mirror of
https://github.com/YuzuZensai/netbird-kubernetes-operator.git
synced 2026-09-13 10:49:15 +00:00
This changes the behavior of the Netbird resource so that they can be shared between routes rather than having one unique created per route. This is important as we may want to have different route types pointing to the same service. Signed-off-by: Philip Laine <philip.laine@gmail.com>
210 lines
6.2 KiB
YAML
210 lines
6.2 KiB
YAML
clusterSecretsPermissions:
|
|
# Required for NBSetupKey validation
|
|
# Required for Ingress functionality to create and validate secrets for routing peers
|
|
allowAllSecrets: true
|
|
|
|
webhook:
|
|
service:
|
|
type: ClusterIP
|
|
port: 443
|
|
targetPort: 9443
|
|
|
|
# TLS configuration for webhook
|
|
# Optional, unused if webhook.enableCertManager is set to true
|
|
tls: {}
|
|
|
|
# Use cert-manager to provision webhook certificates (recommended)
|
|
enableCertManager: true
|
|
|
|
# Narrow down validation and mutation webhooks namespaces
|
|
namespaceSelectors: []
|
|
# - key: foo
|
|
# operator: In
|
|
# values:
|
|
# - bar
|
|
|
|
# Narrow down validation and mutation webhooks objects
|
|
objectSelector:
|
|
matchExpressions: []
|
|
# - key: app.kubernetes.io/name
|
|
# operator: NotIn
|
|
# values:
|
|
# - foo
|
|
|
|
# Failure Policy for webhook
|
|
failurePolicy: Fail
|
|
|
|
operator:
|
|
# This will set the replicaset count more information can be found here: https://kubernetes.io/docs/concepts/workloads/controllers/replicaset/
|
|
replicaCount: 1
|
|
|
|
# This sets the container image more information can be found here: https://kubernetes.io/docs/concepts/containers/images/
|
|
image:
|
|
# Set operator image registry
|
|
registry: docker.io
|
|
# Set operator image repository
|
|
repository: netbirdio/kubernetes-operator
|
|
# This sets the pull policy for images.
|
|
pullPolicy: IfNotPresent
|
|
# Overrides the image tag whose default is the chart appVersion.
|
|
tag: ""
|
|
|
|
metrics:
|
|
enabled: true
|
|
type: ClusterIP
|
|
port: 8080
|
|
|
|
# This is for the secretes for pulling an image from a private repository more information can be found here: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
|
|
imagePullSecrets: []
|
|
# This is to override the chart name.
|
|
nameOverride: ""
|
|
fullnameOverride: ""
|
|
|
|
#This section builds out the service account more information can be found here: https://kubernetes.io/docs/concepts/security/service-accounts/
|
|
serviceAccount:
|
|
# Specifies whether a service account should be created
|
|
create: true
|
|
# Automatically mount a ServiceAccount's API credentials?
|
|
automount: true
|
|
# Annotations to add to the service account
|
|
annotations: {}
|
|
# The name of the service account to use.
|
|
# If not set and create is true, a name is generated using the fullname template
|
|
name: ""
