pullSecrets Specify docker-registry secret names as an array ## image: registry: docker.io @@ -23,92 +56,17 @@ image: ## Optionally specify an array of imagePullSecrets. ## Secrets must be manually created in the namespace. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ + ## e.g: + ## pullSecrets: + ## - myRegistryKeySecretName ## - # pullSecrets: - # - myRegistryKeySecretName + pullSecrets: [] ## Set to true if you would like to see extra information on logs ## - -## Force target Kubernetes version (using Helm capabilites if not set) -## -kubeVersion: - -## String to partially override ebjca.fullname template (will maintain the release name) -## -# nameOverride: - -## String to fully override ebjca.fullname template -## -# fullnameOverride: - -## Deployment pod host aliases -## https://kubernetes.io/docs/concepts/services-networking/add-entries-to-pod-etc-hosts-with-host-aliases/ -## -hostAliases: [] - -## Number of EJBCA replicas to deploy. +## @param replicaCount Number of EJBCA replicas to deploy ## replicaCount: 1 - -## Admin of the application -## ref: https://github.com/bitnami/bitnami-docker-ejbca#environment-variables -## -ejbcaAdminUsername: bitnami - -## Password for the administrator account -## If the password is not specified, a random one will be generated -## -# ejbcaAdminPassword: - -## Alternatively, you can provide the name of an existing secret containing -## a key named "ejbca-admin-password" -## NOTE: This will override the password defined at ejbcaAdminPassword -## -# existingSecret: - -## Options used to launch the WildFly server -## E.g. ejbcaJavaOpts: "-Xms2048m -Xmx2048m" -# ejbcaJavaOpts: - -## Details regarding the CA that EJBCA will instantiate -## -ejbcaCA: - ## The name of the CA - ## - name: "ManagementCA" - - ## The base DomainName of the CA - ## - ## e.g. baseDN: "O=Example CA,C=SE,UID=c-5ca04c9328c8208704310f7c2ed16414" - ## - baseDN: - -## Name of an existing Secret containing a Keystore object -## to be imported by EBJCA. -## -## It should contain at the following two keys: -## -## "keystore.jks" --> The actual keystore object -## "keystore-password" --> Password used to encrypt keystore.jks -## -## ejbcaKeystoreExistingSecret: -## - -## Additional container environment variables -## extraEnv: -## - name: -## value: -## -extraEnv: [] - -## Custom command to override image cmd -## -# command: [] - -## Custom args for the custom command: -# args: [] - -## Additional volume mounts +## @param extraVolumeMounts Additional volume mounts (used along with `extraVolumes`) ## Example: Mount CA file ## extraVolumeMounts ## - name: ca-cert @@ -116,8 +74,7 @@ extraEnv: [] ## mountPath: /path/to/ca_cert ## extraVolumeMounts: [] - -## Additional volumes +## @param extraVolumes Array of extra volumes to be added deployment. Requires setting `extraVolumeMounts` ## Example: Add secret volume ## extraVolumes: ## - name: ca-cert @@ -128,254 +85,70 @@ extraVolumeMounts: [] ## path: ca_cert ## extraVolumes: [] - -## EJBCA containers' resource requests and limits -## ref: http://kubernetes.io/docs/user-guide/compute-resources/ -## -resources: - limits: {} - requests: - memory: 512Mi - cpu: 300m - -## Pod annotations +## @param podAnnotations Additional pod annotations ## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/ ## podAnnotations: {} - -## Additional pod labels +## @param podLabels Additional pod labels ## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/ ## podLabels: {} - -## Add labels to all the deployed resources -## -commonLabels: {} - -## Add annotations to all the deployed resources -## -commonAnnotations: {} - ## K8s Security Context for EJBCA pods ## https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ +## @param podSecurityContext.enabled Enable security context for EJBCA container +## @param podSecurityContext.fsGroup Group ID for the volumes of the pod ## podSecurityContext: enabled: true fsGroup: 1001 - -## K8s Security Context for EJBCA container -## -containerSecurityContext: - enabled: true - runAsUser: 1001 - -## Pod affinity preset +## @param podAffinityPreset Pod affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` ## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity ## Allowed values: soft, hard ## podAffinityPreset: "" - -## Pod anti-affinity preset +## @param podAntiAffinityPreset Pod anti-affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard` ## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity ## Allowed values: soft, hard ## podAntiAffinityPreset: soft - ## Node affinity preset ## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity -## Allowed values: soft, hard +## @param nodeAffinityPreset.type Node affinity preset type. Ignored if `affinity` is set. Allowed values: `soft` or `hard` +## @param nodeAffinityPreset.key Node label key to match Ignored if `affinity` is set. +## @param nodeAffinityPreset.values Node label values to match. Ignored if `affinity` is set. ## nodeAffinityPreset: - ## Node affinity type - ## Allowed values: soft, hard - ## type: "" - ## Node label key to match ## E.g. ## key: "kubernetes.io/e2e-az-name" ## key: "" - ## Node label values to match ## E.g. ## values: ## - e2e-az1 ## - e2e-az2 ## values: [] - -## Affinity for pod assignment +## @param affinity Affinity for pod assignment ## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity ## Note: podAffinityPreset, podAntiAffinityPreset, and nodeAffinityPreset will be ignored when it's set ## affinity: {} - -## Node labels for pod assignment +## @param nodeSelector Node labels for pod assignment ## Ref: https://kubernetes.io/docs/user-guide/node-selection/ ## nodeSelector: {} - -## Tolerations for pod assignment +## @param tolerations Tolerations for pod assignment ## Ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/ ## tolerations: [] - -## EJBCA pod extra options for liveness and readiness probes -## ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle/#container-probes -## -livenessProbe: - enabled: true - initialDelaySeconds: 500 - periodSeconds: 10 - timeoutSeconds: 5 - failureThreshold: 6 - successThreshold: 1 - -readinessProbe: - enabled: true - initialDelaySeconds: 500 - periodSeconds: 10 - timeoutSeconds: 5 - failureThreshold: 6 - successThreshold: 1 - -## Custom liveness and readiness probes (evaluated as a template) -## -customLivenessProbe: {} -customReadinessProbe: {} - -## EJBCA Container ports to open -## -containerPorts: - http: 8080 - https: 8443 - -## Kubernetes configuration -## For minikube, set this to NodePort, elsewhere use LoadBalancer or ClusterIP -## -service: - type: LoadBalancer - ## HTTP Port - ## - port: 8080 - ## HTTPS Port - ## - # httpsPort: 8443 - httpsPort: 8443 - ## HTTPS Advertised port - ## - advertisedHttpsPort: 443 - - ## HTTPS Target Port - ## defaults to https unless overridden to the specified port. - ## if you want the target port to be "http" or "80" you can specify that here. - ## - httpsTargetPort: https - ## Node Ports to expose - ## nodePorts: - ## http: - ## https: - ## - nodePorts: - http: "" - https: "" - ## Enable client source IP preservation - ## ref http://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip - ## - externalTrafficPolicy: Cluster - annotations: {} - ## Limits which cidr blocks can connect to service's load balancer - ## Only valid if service.type: LoadBalancer - ## - loadBalancerSourceRanges: [] - ## Extra ports to expose (normally used with the `sidecar` value) - # extraPorts: - -## Configure the ingress resource that allows you to access the -## EJBCA installation. Set up the URL -## ref: http://kubernetes.io/docs/user-guide/ingress/ -## -ingress: - ## Set to true to enable ingress record generation - ## - enabled: false - - ## Set this to true in order to add the corresponding annotations for cert-manager - ## - certManager: false - - ## Ingress Path type - ## - pathType: ImplementationSpecific - - ## Override API Version (automatically detected if not set) - ## - apiVersion: - - ## When the ingress is enabled, a host pointing to this will be created - ## - hostname: ejbca.local - - ## The Path to EJBCA. You may need to set this to '/*' in order to use this - ## with ALB ingress controllers. - ## - path: / - - ## Ingress annotations done as