Browse Source

fix ingress

pull/114/head
selmankoc 4 years ago
parent
commit
1fac4559e7
  1. 5
      etc/azure/cert-manager.md
  2. 8
      etc/azure/k8s/eshoponabp/charts/web/values.yaml
  3. 2
      etc/azure/scripts/cluster-issuer.yaml
  4. 8
      etc/azure/scripts/corednsms.yaml
  5. 3
      etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml
  6. 5
      etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml
  7. 3
      etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml
  8. 3
      etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml
  9. 5
      etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml
  10. 3
      etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml
  11. 3
      etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml
  12. 3
      etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml
  13. 3
      etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml
  14. 5
      etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml
  15. 13
      etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml
  16. 6
      etc/k8s/eshoponabp/charts/web/values.yaml
  17. 354
      etc/k8s/eshoponabp/values.azure.yaml

5
etc/azure/cert-manager.md

@ -3,7 +3,7 @@
* Create the namespace for ingress-basic
```bash
kubectl create namespace cert-ingress-basic
kubectl create namespace ingress-basic
```
* Add the Jetstack Helm repository.
@ -39,7 +39,7 @@
kubectl get pods --namespace ingress-basic -o wide
```
* Create `ClusterIssuer` with name of `tls-cluster-issuer-prod.yml` for the production certificate through `Let's Encrypt ACME` (Automated Certificate Management Environment) with following content by importing YAML file on Ranhcer and save it under `k8s` folder. *Note that certificate will only be created after annotating and updating the `Ingress` resource.*
* Create `ClusterIssuer` with name of `cluster-issuer.yml` for the production certificate through `Let's Encrypt ACME` (Automated Certificate Management Environment) with following content and save it under `azure/k8s` folder. *Note that certificate will only be created after annotating and updating the `Ingress` resource.*
```yaml
apiVersion: cert-manager.io/v1
@ -69,4 +69,3 @@ kubectl apply -f etc/azure/cluster-issuer.yaml
kubectl get clusterissuers letsencrypt -n ingress-basic -o wide
```
* Issue production Let’s Encrypt Certificate by annotating and adding ingress resource

8
etc/azure/k8s/eshoponabp/charts/web/values.yaml

@ -1,18 +1,18 @@
config:
selfUrl: https://www.admin.eshoponabp.com
selfUrl: https://www.eshoponabp.com
gatewayUrl: "https://gateway.eshoponabp.com/"
authServer:
authority: https://auth.eshoponabp.com
requireHttpsMetadata: "false"
ingress:
host: admin.eshoponabp.com
host: eshop-st-web
tlsSecret: eshop-wildcard-tls
image:
repository: "volocr.azurecr.io/eshoponabp/app-web"
repository: eshoponabp/app-web
tag: latest
pullPolicy: IfNotPresent
# Extra environment variables or configurations
env: {}

2
etc/azure/scripts/cluster-issuer.yaml

@ -5,7 +5,7 @@ metadata:
spec:
acme:
server: https://acme-v02.api.letsencrypt.org/directory
email: info@volosoft.com
email: selman.koc@volosoft.com
privateKeySecretRef:
name: letsencrypt
solvers:

8
etc/azure/scripts/corednsms.yaml

@ -1,8 +0,0 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: coredns-custom
namespace: kube-system
data:
Corefile.override: |
rewrite name substring account.eshoponabp.io es-az-account

3
etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml

@ -7,12 +7,13 @@ metadata:
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: 32k
nginx.ingress.kubernetes.io/proxy-buffers-number: "8"
cert-manager.io/cluster-issuer: letsencrypt
spec:
ingressClassName: nginx
tls:
- hosts:
- {{ .Values.ingress.host }}
secretName: {{ .Values.ingress.tlsSecret }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
rules:
- host: "{{ .Values.ingress.host }}"
http:

5
etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml

