diff --git a/.editorconfig b/.editorconfig index 6f313c6a..91c10aa5 100644 --- a/.editorconfig +++ b/.editorconfig @@ -13,3 +13,6 @@ trim_trailing_whitespace = false [*.yml] indent_size = 2 + +[*.yaml] +indent_size = 2 diff --git a/.values.yaml b/.values.yaml index b4617d45..f82f7d71 100644 --- a/.values.yaml +++ b/.values.yaml @@ -20,548 +20,548 @@ applicationName: "cssd-production-back" ########################################################## cronJob: - enabled: false - jobs: - # db-migration: - # schedule: "* * * 8 *" - # env: - # KEY: - # value: VALUE - # image: - # repository: docker.io/nginx - # tag: v1.0.0 - # digest: '' # if set to a non empty value, digest takes precedence on the tag - # imagePullPolicy: IfNotPresent - # command: ["/bin/bash"] - # args: ["-c","sleep 5000"] - # resources: - # requests: - # memory: 5Gi - # cpu: 1 + enabled: false + jobs: + # db-migration: + # schedule: "* * * 8 *" + # env: + # KEY: + # value: VALUE + # image: + # repository: docker.io/nginx + # tag: v1.0.0 + # digest: '' # if set to a non empty value, digest takes precedence on the tag + # imagePullPolicy: IfNotPresent + # command: ["/bin/bash"] + # args: ["-c","sleep 5000"] + # resources: + # requests: + # memory: 5Gi + # cpu: 1 ########################################################## # Deployment ########################################################## deployment: - enabled: true - # By default deploymentStrategy is set to rollingUpdate with maxSurge of 25% and maxUnavailable of 25% - # You can change type to `Recreate` or can uncomment `rollingUpdate` specification and adjust them to your usage. - strategy: - type: RollingUpdate - # rollingUpdate: - # maxSurge: 25% - # maxUnavailable: 25% + enabled: true + # By default deploymentStrategy is set to rollingUpdate with maxSurge of 25% and maxUnavailable of 25% + # You can change type to `Recreate` or can uncomment `rollingUpdate` specification and adjust them to your usage. + strategy: + type: RollingUpdate + # rollingUpdate: + # maxSurge: 25% + # maxUnavailable: 25% - # Reload deployment if configMap/secret updates - reloadOnChange: true + # Reload deployment if configMap/secret updates + reloadOnChange: true - # Select nodes to deploy which matches the following labels - nodeSelector: - # cloud.google.com/gke-nodepool: default-pool + # Select nodes to deploy which matches the following labels + nodeSelector: + # cloud.google.com/gke-nodepool: default-pool - # Init containers which runs before the app container - hostAliases: - # - ip: "127.0.0.1" - # hostnames: - # - "foo.local" - # - "bar.local" - # - ip: "10.1.2.3" - # hostnames: - # - "foo.remote" - # - "bar.remote" + # Init containers which runs before the app container + hostAliases: + # - ip: "127.0.0.1" + # hostnames: + # - "foo.local" + # - "bar.local" + # - ip: "10.1.2.3" + # hostnames: + # - "foo.remote" + # - "bar.remote" - # Init containers which runs before the app container - initContainers: - # init-contaner: - # image: busybox - # imagePullPolicy: IfNotPresent - # command: ['/bin/sh'] + # Init containers which runs before the app container + initContainers: + # init-contaner: + # image: busybox + # imagePullPolicy: IfNotPresent + # command: ['/bin/sh'] - # Additional labels for Deployment - additionalLabels: - # key: value + # Additional labels for Deployment + additionalLabels: + # key: value - # Additional label added on pod which is used in Service's Label Selector - podLabels: - # env: prod + # Additional label added on pod which is used in Service's Label Selector + podLabels: + # env: prod - # Annotations on deployments - annotations: + # Annotations on deployments + annotations: - # Additional Pod Annotations added on pod created by this Deployment - additionalPodAnnotations: - # key: value + # Additional Pod Annotations added on pod created by this Deployment + additionalPodAnnotations: + # key: value - # Annotations for fluentd Configurations - fluentdConfigAnnotations: - # fluentd: - # regex: hello - # timeFormat: world + # Annotations for fluentd Configurations + fluentdConfigAnnotations: + # fluentd: + # regex: hello + # timeFormat: world - # Replicas to be created - replicas: + # Replicas to be created + replicas: - # Secrets used to pull image - imagePullSecrets: "regcred" + # Secrets used to pull image + imagePullSecrets: "regcred" - # If want to mount Envs from configmap or secret - envFrom: - application-config-env: - type: configmap - nameSuffix: configmap - application-secret-env: - type: secret - nameSuffix: secret + # If want to mount Envs from configmap or secret + envFrom: + application-config-env: + type: configmap + nameSuffix: configmap + application-secret-env: + type: secret + nameSuffix: secret - # Environment variables to be passed to the app container - env: - # FREQUENCY: - # valueFrom: - # configMapKeyRef: - # name: config - # key: frequency + # Environment variables to be passed to the app container + env: + # FREQUENCY: + # valueFrom: + # configMapKeyRef: + # name: config + # key: frequency - # Volumes to be added to the pod - volumes: - nginx-volume: - configMap: - name: '{{ template "application.name" . }}-nginx' - # secret-volume: - # secret: - # secretName: secret-name - # persistent-volume-name: - # persistentVolumeClaim: - # claimName: claim-name + # Volumes to be added to the pod + volumes: + nginx-volume: + configMap: + name: '{{ template "application.name" . }}-nginx' + # secret-volume: + # secret: + # secretName: secret-name + # persistent-volume-name: + # persistentVolumeClaim: + # claimName: claim-name - # Mount path for Volumes - volumeMounts: - nginx-volume: - mountPath: /etc/nginx/nginx.conf - subPath: nginx.conf + # Mount path for Volumes + volumeMounts: + nginx-volume: + mountPath: /etc/nginx/nginx.conf + subPath: nginx.conf - # volume-name-2: - # mountPath: path-2 + # volume-name-2: + # mountPath: path-2 - # Taint tolerations for nodes - tolerations: - # - key: "dedicated" - # operator: "Equal" - # value: "app" - # effect: "NoSchedule" + # Taint tolerations for nodes + tolerations: + # - key: "dedicated" + # operator: "Equal" + # value: "app" + # effect: "NoSchedule" - # Pod affinity and pod anti-affinity allow you to specify rules about how pods should be placed relative to other pods. - affinity: - # nodeAffinity: - # requiredDuringSchedulingIgnoredDuringExecution: - # nodeSelectorTerms: - # - matchExpressions: - # - key: disktype - # operator: In - # values: - # - ssd + # Pod affinity and pod anti-affinity allow you to specify rules about how pods should be placed relative to other pods. + affinity: + # nodeAffinity: + # requiredDuringSchedulingIgnoredDuringExecution: + # nodeSelectorTerms: + # - matchExpressions: + # - key: disktype + # operator: In + # values: + # - ssd - # Topology spread constraints - topologySpreadConstraints: - # - maxSkew: 1 - # topologyKey: kubernetes.io/hostname - # whenUnsatisfiable: ScheduleAnyway - # labelSelector: - # matchExpressions: - # - key: disktype - # operator: In - # values: - # - ssd - # - maxSkew: 1 - # topologyKey: topology.kubernetes.io/zone - # whenUnsatisfiable: ScheduleAnyway - # labelSelector: - # matchExpressions: - # - key: disktype - # operator: In - # values: - # - ssd + # Topology spread constraints + topologySpreadConstraints: + # - maxSkew: 1 + # topologyKey: kubernetes.io/hostname + # whenUnsatisfiable: ScheduleAnyway + # labelSelector: + # matchExpressions: + # - key: disktype + # operator: In + # values: + # - ssd + # - maxSkew: 1 + # topologyKey: topology.kubernetes.io/zone + # whenUnsatisfiable: ScheduleAnyway + # labelSelector: + # matchExpressions: + # - key: disktype + # operator: In + # values: + # - ssd - # Image of the app container - image: - repository: docker.willaspace.com/repository/docker-hosted/external-projects/cssd-back - tag: nginx-latest - digest: '' # if set to a non empty value, digest takes precedence on the tag - pullPolicy: IfNotPresent - dnsConfig: - # options: - # - name: ndots - # value: '1' - # Startup, Readiness and Liveness probes - startupProbe: - enabled: false - failureThreshold: 30 - periodSeconds: 10 - # Must specify either one of the following field when enabled - httpGet: {} - exec: {} - tcpSocket: {} + # Image of the app container + image: + repository: docker.willaspace.com/repository/docker-hosted/external-projects/cssd-back + tag: nginx-latest + digest: '' # if set to a non empty value, digest takes precedence on the tag + pullPolicy: IfNotPresent + dnsConfig: + # options: + # - name: ndots + # value: '1' + # Startup, Readiness and Liveness probes + startupProbe: + enabled: false + failureThreshold: 30 + periodSeconds: 10 + # Must specify either one of the following field when enabled + httpGet: {} + exec: {} + tcpSocket: {} - readinessProbe: - enabled: false - failureThreshold: 3 - periodSeconds: 10 - successThreshold: 1 - timeoutSeconds: 1 - initialDelaySeconds: 10 - # Must specify either one of the following field when enabled - httpGet: {} - exec: {} - tcpSocket: {} + readinessProbe: + enabled: false + failureThreshold: 3 + periodSeconds: 10 + successThreshold: 1 + timeoutSeconds: 1 + initialDelaySeconds: 10 + # Must specify either one of the following field when enabled + httpGet: {} + exec: {} + tcpSocket: {} - livenessProbe: - enabled: false - failureThreshold: 3 - periodSeconds: 10 - successThreshold: 1 - timeoutSeconds: 1 - initialDelaySeconds: 10 - # Must specify either one of the following field when enabled - httpGet: {} - exec: {} - tcpSocket: {} + livenessProbe: + enabled: false + failureThreshold: 3 + periodSeconds: 10 + successThreshold: 1 + timeoutSeconds: 1 + initialDelaySeconds: 10 + # Must specify either one of the following field when enabled + httpGet: {} + exec: {} + tcpSocket: {} - # Resources to be defined for pod - resources: - limits: - memory: 8Gi - cpu: 8 - requests: - memory: 8Gi - cpu: 4 + # Resources to be defined for pod + resources: + limits: + memory: 8Gi + cpu: 8 + requests: + memory: 8Gi + cpu: 4 - # Security Context at Container Level - containerSecurityContext: - readOnlyRootFilesystem: false - runAsNonRoot: false + # Security Context at Container Level + containerSecurityContext: + readOnlyRootFilesystem: false + runAsNonRoot: false - openshiftOAuthProxy: - enabled: false - port: 8080 # Port on which application is running inside container - secretName: "openshift-oauth-proxy-tls" - image: openshift/oauth-proxy:latest # If you have a custom container for oauth-proxy that can be updated here - disableTLSArg: false # If disabled --http-address=:8081 will be used instead of --https-address=:8443 , to be used when an ingress is used for application - # Add additional containers besides init and app containers - additionalContainers: - - name: php-fpm - image: docker.willaspace.com/repository/docker-hosted/external-projects/cssd-back:latest - imagePullPolicy: IfNotPresent - envFrom: - - configMapRef: - name: cssd-production-back-configmap - - secretRef: - name: cssd-production-back-secret + openshiftOAuthProxy: + enabled: false + port: 8080 # Port on which application is running inside container + secretName: "openshift-oauth-proxy-tls" + image: openshift/oauth-proxy:latest # If you have a custom container for oauth-proxy that can be updated here + disableTLSArg: false # If disabled --http-address=:8081 will be used instead of --https-address=:8443 , to be used when an ingress is used for application + # Add additional containers besides init and app containers + additionalContainers: + - name: php-fpm + image: docker.willaspace.com/repository/docker-hosted/external-projects/cssd-back:latest + imagePullPolicy: IfNotPresent + envFrom: + - configMapRef: + name: cssd-production-back-configmap + - secretRef: + name: cssd-production-back-secret - # Security Context for the pod + # Security Context for the pod - securityContext: - # fsGroup: 2000 + securityContext: + # fsGroup: 2000 - # Command for primary container - command: [] + # Command for primary container + command: [] - # Args for primary contaner - args: [] + # Args for primary contaner + args: [] - # List of ports for the primary container - ports: - - containerPort: 80 - name: http - protocol: TCP - #- containerPort: 8778 - # name: jolokia - # protocol: TCP - #- containerPort: 8443 - # name: https - # protocol: TCP + # List of ports for the primary container + ports: + - containerPort: 80 + name: http + protocol: TCP + #- containerPort: 8778 + # name: jolokia + # protocol: TCP + #- containerPort: 8443 + # name: https + # protocol: TCP ########################################################## # Add Storage volumes to the pods ########################################################## persistence: - enabled: false - mountPVC: false - mountPath: "/" - name: "" - accessMode: ReadWriteOnce - ## If defined, storageClass: - ## If set to "-", storageClass: "", which disables dynamic provisioning - ## If undefined (the default) or set to null, no storageClass spec is - ## set, choosing the default provisioner. (gp2 on AWS, standard on - ## GKE, AWS & OpenStack) - ## - storageClass: "-" - additionalLabels: - # key: "value" - annotations: - # "helm.sh/resource-policy": keep - storageSize: 8Gi - volumeMode: "" - volumeName: "" + enabled: false + mountPVC: false + mountPath: "/" + name: "" + accessMode: ReadWriteOnce + ## If defined, storageClass: + ## If set to "-", storageClass: "", which disables dynamic provisioning + ## If undefined (the default) or set to null, no storageClass spec is + ## set, choosing the default provisioner. (gp2 on AWS, standard on + ## GKE, AWS & OpenStack) + ## + storageClass: "-" + additionalLabels: + # key: "value" + annotations: + # "helm.sh/resource-policy": keep + storageSize: 8Gi + volumeMode: "" + volumeName: "" ########################################################## # Service object for servicing pods ########################################################## service: - enabled: true - additionalLabels: - # expose: "true" + enabled: true + additionalLabels: + # expose: "true" - annotations: - # config.xposer.stakater.com/Domain: stakater.com - # config.xposer.stakater.com/IngressNameTemplate: '{{ "{{.Service}}-{{.Namespace}}" }}' - # config.xposer.stakater.com/IngressURLPath: / - # config.xposer.stakater.com/IngressURLTemplate: '{{ "{{.Service}}.{{.Namespace}}.