Browse Source

Helm Chart Security Enhancements and Feature Additions (#1211)

* Update Squidex Helm chart to version 1.0.4 with appVersion 7.18.0. Enhanced values.yaml with new parameters for deployment strategy, autoscaling, and network policies. Adjusted service port to 8080 and added support for pod disruption budgets. Introduced Horizontal Pod Autoscaler and NetworkPolicy templates for improved resource management and security.

* Enhance Squidex Helm chart README with additional configuration parameters for deployment strategy, autoscaling, pod disruption budgets, affinity, scheduling, ingress, and security context. Updated service port to 8080 and included detailed descriptions for new settings to improve user guidance.

* Update Squidex Helm chart configuration to include optional security contexts for pods and containers. Added commented annotations for ingress settings in values.yaml to enhance user customization options.

* Enhance Squidex Helm chart by adding optional parameters for topology spread constraints and priority class name in values.yaml. Update deployment template to conditionally include these settings, improving deployment flexibility and customization.

* Fix the values.yaml file to allow the README generator to run.

* Update Squidex Helm chart to change default service account name to an empty string in values.yaml and README.md for improved flexibility.

* Update Squidex Helm chart version to 2.0.1 for compatibility with appVersion 7.18.0.

* docs: update README to reflect change from 'skip' to 'param' for priorityClassName, topologySpreadConstraints, annotations, resources, and labels

* Update Squidex Helm chart to increase default replica count from 1 to 3 in both README.md and values.yaml.
pull/1218/head
Sina Darbouy 1 year ago
committed by GitHub
parent
commit
bf60028b42
No known key found for this signature in database GPG Key ID: B5690EEEBB952194
  1. 2
      helm/squidex7/Chart.yaml
  2. 51
      helm/squidex7/README.md
  3. 5
      helm/squidex7/templates/_helpers.tpl
  4. 23
      helm/squidex7/templates/deployment-worker.yaml
  5. 30
      helm/squidex7/templates/deployment.yaml
  6. 14
      helm/squidex7/templates/hpa.yaml
  7. 2
      helm/squidex7/templates/ingress.yaml
  8. 19
      helm/squidex7/templates/networkpolicy.yaml
  9. 20
      helm/squidex7/templates/pdb.yaml
  10. 2
      helm/squidex7/templates/service.yaml
  11. 160
      helm/squidex7/values.yaml

2
helm/squidex7/Chart.yaml

@ -5,7 +5,7 @@ name: squidex7
icon: https://raw.githubusercontent.com/Squidex/squidex/master/media/logo-squared.png icon: https://raw.githubusercontent.com/Squidex/squidex/master/media/logo-squared.png
description: Squidex CMS v7.0 and newer description: Squidex CMS v7.0 and newer
version: 2.0.0 version: 2.0.1
appVersion: "7.18.0" appVersion: "7.18.0"
home: https://squidex.io/ home: https://squidex.io/