@ -7,14 +7,15 @@ metadata:
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: 32k
nginx.ingress.kubernetes.io/proxy-buffers-number: "8"
cert-manager.io/cluster-issuer: letsencrypt
nginx.ingress.kubernetes.io/configuration-snippet: |
more_set_input_headers "from-ingress: true";
spec:
ingressClassName: nginx
tls:
- hosts:
- "eshop-st-authserver"
secretName: "eshop-wildcard-tls"
- {{ .Values.ingress.host }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
rules:
- host: "{{ .Values.ingress.host }}"
http:

3
etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml

@ -7,12 +7,13 @@ metadata:
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: 32k
nginx.ingress.kubernetes.io/proxy-buffers-number: "8"
cert-manager.io/cluster-issuer: letsencrypt
spec:
ingressClassName: nginx
tls:
- hosts:
- {{ .Values.ingress.host }}
secretName: {{ .Values.ingress.tlsSecret }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
rules:
- host: "{{ .Values.ingress.host }}"
http:

3
etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml

@ -7,12 +7,13 @@ metadata:
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: 32k
nginx.ingress.kubernetes.io/proxy-buffers-number: "8"
cert-manager.io/cluster-issuer: letsencrypt
spec:
ingressClassName: nginx
tls:
- hosts:
- {{ .Values.ingress.host }}
secretName: {{ .Values.ingress.tlsSecret }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
rules:
- host: "{{ .Values.ingress.host }}"
http:

5
etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml

@ -10,15 +10,16 @@ metadata:
{{- if eq .Release.Name "es-az" }}
nginx.ingress.kubernetes.io/from-to-www-redirect: "true"
{{- end }}
cert-manager.io/cluster-issuer: letsencrypt
spec:
ingressClassName: nginx
tls:
- hosts:
- {{ .Values.ingress.host }}
{{- if eq .Release.Name "es-az" }}
- {{ print "www." .Values.global.ingress.host }}
- {{ print "www." .Values.ingress.host }}
{{- end }}
secretName: {{ .Values.ingress.tlsSecret }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
rules:
{{- if eq .Release.Name "es-az" }}
- host: "{{ print "www." .Values.ingress.host }}"

3
etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml

@ -10,6 +10,7 @@ metadata:
{{- if eq .Release.Name "es-az" }}
nginx.ingress.kubernetes.io/from-to-www-redirect: "true"
{{- end }}
cert-manager.io/cluster-issuer: letsencrypt
spec:
ingressClassName: nginx
tls:
@ -18,7 +19,7 @@ spec:
{{- if eq .Release.Name "es-az" }}
- {{ print "www." .Values.ingress.host }}
{{- end }}
secretName: {{ .Values.ingress.tlsSecret }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
rules:
{{- if eq .Release.Name "es-az" }}
- host: "{{ print "www." .Values.ingress.host }}"

3
etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml

@ -7,12 +7,13 @@ metadata:
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: 32k
nginx.ingress.kubernetes.io/proxy-buffers-number: "8"
cert-manager.io/cluster-issuer: letsencrypt
spec:
ingressClassName: nginx
tls:
- hosts:
- {{ .Values.ingress.host }}
secretName: {{ .Values.ingress.tlsSecret }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
rules:
- host: "{{ .Values.ingress.host }}"
http:

3
etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml

@ -7,12 +7,13 @@ metadata:
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: 32k
nginx.ingress.kubernetes.io/proxy-buffers-number: "8"
cert-manager.io/cluster-issuer: letsencrypt
spec:
ingressClassName: nginx
tls:
- hosts:
- {{ .Values.ingress.host }}
secretName: {{ .Values.ingress.tlsSecret }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
rules:
- host: "{{ .Values.ingress.host }}"
http:

3
etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml

@ -7,12 +7,13 @@ metadata:
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: 32k
nginx.ingress.kubernetes.io/proxy-buffers-number: "8"
cert-manager.io/cluster-issuer: letsencrypt
spec:
ingressClassName: nginx
tls:
- hosts:
- {{ .Values.ingress.host }}
secretName: {{ .Values.ingress.tlsSecret }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