key:value pairs - ## For a full list of possible ingress annotations, please see - ## ref: https://github.com/kubernetes/ingress-nginx/blob/master/docs/user-guide/nginx-configuration/annotations.md - ## - ## If certManager is set to true, annotation kubernetes.io/tls-acme: "true" will automatically be set - ## - annotations: {} - - ## Enable TLS configuration for the hostname defined at ingress.hostname parameter - ## TLS certificates will be retrieved from a TLS secret with name: {{- printf "%s-tls" .Values.ingress.hostname }} - ## You can use the ingress.secrets parameter to create this TLS secret or relay on cert-manager to create it - ## - tls: false - - ## The list of additional hostnames to be covered with this ingress record. - ## Most likely the hostname above will be enough, but in the event more hosts are needed, this is an array - ## extraHosts: - ## - name: ejbca.local - ## path: / - ## - - ## Any additional arbitrary paths that may need to be added to the ingress under the main host. - ## For example: The ALB ingress controller requires a special rule for handling SSL redirection. - ## extraPaths: - ## - path: /* - ## backend: - ## serviceName: ssl-redirect - ## servicePort: use-annotation - ## - - ## The tls configuration for additional hostnames to be covered with this ingress record. - ## see: https://kubernetes.io/docs/concepts/services-networking/ingress/#tls - ## extraTls: - ## - hosts: - ## - ejbca.local - ## secretName: ejbca.local-tls - ## - - ## If you're providing your own certificates, please use this to add the certificates as secrets - ## key and certificate should start with -----BEGIN CERTIFICATE----- or - ## -----BEGIN RSA PRIVATE KEY----- - ## - ## name should line up with a tlsSecret set further up - ## If you're using cert-manager, this is unneeded, as it will create the secret for you if it is not set - ## - ## It is also possible to create and manage the certificates outside of this helm chart - ## Please see README.md for more information - ## - secrets: [] - ## - name: ejbca.local-tls - ## key: - ## certificate: - ## - ## Enable persistence using Persistent Volume Claims ## ref: http://kubernetes.io/docs/user-guide/persistent-volumes/ +## @param persistence.enabled Whether to enable persistence based on Persistent Volume Claims +## @param persistence.accessMode PVC Access Mode (RWO, ROX, RWX) +## @param persistence.size Size of the PVC to request +## @param persistence.storageClass PVC Storage Class +## @param persistence.existingClaim Name of an existing PVC to reuse ## persistence: enabled: true @@ -386,46 +159,304 @@ persistence: ## set, choosing the default provisioner. (gp2 on AWS, standard on ## GKE, AWS & OpenStack) ## - # storageClass: "-" + storageClass: + ## If you want to reuse an existing claim, you can pass the name of the PVC using the existingClaim variable + ## e.g: + ## existingClaim: your-claim ## - ## If you want to reuse an existing claim, you can pass the name of the PVC using - ## the existingClaim variable - # existingClaim: your-claim + existingClaim: accessMode: ReadWriteOnce size: 2Gi +## @param sidecars Attach additional sidecar containers to the pod +## Example: +## sidecars: +## - name: your-image-name +## image: your-image +## imagePullPolicy: Always +## ports: +## - name: portname +## containerPort: 1234 +## +sidecars: {} +## @param initContainers Additional init containers to add to the pods +## ref: https://kubernetes.io/docs/concepts/workloads/pods/init-containers/ +## Example: +## initContainers: +## - name: your-image-name +## image: your-image +## imagePullPolicy: Always +## +initContainers: {} +## @param hostAliases Add deployment host aliases +## https://kubernetes.io/docs/concepts/services-networking/add-entries-to-pod-etc-hosts-with-host-aliases/ +## +hostAliases: [] +## @param ejbcaAdminUsername EJBCA administrator username +## ref: https://github.com/bitnami/bitnami-docker-ejbca#environment-variables +## +ejbcaAdminUsername: bitnami +## @param ejbcaAdminPassword Password for the administrator account +## If the password is not specified, a random one will be generated +## +ejbcaAdminPassword: +## @param existingSecret Alternatively, you can provide the name of an existing secret containing +## a key named "ejbca-admin-password" +## NOTE: This will override the password defined at ejbcaAdminPassword +## +existingSecret: +## @param ejbcaJavaOpts Options used to launch the WildFly server +## E.g. ejbcaJavaOpts: "-Xms2048m -Xmx2048m" +ejbcaJavaOpts: +## Details regarding the CA that EJBCA will instantiate +## @param ejbcaCA.name Name of the CA EJBCA will instantiate by default +## @param ejbcaCA.baseDN Base DomainName of the CA EJBCA will instantiate by default +## +ejbcaCA: + name: "ManagementCA" + ## e.g. baseDN: "O=Example CA,C=SE,UID=c-5ca04c9328c8208704310f7c2ed16414" + ## + baseDN: +## @param ejbcaKeystoreExistingSecret Name of an existing Secret containing a Keystore object +## to be imported by EBJCA. +## +## It should contain at the following two keys: +## +## "keystore.jks" --> The actual keystore object +## "keystore-password" --> Password used to encrypt keystore.jks +## +ejbcaKeystoreExistingSecret: +## @param extraEnv Additional container environment variables +## extraEnv: +## - name: +## value: +## +extraEnv: [] +## @param command Custom command to override image cmd +## +command: [] +## @param args Custom args for the custom command +## +args: [] +## EJBCA containers' resource requests and limits +## ref: http://kubernetes.io/docs/user-guide/compute-resources/ +## @param resources.limits The resources limits for the container +## @param resources.requests [object] The requested resources for the container +## +resources: + limits: {} + requests: + memory: 512Mi + cpu: 300m +## K8s Security Context for EJBCA container +## @param containerSecurityContext.enabled Enabled EJBCA containers' Security Context +## @param containerSecurityContext.runAsUser Set EJBCA containers' Security Context runAsUser +## +containerSecurityContext: + enabled: true + runAsUser: 1001 +## EJBCA pod extra options for liveness probe +## ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle/#container-probes +## @param livenessProbe.enabled Enable/disable livenessProbe +## @param livenessProbe.initialDelaySeconds Delay before liveness probe is initiated +## @param livenessProbe.periodSeconds How often to perform the probe +## @param livenessProbe.timeoutSeconds When the probe times out +## @param livenessProbe.failureThreshold Minimum consecutive failures for the probe +## @param livenessProbe.successThreshold Minimum consecutive successes for the probe +## +livenessProbe: + enabled: true + initialDelaySeconds: 500 + periodSeconds: 10 + timeoutSeconds: 5 + failureThreshold: 6 + successThreshold: 1 +## EJBCA pod extra options for readiness probe +## ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle/#container-probes +## @param readinessProbe.enabled Enable/disable readinessProbe +## @param readinessProbe.initialDelaySeconds Delay before readiness probe is initiated +## @param readinessProbe.periodSeconds How often to perform the probe +## @param readinessProbe.timeoutSeconds When the probe times out +## @param readinessProbe.failureThreshold Minimum consecutive failures for the probe +## @param readinessProbe.successThreshold Minimum consecutive successes for the probe +## +readinessProbe: + enabled: true + initialDelaySeconds: 500 + periodSeconds: 10 + timeoutSeconds: 5 + failureThreshold: 6 + successThreshold: 1 +## @param customLivenessProbe Custom liveness probe to execute (when the main one is disabled) +## +customLivenessProbe: {} +## @param customReadinessProbe Custom readiness probe to execute (when the main one is disabled) +## +customReadinessProbe: {} +## @param containerPorts [object] EJBCA Container ports to open +## +containerPorts: + http: 8080 + https: 8443 +## @section Service parameters + +## Kubernetes configuration. For minikube, set this to NodePort, elsewhere use LoadBalancer or ClusterIP ## +service: + ## @param service.type Kubernetes Service type + ## + type: LoadBalancer + ## @param service.port Service HTTP port + ## + port: 8080 + ## @param service.httpsPort Service HTTPS port + ## + httpsPort: 8443 + ## @param service.advertisedHttpsPort Port used for the administration + ## + advertisedHttpsPort: 443 + ## @param service.httpsTargetPort Service Target HTTPS port + ## defaults to https unless overridden to the specified port. + ## if you want the target port to be "http" or "80" you can specify that here. + ## + httpsTargetPort: https + ## @param service.nodePorts [object] Node Ports to expose + ## nodePorts: + ## http: + ## https: + ## + nodePorts: + http: "" + https: "" + ## @param service.externalTrafficPolicy Enable client source IP preservation + ## ref http://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip + ## + externalTrafficPolicy: Cluster + ## @param service.annotations Service annotations + ## + annotations: {} + ## @param service.loadBalancerSourceRanges Limits which cidr blocks can connect to service's load balancer + ## Only valid if service.type: LoadBalancer + ## + loadBalancerSourceRanges: [] + ## @param service.extraPorts Extra ports to expose in the service (normally used with the `sidecar` value) + ## + extraPorts: + +## @section Ingress parameters + +## Configure the ingress resource that allows you to access the +## EJBCA installation. Set up the URL +## ref: http://kubernetes.io/docs/user-guide/ingress/ +## +ingress: + ## @param ingress.enabled Enable ingress controller resource + ## + enabled: false + ## @param ingress.certManager Add annotations for cert-manager + ## + certManager: false + ## @param ingress.pathType Ingress Path type + ## + pathType: ImplementationSpecific + ## @param ingress.apiVersion Override API Version (automatically detected if not set) + ## + apiVersion: + ## @param ingress.hostname Default host for the ingress resource + ## + hostname: ejbca.local + ## @param ingress.path The Path to EJBCA. You may need to set this to '/*' in order to use this + ## with ALB ingress controllers. + ## + path: / + ## @param ingress.annotations Ingress annotations done as key:value pairs + ## For a full list of possible ingress annotations, please see + ## ref: https://github.com/kubernetes/ingress-nginx/blob/master/docs/user-guide/nginx-configuration/annotations.md + ## + ## If certManager is set to true, annotation kubernetes.io/tls-acme: "true" will automatically be set + ## + annotations: {} + ## @param ingress.tls Enable TLS configuration for the hostname defined at ingress.hostname parameter + ## TLS certificates will be retrieved from a TLS secret with name: {{- printf "%s-tls" .Values.ingress.hostname }} + ## You can use the ingress.secrets parameter to create this TLS secret or relay on cert-manager to create it + ## + tls: false + ## @param ingress.extraHosts The list of additional hostnames to be covered with this ingress record. + ## Most likely the hostname above will be enough, but in the event more hosts are needed, this is an array + ## extraHosts: + ## - name: ejbca.local + ## path: / + extraHosts: [] + ## @param ingress.extraPaths Any additional arbitrary paths that may need to be added to the ingress under the main host. + ## For example: The ALB ingress controller requires a special rule for handling SSL redirection. + ## extraPaths: + ## - path: /* + ## backend: + ## serviceName: ssl-redirect + ## servicePort: use-annotation + extraPaths: [] + ## @param ingress.extraTls The tls configuration for additional hostnames to be covered with this ingress record. + ## see: https://kubernetes.io/docs/concepts/services-networking/ingress/#tls + ## extraTls: + ## - hosts: + ## - ejbca.local + ## secretName: ejbca.local-tls + extraTls: [] + ## @param ingress.secrets If you're providing your own certificates, please use this to add the certificates as secrets + ## key and certificate should start with -----BEGIN CERTIFICATE----- or + ## -----BEGIN RSA PRIVATE KEY----- + ## + ## name should line up with a tlsSecret set further up + ## If you're using cert-manager, this is unneeded, as it will create the secret for you if it is not set + ## + ## It is also possible to create and manage the certificates outside of this helm chart + ## Please see README.md for more information + ## Example: + ## - name: ejbca.local-tls + ## key: + ## certificate: + ## + secrets: [] + +## @section Database parameters + ## MariaDB chart configuration -## ## https://github.com/bitnami/charts/blob/master/bitnami/mariadb/values.yaml ## mariadb: - ## Whether to deploy a mariadb server to satisfy the applications database requirements. To use an external database set this to false and configure the externalDatabase parameters + ## @param mariadb.enabled Whether to deploy a mariadb server to satisfy the applications database requirements. + ## To use an external database set this to false and configure the externalDatabase parameters ## enabled: true - - ## MariaDB architecture. Allowed values: standalone or replication + ## @param mariadb.architecture MariaDB architecture (`standalone` or `replication`) ## architecture: standalone - ## MariaDB Authentication parameters + ## @param mariadb.auth.rootPassword Password for the MariaDB `root` user + ## @param mariadb.auth.database Database name to create + ## @param mariadb.auth.username Database user to create + ## @param mariadb.auth.password Password for the database ## auth: - ## MariaDB root password ## ref: https://github.com/bitnami/bitnami-docker-mariadb#setting-the-root-password-on-first-run ## rootPassword: "" - ## MariaDB custom user and database ## ref: https://github.com/bitnami/bitnami-docker-mariadb/blob/master/README.md#creating-a-database-on-first-run - ## ref: https://github.com/bitnami/bitnami-docker-mariadb/blob/master/README.md#creating-a-database-user-on-first-run ## database: bitnami_ejbca + ## ref: https://github.com/bitnami/bitnami-docker-mariadb/blob/master/README.md#creating-a-database-user-on-first-run + ## username: bn_ejbca password: "" - primary: ## Enable persistence using Persistent Volume Claims ## ref: http://kubernetes.io/docs/user-guide/persistent-volumes/ + ## @param mariadb.primary.persistence.enabled Enable database persistence using PVC + ## @param mariadb.primary.persistence.storageClass MariaDB primary persistent volume storage Class + ## @param mariadb.primary.persistence.accessMode Persistent Volume access mode + ## @param mariadb.primary.persistence.size Database Persistent Volume Size + ## @param mariadb.primary.persistence.hostPath Set path in case you want to use local host path volumes (not recommended in production) + ## @param mariadb.primary.persistence.existingClaim Name of an existing `PersistentVolumeClaim` for MariaDB primary replicas ## persistence: enabled: true @@ -439,57 +470,21 @@ mariadb: storageClass: accessMode: ReadWriteOnce size: 8Gi - ## Set path in case you want to use local host path volumes (not recommended in production) - ## hostPath: - ## Use an existing PVC - ## existingClaim: - -## ## External Database Configuration -## ## All of these values are only used when mariadb.enabled is set to false +## @param externalDatabase.host Host of the external database +## @param externalDatabase.user non-root Username for EJBCA Database +## @param externalDatabase.password Password for the above username +## @param externalDatabase.existingSecret Name of an existing secret resource containing the DB password in a 'mariadb-password' key +## @param externalDatabase.database Name of the existing database +## @param externalDatabase.port Database port number ## externalDatabase: - ## Database host - ## host: localhost - ## non-root Username for EJBCA Database - ## user: bn_ejbca - ## Database password - ## password: "" - ## Name of an existing secret resource containing the DB password in a 'mariadb-password' key - ## existingSecret: "" - ## Database name - ## database: bitnami_ejbca - - ## Database port number - ## port: 3306 - -## Add sidecars to the pod. -## Example: -## sidecars: -## - name: your-image-name -## image: your-image -## imagePullPolicy: Always -## ports: -## - name: portname -## containerPort: 1234 -## -sidecars: {} - -## Add init containers to the pod. -## ref: https://kubernetes.io/docs/concepts/workloads/pods/init-containers/ -## Example: -## initContainers: -## - name: your-image-name -## image: your-image -## imagePullPolicy: Always -## -initContainers: {}