51
helm/squidex7/README.md

@ -46,17 +46,34 @@ The command removes all the Kubernetes components associated with the chart and
### Global parameters ### Global parameters
| Name | Description | Value | | Name | Description | Value |
| -------------------------- | ------------------------------ | ----------------- | | -------------------------------------------------- | ------------------------------------------------------------------- | ----------------- |
| `service.type` | Kubernetes Service type | `ClusterIP` | | `nameOverride` | Override the name of the application. | `squidex` |
| `service.port` | Kubernetes Service port | `80` | | `labels` | Labels to add to the deployment | `{}` |
| `deployment.replicaCount` | Number of instances. | `1` | | `service.type` | Kubernetes Service type | `ClusterIP` |
| `image.repository` | Squidex image registry | `squidex/squidex` | | `service.port` | Kubernetes Service port | `8080` |
| `image.pullPolicy` | Squidex image pull policy | `IfNotPresent` | | `deployment.replicaCount` | Number of replicas (ignored if autoscaling enabled) | `3` |
| `runAsNonRoot` | | `false` | | `deployment.worker.replicaCount` | Number of worker instances | `1` |
| `ingress.enabled` | True to deploy an ingress | `true` | | `deployment.revisionHistoryLimit` | Number of revision history | `2` |
| `ingress.ingressClassName` | The ingress class. | `nginx` | | `deployment.serviceAccountName` | Name of the service account to use | `""` |
| `ingress.hostName` | The host name for the ingress. | `squidex.local` | | `deployment.strategy.type` | Deployment strategy type | `RollingUpdate` |
| `deployment.strategy.rollingUpdate.maxSurge` | Maximum number of pods that can be created above the desired amount | `1` |
| `deployment.strategy.rollingUpdate.maxUnavailable` | Maximum number of unavailable pods during update | `0` |
| `deployment.restartPolicy` | Pod restart policy | `Always` |
| `deployment.annotations` | Annotations to add to the deployment | `nil` |
| `deployment.command` | Command to run in the container | `nil` |
| `deployment.args` | Arguments to pass to the container | `nil` |
| `networkPolicy.enabled` | Enable network policies | `true` |
| `image.repository` | Squidex image registry | `squidex/squidex` |
| `image.pullPolicy` | Squidex image pull policy | `IfNotPresent` |
| `resources` | Resource requests and limits | `{}` |
| `topologySpreadConstraints` | Topology spread constraints for pod scheduling | `[]` |
| `priorityClassName` | Priority class name for the pod | `nil` |
| `runAsNonRoot` | Run container as non-root user. | `true` |
| `ingress.enabled` | True to deploy an ingress | `true` |
| `ingress.ingressClassName` | The ingress class. | `nginx` |
| `ingress.annotations` | Ingress annotations | `{}` |
| `ingress.hostName` | The host name for the ingress. | `squidex.local` |
### Squidex parameters ### Squidex parameters
@ -90,7 +107,7 @@ The command removes all the Kubernetes components associated with the chart and
| `env.LOGGING__APPLICATIONINSIGHTS__CONNECTIONSTRING` | The connection string to application insights. | `nil` | | `env.LOGGING__APPLICATIONINSIGHTS__CONNECTIONSTRING` | The connection string to application insights. | `nil` |
| `env.LOGGING__COLORS` | Use colors in the console output. | `false` | | `env.LOGGING__COLORS` | Use colors in the console output. | `false` |
| `env.LOGGING__HUMAN` | Setting the flag to true, enables well formatteds json logs. | `false` | | `env.LOGGING__HUMAN` | Setting the flag to true, enables well formatteds json logs. | `false` |
| `env.LOGGING__LEVEL` | Trace, Debug, Information, Warning, Error, Fatal | `INFORMATION` | | `env.LOGGING__LEVEL` | Trace, Debug, Information, Warning, Error, Fatal | `Warning` |
| `env.LOGGING__LOGREQUESTS` | Set to false to disable logging of http requests. | `true` | | `env.LOGGING__LOGREQUESTS` | Set to false to disable logging of http requests. | `true` |
| `env.LOGGING__OTLP__ENABLED` | True, to enable OpenTelemetry Protocol integration | `false` | | `env.LOGGING__OTLP__ENABLED` | True, to enable OpenTelemetry Protocol integration | `false` |
| `env.LOGGING__OLTP__ENDPOINT` | The endpoint to the agent | `nil` | | `env.LOGGING__OLTP__ENDPOINT` | The endpoint to the agent | `nil` |
@ -101,7 +118,13 @@ The command removes all the Kubernetes components associated with the chart and
| `env.STORE__MONGODB__CONTENTDATABASE` | The name of the database for content items. | `SquidexContent` | | `env.STORE__MONGODB__CONTENTDATABASE` | The name of the database for content items. | `SquidexContent` |
| `env.URLS__BASEURL` | Set the base url of your application, to generate correct urls in background process. | `https://squidex.local/` | | `env.URLS__BASEURL` | Set the base url of your application, to generate correct urls in background process. | `https://squidex.local/` |
| `env.URLS__ENFORCEHTTPS` | Set it to true to redirect the user from http to https permanently | `false` | | `env.URLS__ENFORCEHTTPS` | Set it to true to redirect the user from http to https permanently | `false` |
| `env.ASPNETCORE_URLS` | An override to ensure that kestrel starts on a non-privileged port | `http://+:80` | | `env.ASPNETCORE_URLS` | An override to ensure that kestrel starts on a non-privileged port | `http://+:8080` |
| `autoscaling.enabled` | Enable autoscaling for the deployment | `true` |
| `autoscaling.maxReplicas` | Maximum number of replicas | `6` |
| `autoscaling.minReplicas` | Minimum number of replicas | `3` |
| `autoscaling.targetCPUUtilizationPercentage` | Target CPU utilization percentage | `85` |
| `podDisruptionBudget.minAvailable` | Minimum number of available pods | `1` |
| `podDisruptionBudget.unhealthyPodEvictionPolicy` | Policy for evicting unhealthy pods | `AlwaysAllow` |
### MongoDB parameters ### MongoDB parameters
@ -124,4 +147,4 @@ Parameters are generated with: https://github.com/bitnami-labs/readme-generator-
## Support ## Support
Use the support forum to get help: https://support.squidex.io Use the support forum to get help: https://support.squidex.io

5
helm/squidex7/templates/_helpers.tpl

@ -19,7 +19,8 @@ app.kubernetes.io/version: {{ .Values.selectors.version | quote }}
helm.sh/chart: {{ include "squidex.chart" . }} helm.sh/chart: {{ include "squidex.chart" . }}
app.kubernetes.io/managed-by: {{ .Release.Service }} app.kubernetes.io/managed-by: {{ .Release.Service }}
{{- if .Values.labels }} {{- if .Values.labels }}
{{- toYaml .Values.labels | nindent 4 }} {{- "\n" -}}
{{- toYaml .Values.labels }}
{{- end -}} {{- end -}}
{{- end -}} {{- end -}}
@ -70,4 +71,4 @@ If release name contains chart name it will be used as a full name.
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}} {{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
{{- end -}} {{- end -}}
{{- end -}} {{- end -}}
{{- end -}} {{- end -}}