rules:
- host: "{{ .Values.ingress.host }}"
http:

5
etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml

@ -10,6 +10,7 @@ metadata:
{{- if eq .Release.Name "es-az" }}
nginx.ingress.kubernetes.io/from-to-www-redirect: "true"
{{- end }}
cert-manager.io/cluster-issuer: letsencrypt
spec:
ingressClassName: nginx
tls:
@ -18,12 +19,12 @@ spec:
{{- if eq .Release.Name "es-az" }}
- {{ print "www." .Values.ingress.host }}
{{- end }}
secretName: {{ .Values.ingress.tlsSecret }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
rules:
{{- if eq .Release.Name "es-az" }}
- host: "{{ print "www." .Values.ingress.host }}"
{{- else }}
- host: "{{ .Values.ingress.host }}"
- host: "{{ .Values.ingress.host }}"
{{- end }}
http:
paths:

13
etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml

@ -7,24 +7,15 @@ metadata:
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: 32k
nginx.ingress.kubernetes.io/proxy-buffers-number: "8"
{{- if eq .Release.Name "es-az" }}
nginx.ingress.kubernetes.io/from-to-www-redirect: "true"
{{- end }}
cert-manager.io/cluster-issuer: letsencrypt
spec:
ingressClassName: nginx
tls:
- hosts:
- {{ .Values.ingress.host }}
{{- if eq .Release.Name "eh-es" }}
- {{ print "www." .Values.ingress.host }}
{{- end }}
secretName: {{ .Values.ingress.tlsSecret }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
rules:
{{- if eq .Release.Name "eh-es" }}
- host: "{{ print "www." .Values.ingress.host }}"
{{- else }}
- host: "{{ .Values.ingress.host }}"
{{- end }}
http:
paths:
- path: /

6
etc/k8s/eshoponabp/charts/web/values.yaml

@ -1,8 +1,8 @@
config:
selfUrl: https://eshop-st-web
gatewayUrl: "https://eshop-st-gateway-web/"
selfUrl: https://www.admin.eshoponabp.com
gatewayUrl: "https://www.gateway.eshoponabp.com/"
authServer:
authority: http://eshop-st-authserver
authority: https://auth.eshoponabp.com
requireHttpsMetadata: "false"
ingress:

354
etc/k8s/eshoponabp/values.azure.yaml

@ -0,0 +1,354 @@
# auth-server sub-chart override
authserver:
config:
selfUrl: https://auth.eshoponabp.com
corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com,https://identity.eshoponabp.com,https://administration.eshoponabp.com,https://basket.eshoponabp.com,https://catalog.eshoponabp.com,https://order.eshoponabp.com,https://payment.eshoponabp.com
allowedRedirectUrls: https://admin.eshoponabp.com
connectionStrings:
administrationService: "Host=es-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
identityService: "Host=es-az-postgresdb;Port=5432;Database=EShopOnAbp_Identity;User ID=postgres;password=myPassw0rd;Pooling=false"
dotnetEnv: Production
redisHost: es-az-redis
rabbitmqHost: es-az-rabbitmq
elasticsearchHost: es-az-elasticsearch
ingress:
host: auth.eshoponabp.com
tlsSecret: eshop-wildcard-tls
image:
repository: "volocr.azurecr.io/eshoponabp/app-authserver"
tag: latest
# web sub-chart override
web:
config:
selfUrl: https://admin.eshoponabp.com
gatewayUrl: https://www.gateway.eshoponabp.com
ingress:
host: admin.eshoponabp.com
image:
repository: "volocr.azurecr.io/eshoponabp/app-web"
tag: latest
# public-web sub-chart override
public-web:
config:
selfUrl: https://www.eshoponabp.com
gatewayUrl: https://www.gateway-public.eshoponabp.com
authServer:
authority: https://auth.eshoponabp.com
requireHttpsMetadata: "false"
dotnetEnv: Production
redisHost: es-az-redis
rabbitmqHost: es-az-rabbitmq
elasticsearchHost: es-az-elasticsearch
ingress:
host: eshoponabp.com
image:
repository: "volocr.azurecr.io/eshoponabp/app-publicweb"
tag: latest
# identity-service sub-chart override
identity:
config:
selfUrl: https://identity.eshoponabp.com
corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com
connectionStrings:
identityService: "Host=es-az-postgresdb;Port=5432;Database=EShopOnAbp_Identity;User ID=postgres;password=myPassw0rd;Pooling=false"
administrationService: "Host=es-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: https://auth.eshoponabp.com
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