{{.Domain}}" }}' - # service.alpha.openshift.io/serving-cert-secret-name: | - # '{{ template "application.name" . }}-tls' - # xposer.stakater.com/annotations: |- - # kubernetes.io/ingress.class: external-ingress - # ingress.kubernetes.io/rewrite-target: / - # ingress.kubernetes.io/force-ssl-redirect: true + annotations: + # config.xposer.stakater.com/Domain: stakater.com + # config.xposer.stakater.com/IngressNameTemplate: '{{ "{{.Service}}-{{.Namespace}}" }}' + # config.xposer.stakater.com/IngressURLPath: / + # config.xposer.stakater.com/IngressURLTemplate: '{{ "{{.Service}}.{{.Namespace}}.{{.Domain}}" }}' + # service.alpha.openshift.io/serving-cert-secret-name: | + # '{{ template "application.name" . }}-tls' + # xposer.stakater.com/annotations: |- + # kubernetes.io/ingress.class: external-ingress + # ingress.kubernetes.io/rewrite-target: / + # ingress.kubernetes.io/force-ssl-redirect: true - ports: - - port: 80 - name: http - protocol: TCP - targetPort: 80 - type: NodePort + ports: + - port: 80 + name: http + protocol: TCP + targetPort: 80 + type: NodePort ########################################################## # Ingress object for exposing services ########################################################## ingress: - enabled: true + enabled: true - # Name of the ingress class - ingressClassName: 'nginx' + # Name of the ingress class + ingressClassName: 'nginx' - # List of host addresses to be exposed by this Ingress - hosts: - - host: cssd-doc.ir - # Additional labels for this Ingress - additionalLabels: + # List of host addresses to be exposed by this Ingress + hosts: + - host: cssd-doc.ir + # Additional labels for this Ingress + additionalLabels: - # Add annotations to this Ingress - annotations: - # kubernetes.io/ingress.class: external-ingress - # ingress.kubernetes.io/rewrite-target: / - # ingress.kubernetes.io/force-ssl-redirect: true + # Add annotations to this Ingress + annotations: + # kubernetes.io/ingress.class: external-ingress + # ingress.kubernetes.io/rewrite-target: / + # ingress.kubernetes.io/force-ssl-redirect: true - # TLS details for this Ingress - tls: - # Secrets must be manually created in the namespace. - - secretName: cssd-doc-com-certificate - hosts: - - cssd-doc.ir + # TLS details for this Ingress + tls: + # Secrets must be manually created in the namespace. + - secretName: cssd-doc-ir-certificate + hosts: + - cssd-doc.ir ########################################################## # Route object for exposing services (OpenShift) ########################################################## route: - enabled: false + enabled: false - # Add annotations to this Route - annotations: - # kubernetes.io/ingress.class: external-ingress - # ingress.kubernetes.io/rewrite-target: / - # ingress.kubernetes.io/force-ssl-redirect: true + # Add annotations to this Route + annotations: + # kubernetes.io/ingress.class: external-ingress + # ingress.kubernetes.io/rewrite-target: / + # ingress.kubernetes.io/force-ssl-redirect: true - # Additional labels for this Route - additionalLabels: + # Additional labels for this Route + additionalLabels: - # If no host is added then openshift inserts the default hostname. To Add host explicitly, use host attribute - host: + # If no host is added then openshift inserts the default hostname. To Add host explicitly, use host attribute + host: - path: - # Port of the service that serves pods - port: - targetPort: http + path: + # Port of the service that serves pods + port: + targetPort: http - to: - weight: 100 + to: + weight: 100 - wildcardPolicy: None + wildcardPolicy: None - tls: - # TLS Termination strategy - termination: edge - insecureEdgeTerminationPolicy: Redirect + tls: + # TLS Termination strategy + termination: edge + insecureEdgeTerminationPolicy: Redirect - alternateBackends: - # kind: Service - # name: alternate-application - # weight: 20 + alternateBackends: + # kind: Service + # name: alternate-application + # weight: 20 ########################################################## # SecretProviderClass ########################################################## secretProviderClass: - enabled: false - name: "" - # name: example - provider: "" - # provider: vault - vaultAddress: "" - # vaultAddress: http://vault:8200 - roleName: "" - # roleName: example-role - objects: - #- objectName: MONGO_HOST - # secretPath: testing/data/mongoDb - # secretKey: MONGO_HOST - secretObjects: - #- data: - # - key: MONGO_HOST - # objectName: host - # secretName: secret-mongo-host - # type: Opaque + enabled: false + name: "" + # name: example + provider: "" + # provider: vault + vaultAddress: "" + # vaultAddress: http://vault:8200 + roleName: "" + # roleName: example-role + objects: + #- objectName: MONGO_HOST + # secretPath: testing/data/mongoDb + # secretKey: MONGO_HOST + secretObjects: + #- data: + # - key: MONGO_HOST + # objectName: host + # secretName: secret-mongo-host + # type: Opaque ########################################################## # Expose Application on Forecastle Dashboard # https://github.com/stakater/Forecastle ########################################################## forecastle: - enabled: false + enabled: false - # Add additional labels on Forecastle Custom Resource - additionalLabels: + # Add additional labels on Forecastle Custom Resource + additionalLabels: - # URL of the icon for the custom app - icon: https://raw.githubusercontent.com/stakater/ForecastleIcons/master/stakater-big.png + # URL of the icon for the custom app + icon: https://raw.githubusercontent.com/stakater/ForecastleIcons/master/stakater-big.png - # Name of the application to be displayed on the Forecastle Dashboard - displayName: "application" + # Name of the application to be displayed on the Forecastle Dashboard + displayName: "application" - # Group for the custom app (default: .Release.Namespace) - group: "" + # Group for the custom app (default: .Release.Namespace) + group: "" - # Add properties to Custom Resource - properties: + # Add properties to Custom Resource + properties: - # Whether app is network restricted or not - networkRestricted: false + # Whether app is network restricted or not + networkRestricted: false ########################################################## # Role Based Access Control (RBAC) ########################################################## rbac: + enabled: true + + # Service Account to use by pods + serviceAccount: enabled: true + name: "cssd-production-back" - # Service Account to use by pods - serviceAccount: - enabled: true - name: "cssd-production-back" + # Additional Labels on service account + additionalLabels: + # key: value - # Additional Labels on service account - additionalLabels: - # key: value + # Annotations on service account + annotations: + # key: value - # Annotations on service account - annotations: - # key: value - - # Create Roles (Namespaced) - roles: - # - name: configmaps - # rules: - # - apiGroups: - # - "" - # resources: - # - configmaps - # verbs: - # - get - # - name: secrets - # rules: - # - apiGroups: - # - "" - # resources: - # - secrets - # verbs: - # - get + # Create Roles (Namespaced) + roles: + # - name: configmaps + # rules: + # - apiGroups: + # - "" + # resources: + # - configmaps + # verbs: + # - get + # - name: secrets + # rules: + # - apiGroups: + # - "" + # resources: + # - secrets + # verbs: + # - get ########################################################## # Additional ConfigMaps ########################################################## configMap: - enabled: true - files: - nginx: - nginx.conf: | - user nginx; - worker_processes auto; + enabled: true + files: + nginx: + nginx.conf: | + user nginx; + worker_processes auto; - error_log /var/log/nginx/error.log warn; - pid /var/run/nginx.pid; + error_log /var/log/nginx/error.log warn; + pid /var/run/nginx.pid; - events { - worker_connections 1024; + events { + worker_connections 1024; + } + + http { + include /etc/nginx/mime.types; + default_type application/octet-stream; + server_tokens off; + + log_format main '$remote_addr - $remote_user [$time_local] "$request" ' + '$status $body_bytes_sent "$http_referer" ' + '"$http_user_agent" "$http_x_forwarded_for" "$http_x_real_ip" "$http_x_client_ip"'; + + access_log /var/log/nginx/access.log main; + + sendfile on; + keepalive_timeout 65; + + server { + listen 80; + + access_log /var/log/nginx/access.log main; + error_log /var/log/nginx/error.log; + + charset utf-8; + client_max_body_size 500m; + + error_page 404 /index.php; + + index index.html index.htm index.php; + location / { + try_files $uri $uri/ /index.php?$query_string; + proxy_set_header X-Real-IP $http_x_real_ip; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; } - http { - include /etc/nginx/mime.types; - default_type application/octet-stream; - server_tokens off; - - log_format main '$remote_addr - $remote_user [$time_local] "$request" ' - '$status $body_bytes_sent "$http_referer" ' - '"$http_user_agent" "$http_x_forwarded_for" "$http_x_real_ip" "$http_x_client_ip"'; - - access_log /var/log/nginx/access.log main; - - sendfile on; - keepalive_timeout 65; - - server { - listen 80; - - access_log /var/log/nginx/access.log main; - error_log /var/log/nginx/error.log; - - charset utf-8; - client_max_body_size 500m; - - error_page 404 /index.php; - - index index.html index.htm index.php; - location / { - try_files $uri $uri/ /index.php?$query_string; - proxy_set_header X-Real-IP $http_x_real_ip; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - } - - location ~* ^/.+\.(jpg|jpeg|png|gif|ico|css|js|otf|ttf|eot|woff|svg)$ { - root /var/www/html/public; - expires 365d; - } - - location ~ \.php { - fastcgi_pass localhost:9000; - fastcgi_split_path_info ^(.