|
|
|
|
# This is for setting Kubernetes Annotations to a Pod.
|
|
# For more information checkout: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/
|
|
podAnnotations: {}
|
|
# This is for setting Kubernetes Labels to a Pod.
|
|
# For more information checkout: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
|
|
podLabels: {}
|
|
|
|
securityContext:
|
|
allowPrivilegeEscalation: false
|
|
capabilities:
|
|
drop:
|
|
- ALL
|
|
|
|
podSecurityContext:
|
|
runAsNonRoot: true
|
|
seccompProfile:
|
|
type: RuntimeDefault
|
|
|
|
|
|
# This is for setting up a service more information can be found here: https://kubernetes.io/docs/concepts/services-networking/service/
|
|
service:
|
|
# This sets the service type more information can be found here: https://kubernetes.io/docs/concepts/services-networking/service/#publishing-services-service-types
|
|
type: ClusterIP
|
|
# This sets the ports more information can be found here: https://kubernetes.io/docs/concepts/services-networking/service/#field-spec-ports
|
|
port: 9443
|
|
|
|
resources: {}
|
|
# limits:
|
|
# cpu: 100m
|
|
# memory: 128Mi
|
|
# requests:
|
|
# cpu: 100m
|
|
# memory: 128Mi
|
|
|
|
# This is to setup the liveness and readiness probes more information can be found here: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
|
|
livenessProbe:
|
|
port: 8081
|
|
initialDelaySeconds: 15
|
|
periodSeconds: 20
|
|
successThreshold: 1
|
|
timeoutSeconds: 1
|
|
|
|
readinessProbe:
|
|
port: 8081
|
|
initialDelaySeconds: 5
|
|
periodSeconds: 10
|
|
successThreshold: 1
|
|
timeoutSeconds: 1
|
|
|
|
# Additional volumes on the output Deployment definition.
|
|
volumes: []
|
|
|
|
# Additional volumeMounts on the output Deployment definition.
|
|
volumeMounts: []
|
|
|
|
nodeSelector: {}
|
|
|
|
tolerations: []
|
|
|
|
affinity: {}
|
|
|
|
ingress:
|
|
# Enable ingress capabilities to expose services
|
|
enabled: false
|
|
# Create router per namespace, useful for strict networking requirements
|
|
namespacedNetworks: false
|
|
# Allow creating policies through Service annotations
|
|
allowAutomaticPolicyCreation: false
|
|
kubernetesAPI: # DEPRECATED: Use netbirdio/netbird-operator-configs Chart instead
|
|
enabled: false
|
|
groups: []
|
|
# - group1
|
|
# - group2
|
|
policies: []
|
|
# - default
|
|
router: # DEPRECATED: Use netbirdio/netbird-operator-configs Chart instead
|
|
# Deploy routing peer(s)
|
|
enabled: false
|
|
# replicas: 3
|
|
# resources:
|
|
# requests:
|
|
# cpu: 100m
|
|
# memory: 100Mi
|
|
# limits:
|
|
# cpu: 100m
|
|
# memory: 100Mi
|
|
# labels: {}
|
|
# annotations: {}
|
|
# nodeSelector: {}
|
|
# tolerations: []
|
|
# Only needed if namespacedNetworks is set to true
|
|
namespaces: {}
|
|
# default:
|
|
# replicas: 3
|
|
# resources:
|
|
# requests:
|
|
# cpu: 100m
|
|
# memory: 100Mi
|
|
# limits:
|
|
# cpu: 100m
|
|
# memory: 100Mi
|
|
# labels: {}
|
|
# annotations: {}
|
|
# nodeSelector: {}
|
|
# tolerations: []
|
|
# NetBird Policies for use with exposed services
|
|
policies: {} # DEPRECATED: Use netbirdio/netbird-operator-configs Chart instead
|
|
# default:
|
|
# name: Kubernetes Default Policy
|
|
# sourceGroups:
|
|
# - All
|
|
|
|
gatewayAPI:
|
|
enabled: false
|
|
|
|
cluster:
|
|
# Cluster DNS name (used for webhooks certificates and for network resource DNS names)
|
|
dns: svc.cluster.local
|
|
# Cluster name (used for generating network and network resource names in NetBird)
|
|
name: kubernetes
|
|
|
|
netbirdAPI: {}
|
|
# NetBird Service Account Token
|
|
# key: "nbp_m0LM9ZZvDUzFO0pY50iChDOTxJgKFM3DIqmZ"
|
|
#keyFromSecret:
|
|
# name: "Secret name"
|
|
# key: "NB_API_KEY"
|
|
|
|
#routingClientImage: "netbirdio/netbird:latest"
|
|
|
|
general:
|
|
# General labels, applied to all created K8s resources
|
|
labels: {}
|
|
# acme_com_managed_by: platform-engineering
|
|
# acme_com_owned_by: release-engineering
|