dotnetEnv: Production
redisHost: es-az-redis
rabbitmqHost: es-az-rabbitmq
elasticsearchHost: es-az-elasticsearch
identityServerClients: # Seeded Clients
webRootUrl: https://admin.eshoponabp.com/
publicWebRootUrl: https://www.eshoponabp.com/
webGatewayRootUrl: https://www.gateway.eshoponabp.com/
publicWebGatewayRootUrl: https://www.gateway-public.eshoponabp.com/
identityServiceRootUrl: https://identity.eshoponabp.com/
administrationServiceRootUrl: https://administration.eshoponabp.com/
accountServiceRootUrl: https://auth.eshoponabp.com
basketServiceRootUrl: https://basket.eshoponabp.com/
catalogServiceRootUrl: https://catalog.eshoponabp.com
orderingServiceRootUrl: https://order.eshoponabp.com
paymentServiceRootUrl: https://payment.eshoponabp.com
ingress:
host: identity.eshoponabp.com
image:
repository: "volocr.azurecr.io/eshoponabp/service-identity"
tag: latest
# administration sub-chart override
administration:
config:
selfUrl: https://administration.eshoponabp.com
corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com,https://eshop-az-gateway-internal
connectionStrings:
administrationService: "Host=es-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: https://auth.eshoponabp.com
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
remoteServices:
abpIdentityBaseUrl: https://identity.eshoponabp.com
useCurrentToken: "false"
dotnetEnv: Production
redisHost: es-az-redis
rabbitmqHost: es-az-rabbitmq
elasticsearchHost: es-az-elasticsearch
synchedCommunication: # Used for server-to-server (client-credentials) communication with identityService for user permissions
authority: https://auth.eshoponabp.com
ingress:
host: administration.eshoponabp.com
image:
repository: "volocr.azurecr.io/eshoponabp/service-administration"
tag: latest
# gateway-web sub-chart override
gateway-web:
config:
selfUrl: https://www.gateway.eshoponabp.com
corsOrigins: https://admin.eshoponabp.com
globalConfigurationBaseUrl: http://eshop-az-gateway-public
authServer:
authority: https://auth.eshoponabp.com
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
dotnetEnv: Production
redisHost: es-az-redis
rabbitmqHost: es-az-rabbitmq
elasticsearchHost: es-az-elasticsearch
ingress:
host: gateway.eshoponabp.com
image:
repository: "volocr.azurecr.io/eshoponabp/gateway-web"
tag: latest
reRoutes:
accountService:
url: https://auth.eshoponabp.com
identityService:
url: http://eshop-az-identity
administrationService:
url: http://eshop-az-administration
# gateway-web-public sub-chart override
gateway-web-public:
config:
selfUrl: https://www.gateway-public.eshoponabp.com
authServer:
authority: https://auth.eshoponabp.com
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
dotnetEnv: Production
redisHost: es-az-redis
rabbitmqHost: es-az-rabbitmq
elasticsearchHost: es-az-elasticsearch
ingress:
host: gateway-public.eshoponabp.com
image:
repository: "volocr.azurecr.io/eshoponabp/gateway-web-public"
tag: latest
reRoutes:
accountService:
url: https://auth.eshoponabp.com
identityService:
url: http://eshop-az-identity
administrationService:
url: http://eshop-az-administration
catalogService:
url: http://eshop-az-catalog
basketService:
url: http://eshop-az-basket
orderingService:
url: http://eshop-az-ordering
paymentService:
url: http://eshop-az-payment
# basket-service sub-chart override
basket:
config:
selfUrl: https://basket.eshoponabp.com
corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com,https://publicweb.eshoponabp.com
connectionStrings:
administrationService: "Host=es-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: https://auth.eshoponabp.com
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
dotnetEnv: Production
redisHost: es-az-redis
rabbitmqHost: es-az-rabbitmq
elasticsearchHost: es-az-elasticsearch
remoteServices:
catalogBaseUrl: http://eshop-az-catalog
catalogGrpcUrl: http://eshop-az-catalog
ingress:
host: basket.eshoponabp.com
image:
repository: "volocr.azurecr.io/eshoponabp/service-basket"
tag: latest