+\.php)(.*)$; - include /etc/nginx/fastcgi_params; - fastcgi_param SCRIPT_FILENAME /var/www/html/public/index.php; - fastcgi_param X-Real-IP $http_x_real_ip; - fastcgi_param X-Forwarded-For $http_x_forwarded_for; - } - } + location ~* ^/.+\.(jpg|jpeg|png|gif|ico|css|js|otf|ttf|eot|woff|svg)$ { + root /var/www/html/public; + expires 365d; } + location ~ \.php { + fastcgi_pass localhost:9000; + fastcgi_split_path_info ^(.+\.php)(.*)$; + include /etc/nginx/fastcgi_params; + fastcgi_param SCRIPT_FILENAME /var/www/html/public/index.php; + fastcgi_param X-Real-IP $http_x_real_ip; + fastcgi_param X-Forwarded-For $http_x_forwarded_for; + } + } + } + ########################################################## # SealedSecrets ########################################################## sealedSecret: - enabled: false - additionalLabels: - #key: value - annotations: - #key: value - files: + enabled: false + additionalLabels: + #key: value + annotations: + #key: value + files: # #nameSuffix of sealedSecret # example: # encryptedData: @@ -579,12 +579,12 @@ sealedSecret: # Additional Secrets ########################################################## secret: - enabled: false - additionalLabels: - # key: value - annotations: - # key: value - files: + enabled: false + additionalLabels: + # key: value + annotations: + # key: value + files: # nameSuffix of Secret # credentials: # data: @@ -599,261 +599,261 @@ secret: # Service Monitor to collect Prometheus metrices ########################################################## serviceMonitor: - enabled: false + enabled: false - # Additional labels - additionalLabels: - # key: value + # Additional labels + additionalLabels: + # key: value - # Additional annotations - annotations: - # key: value + # Additional annotations + annotations: + # key: value - # List of the endpoints of service from which prometheus will scrape data - endpoints: - - interval: 5s - path: /actuator/prometheus - port: http + # List of the endpoints of service from which prometheus will scrape data + endpoints: + - interval: 5s + path: /actuator/prometheus + port: http ########################################################## # HPA - Horizontal Pod Autoscaling ########################################################## autoscaling: - # enabled is a boolean flag for enabling or disabling autoscaling - enabled: false - # additionalLabels defines additional labels - additionalLabels: - # key: value - # annotations defines annotations in key value pair - annotations: - # key: value - # minReplicas sets the minimum number of replicas - minReplicas: 1 - # maxReplicas sets the maximum number of replicas - maxReplicas: 10 - # metrics is the list of metrics used for hpa - metrics: - - type: Resource - resource: - name: cpu - target: - type: Utilization - averageUtilization: 60 - - type: Resource - resource: - name: memory - target: - type: Utilization - averageUtilization: 60 + # enabled is a boolean flag for enabling or disabling autoscaling + enabled: false + # additionalLabels defines additional labels + additionalLabels: + # key: value + # annotations defines annotations in key value pair + annotations: + # key: value + # minReplicas sets the minimum number of replicas + minReplicas: 1 + # maxReplicas sets the maximum number of replicas + maxReplicas: 10 + # metrics is the list of metrics used for hpa + metrics: + - type: Resource + resource: + name: cpu + target: + type: Utilization + averageUtilization: 60 + - type: Resource + resource: + name: memory + target: + type: Utilization + averageUtilization: 60 ########################################################## # EndpointMonitor for IMC # https://github.com/stakater/IngressMonitorController ########################################################## endpointMonitor: - enabled: false + enabled: false - # Additional labels - additionalLabels: - # key: value + # Additional labels + additionalLabels: + # key: value - # Additional annotations - annotations: - # key: value + # Additional annotations + annotations: + # key: value ########################################################## # Certficate CRD to generate the certificate ########################################################## certificate: + enabled: false + + # Additional labels + additionalLabels: + # key: value + + # Additional annotations + annotations: + # key: value + + secretName: tls-cert + duration: 8760h0m0s # 1 year + renewBefore: 720h0m0s # 30d + subject: + # organizations: + # - stakater + # countries: + # - SE + # organizationalUnits: + # - '{{ template "application.namespace" . }}' + # localities: + # - Stockholm + # provinces: + # - Stockholm + commonName: admin-app + keyAlgorithm: rsa + keyEncoding: pkcs1 + keySize: 2048 + isCA: false + usages: + # - digital signature + # - client auth + dnsNames: + # - admin-app + ipAddresses: + # - 192.168.0.5 + uriSANs: + # - spiffe://cluster.local/ns/sandbox/sa/example + emailSANs: + # - emailSubjectAltNames + privateKey: enabled: false - - # Additional labels - additionalLabels: - # key: value - - # Additional annotations - annotations: - # key: value - - secretName: tls-cert - duration: 8760h0m0s # 1 year - renewBefore: 720h0m0s # 30d - subject: - # organizations: - # - stakater - # countries: - # - SE - # organizationalUnits: - # - '{{ template "application.namespace" . }}' - # localities: - # - Stockholm - # provinces: - # - Stockholm - commonName: admin-app - keyAlgorithm: rsa - keyEncoding: pkcs1 - keySize: 2048 - isCA: false - usages: - # - digital signature - # - client auth - dnsNames: - # - admin-app - ipAddresses: - # - 192.168.0.5 - uriSANs: - # - spiffe://cluster.local/ns/sandbox/sa/example - emailSANs: - # - emailSubjectAltNames - privateKey: - enabled: false - rotationPolicy: Always - issuerRef: - name: ca-issuer - # We can reference ClusterIssuers by changing the kind here. - kind: ClusterIssuer - group: #cert-manager.io - keystores: - enabled: false - pkcs12: - create: true - key: test_key - name: test-creds - jks: - create: false - key: test_key - name: test-creds + rotationPolicy: Always + issuerRef: + name: ca-issuer + # We can reference ClusterIssuers by changing the kind here. + kind: ClusterIssuer + group: #cert-manager.io + keystores: + enabled: false + pkcs12: + create: true + key: test_key + name: test-creds + jks: + create: false + key: test_key + name: test-creds ########################################################## # AlertmanagerConfig object for defining application # specific alertmanager configurations ########################################################## alertmanagerConfig: - enabled: false + enabled: false - # AlertmanagerConfig selectionLabels to specify label to be picked up by Alertmanager to add it to base config. Read more about it at [https://docs.openshift.com/container-platform/4.7/rest_api/monitoring_apis/alertmanager-monitoring-coreos-com-v1.html] under .spec.alertmanagerConfigSelector - selectionLabels: - alertmanagerConfig: "workload" + # AlertmanagerConfig selectionLabels to specify label to be picked up by Alertmanager to add it to base config. Read more about it at [https://docs.openshift.com/container-platform/4.7/rest_api/monitoring_apis/alertmanager-monitoring-coreos-com-v1.html] under .spec.alertmanagerConfigSelector + selectionLabels: + alertmanagerConfig: "workload" - # AlertmanagerConfig spec, read details here [https://docs.openshift.com/container-platform/4.7/rest_api/monitoring_apis/alertmanagerconfig-monitoring-coreos-com-v1alpha1.html] - spec: - route: - # receiver: "null" - # groupBy: - # - job - # routes: - # - receiver: "null" - # groupBy: - # - alertname - # - severity - # continue: true - # groupWait: 30s - # groupInterval: 5m - # repeatInterval: 12h - receivers: [] - # - name: "null" - inhibitRules: [] - # - sourceMatch: - # severity: 'critical' - # targetMatch: - # severity: 'warning' - # equal: ['cluster', 'service'] + # AlertmanagerConfig spec, read details here [https://docs.openshift.com/container-platform/4.7/rest_api/monitoring_apis/alertmanagerconfig-monitoring-coreos-com-v1alpha1.html] + spec: + route: + # receiver: "null" + # groupBy: + # - job + # routes: + # - receiver: "null" + # groupBy: + # - alertname + # - severity + # continue: true + # groupWait: 30s + # groupInterval: 5m + # repeatInterval: 12h + receivers: [] + # - name: "null" + inhibitRules: [] + # - sourceMatch: + # severity: 'critical' + # targetMatch: + # severity: 'warning' + # equal: ['cluster', 'service'] ########################################################## # PrometheusRule object for defining application # alerting rules ########################################################## prometheusRule: - enabled: false + enabled: false - # PrometheusRule labels - additionalLabels: - # prometheus: stakater-workload-monitoring - # role: alert-rules + # PrometheusRule labels + additionalLabels: + # prometheus: stakater-workload-monitoring + # role: alert-rules - # Groups with alerting rules. Read more here [https://docs.openshift.com/container-platform/4.7/rest_api/monitoring_apis/prometheusrule-monitoring-coreos-com-v1.html] + # Groups with alerting rules. Read more here [https://docs.openshift.com/container-platform/4.7/rest_api/monitoring_apis/prometheusrule-monitoring-coreos-com-v1.html] - groups: [] - # - name: example-app-uptime - # rules: - # - alert: ExampleAppDown - # annotations: - # message: >- - # The Example App is Down (Test Alert) - # expr: up{namespace="test-app"} == 0 - # for: 1m - # labels: - # severity: critical + groups: [] + # - name: example-app-uptime + # rules: + # - alert: ExampleAppDown + # annotations: + # message: >- + # The Example App is Down (Test Alert) + # expr: up{namespace="test-app"} == 0 + # for: 1m + # labels: + # severity: critical ########################################################## # External Secrets ########################################################## externalSecret: - enabled: false + enabled: false - # Default SecretStore for all externalsecrets defines which SecretStore to use when fetching the secret data - secretStore: - name: tenant-vault-secret-store - #kind: ClusterSecretStore # Defaults to SecretStore if not specified + # Default SecretStore for all externalsecrets defines which SecretStore to use when fetching the secret data + secretStore: + name: tenant-vault-secret-store + #kind: ClusterSecretStore # Defaults to SecretStore if not specified - # RefreshInterval is the amount of time before the values reading again from the SecretStore provider - refreshInterval: "1m" - files: - # mongodb: - # # Data defines the connection between the Kubernetes Secret keys and the Provider data - # data: - # mongo-password: - # remoteRef: - # key: monodb - # property: passowrd - # secretStore: - # name: secret-store-name-2 # specify if value is other than default secretstore - # labels: - # stakater.com/app: mongodb - # # - # postgres: - ## Used to fetch all properties from the Provider key - # dataFrom: - # key: postgres + # RefreshInterval is the amount of time before the values reading again from the SecretStore provider + refreshInterval: "1m" + files: + # mongodb: + # # Data defines the connection between the Kubernetes Secret keys and the Provider data + # data: + # mongo-password: + # remoteRef: + # key: monodb + # property: passowrd + # secretStore: + # name: secret-store-name-2 # specify if value is other than default secretstore + # labels: + # stakater.com/app: mongodb + # # + # postgres: + ## Used to fetch all properties from the Provider key + # dataFrom: + # key: postgres ########################################################## # Network Policy ########################################################## networkPolicy: - enabled: false - additionalLabels: - # key: value - annotations: - # key: value - ingress: - # - from: - # - ipBlock: - # cidr: 172.17.0.0/16 - # except: - # - 172.17.1.0/24 - # - namespaceSelector: - # matchLabels: - # project: myproject - # - podSelector: - # matchLabels: - # role: frontend - # ports: - # - protocol: TCP - # port: 6379 - egress: - # - to: - # - ipBlock: - # cidr: 10.0.0.0/24 - # ports: - # - protocol: TCP - # port: 5978 + enabled: false + additionalLabels: + # key: value + annotations: + # key: value + ingress: + # - from: + # - ipBlock: + # cidr: 172.17.0.0/16 + # except: + # - 172.17.1.0/24 + # - namespaceSelector: + # matchLabels: + # project: myproject + # - podSelector: + # matchLabels: + # role: frontend + # ports: + # - protocol: TCP + # port: 6379 + egress: + # - to: + # - ipBlock: + # cidr: 10.0.0.0/24 + # ports: + # - protocol: TCP + # port: 5978 ########################################################## # Pod disruption budget - PDB ########################################################## pdb: - enabled: false - minAvailable: 1 + enabled: false + minAvailable: 1 # maxUnavailable: 1 ########################################################## @@ -861,29 +861,29 @@ pdb: # Grafana Dashboard ########################################################## grafanaDashboard: - enabled: false + enabled: false - # GrafanaDashboard additonal labels - additionalLabels: - # grafanaDashboard: grafana-operator + # GrafanaDashboard additonal labels + additionalLabels: + # grafanaDashboard: grafana-operator - # GrafanaDashboard annotations - annotations: - # key: value + # GrafanaDashboard annotations + annotations: + # key: value - # GrafanaDashboard contents - # this includes pairs of dashboard name and associated json content - # Accoroding to GrafanaDashboard behavior, if both url and json are specified then the GrafanaDashboard content will be updated with fetched content from url - contents: - # dashboard-name-1: - # json: |- - # { - # "data" - # } - # url: http://hostname/path/to/file.json - # dashboard-name-2: - # json: |- - # { - # "data" - # } - # url: http://hostname/path/to/file.json + # GrafanaDashboard contents + # this includes pairs of dashboard name and associated json content + # Accoroding to GrafanaDashboard behavior, if both url and json are specified then the GrafanaDashboard content will be updated with fetched content from url + contents: + # dashboard-name-1: + # json: |- + # { + # "data" + # } + # url: http://hostname/path/to/file.json + # dashboard-name-2: + # json: |- + # { + # "data" + # } + # url: http://hostname/path/to/file.json