# catalog-service sub-chart override
catalog:
config:
selfUrl: https://catalog.eshoponabp.com
corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com,https://publicweb.eshoponabp.com,https://admin.eshoponabp.com
connectionStrings:
catalogService: "mongodb://es-az-mongodb/EShopOnAbp_Catalog"
administrationService: "Host=es-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: https://auth.eshoponabp.com
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
dotnetEnv: Production
redisHost: es-az-redis
rabbitmqHost: es-az-rabbitmq
elasticsearchHost: es-az-elasticsearch
kestrel:
httpUrl: http://eshop-az-catalog:80
httpProtocols: Http1AndHttp2
grpcUrl: http://eshop-az-catalog:81
grpcProtocols: Http2
ingress:
host: catalog.eshoponabp.com
image:
repository: "volocr.azurecr.io/eshoponabp/service-catalog"
tag: latest
# ordering-service sub-chart override
ordering:
config:
selfUrl: https://order.eshoponabp.com
corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com
connectionStrings:
orderingService: "Host=es-az-postgresdb;Port=5432;Database=EShopOnAbp_Ordering;User ID=postgres;password=myPassw0rd;Pooling=false"
administrationService: "Host=es-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: https://auth.eshoponabp.com
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
dotnetEnv: Production
redisHost: es-az-redis
rabbitmqHost: es-az-rabbitmq
elasticsearchHost: es-az-elasticsearch
ingress:
host: order.eshoponabp.com
image:
repository: "volocr.azurecr.io/eshoponabp/service-ordering"
tag: latest
# payment-service sub-chart override
payment:
config:
selfUrl: https://payment.eshoponabp.com
corsOrigins: https://www.gateway.eshoponabp.com,https://www.gateway-public.eshoponabp.com
connectionStrings:
paymentService: "Host=es-az-postgresdb;Port=5432;Database=EShopOnAbp_Payment;User ID=postgres;password=myPassw0rd;Pooling=false"
administrationService: "Host=es-az-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: https://auth.eshoponabp.com
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
dotnetEnv: Production
redisHost: es-az-redis
rabbitmqHost: es-az-rabbitmq
elasticsearchHost: es-az-elasticsearch
ingress:
host: payment.eshoponabp.com
image:
repository: "volocr.azurecr.io/eshoponabp/service-payment"
tag: latest
# Default values for eshoponabp.
# This is a YAML-formatted file.
# Declare variables to be passed into your templates.
replicaCount: 1
image:
repository: nginx
pullPolicy: IfNotPresent
# Overrides the image tag whose default is the chart appVersion.
tag: ""
imagePullSecrets: []
nameOverride: ""
fullnameOverride: ""
serviceAccount:
# Specifies whether a service account should be created
create: true
# Annotations to add to the service account
annotations: {}
# The name of the service account to use.
# If not set and create is true, a name is generated using the fullname template
name: ""
podAnnotations: {}
podSecurityContext: {}
# fsGroup: 2000
securityContext: {}
# capabilities:
# drop:
# - ALL
# readOnlyRootFilesystem: true
# runAsNonRoot: true
# runAsUser: 1000
service:
type: ClusterIP
port: 80
ingress:
enabled: false
className: ""
annotations: {}
# kubernetes.io/ingress.class: nginx
# kubernetes.io/tls-acme: "true"
hosts:
- host: chart-example.local
paths:
- path: /
pathType: ImplementationSpecific
tls: []
# - secretName: chart-example-tls
# hosts:
# - chart-example.local
resources: {}
# We usually recommend not to specify default resources and to leave this as a conscious
# choice for the user. This also increases chances charts run on environments with little
# resources, such as Minikube. If you do want to specify resources, uncomment the following
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
# limits:
# cpu: 100m
# memory: 128Mi
# requests:
# cpu: 100m
# memory: 128Mi
autoscaling:
enabled: false
minReplicas: 1
maxReplicas: 100
targetCPUUtilizationPercentage: 80
# targetMemoryUtilizationPercentage: 80
nodeSelector: {}
tolerations: []
affinity: {}
Loading…
Cancel
Save