23
helm/squidex7/templates/deployment-worker.yaml

@ -6,7 +6,10 @@ metadata:
{{- include "squidex.labels" . | indent 4 }} {{- include "squidex.labels" . | indent 4 }}
app.kubernetes.io/role: worker app.kubernetes.io/role: worker
spec: spec:
replicas: 1 replicas: {{ .Values.deployment.worker.replicaCount }}
revisionHistoryLimit: {{ .Values.deployment.revisionHistoryLimit }}
strategy:
{{- toYaml .Values.deployment.strategy | nindent 4 }}
selector: selector:
matchLabels: matchLabels:
{{- include "squidex.selectors" . | indent 6 }} {{- include "squidex.selectors" . | indent 6 }}
@ -16,6 +19,10 @@ spec:
labels: labels:
{{- include "squidex.selectors" . | indent 8 }} {{- include "squidex.selectors" . | indent 8 }}
app.kubernetes.io/role: worker app.kubernetes.io/role: worker
{{- if .Values.deployment.annotations }}
annotations:
{{- toYaml .Values.deployment.annotations | nindent 8 }}
{{- end }}
spec: spec:
{{- with .Values.imagePullSecrets }} {{- with .Values.imagePullSecrets }}
imagePullSecrets: imagePullSecrets:
@ -25,6 +32,7 @@ spec:
securityContext: securityContext:
{{- toYaml .Values.podSecurityContext | nindent 8 }} {{- toYaml .Values.podSecurityContext | nindent 8 }}
{{- end }} {{- end }}
restartPolicy: {{ .Values.deployment.restartPolicy }}
containers: containers:
- name: {{ .Chart.Name }} - name: {{ .Chart.Name }}
image: "{{ .Values.image.repository }}:{{ default .Chart.AppVersion .Values.image.tag }}" image: "{{ .Values.image.repository }}:{{ default .Chart.AppVersion .Values.image.tag }}"
@ -33,9 +41,17 @@ spec:
securityContext: securityContext:
{{- toYaml .Values.containerSecurityContext | nindent 12 }} {{- toYaml .Values.containerSecurityContext | nindent 12 }}
{{- end }} {{- end }}
{{- if .Values.deployment.command }}
command:
{{- toYaml .Values.deployment.command | nindent 12 }}
{{- end }}
{{- if .Values.deployment.args }}
args:
{{- toYaml .Values.deployment.args | nindent 12 }}
{{- end }}
ports: ports:
- name: http - name: http
containerPort: 80 containerPort: 8080
protocol: TCP protocol: TCP
livenessProbe: livenessProbe:
httpGet: httpGet:
@ -58,7 +74,6 @@ spec:
value: {{ $val | quote }} value: {{ $val | quote }}
{{- end }} {{- end }}
{{- end }} {{- end }}
- name: CLUSTERING__WORKER - name: CLUSTERING__WORKER
value: "true" value: "true"
@ -85,4 +100,4 @@ spec:
{{- toYaml .Values.tolerations | nindent 8 }} {{- toYaml .Values.tolerations | nindent 8 }}
{{- if (.Values.deployment.serviceAccountName) }} {{- if (.Values.deployment.serviceAccountName) }}
serviceAccountName: {{ .Values.deployment.serviceAccountName}} serviceAccountName: {{ .Values.deployment.serviceAccountName}}
{{- end }} {{- end }}

30
helm/squidex7/templates/deployment.yaml

@ -6,7 +6,12 @@ metadata:
{{- include "squidex.labels" . | indent 4 }} {{- include "squidex.labels" . | indent 4 }}
app.kubernetes.io/role: api app.kubernetes.io/role: api
spec: spec:
{{- if not .Values.autoscaling.enabled }}
replicas: {{ .Values.deployment.replicaCount }} replicas: {{ .Values.deployment.replicaCount }}
{{- end }}
revisionHistoryLimit: {{ .Values.deployment.revisionHistoryLimit }}
strategy:
{{- toYaml .Values.deployment.strategy | nindent 4 }}
selector: selector:
matchLabels: matchLabels:
{{- include "squidex.selectors" . | indent 6 }} {{- include "squidex.selectors" . | indent 6 }}
@ -16,6 +21,10 @@ spec:
labels: labels:
{{- include "squidex.selectors" . | indent 8 }} {{- include "squidex.selectors" . | indent 8 }}
app.kubernetes.io/role: api app.kubernetes.io/role: api
{{- if .Values.deployment.annotations }}
annotations:
{{- toYaml .Values.deployment.annotations | nindent 8 }}
{{- end }}
spec: spec:
{{- with .Values.imagePullSecrets }} {{- with .Values.imagePullSecrets }}
imagePullSecrets: imagePullSecrets:
@ -25,6 +34,10 @@ spec:
securityContext: securityContext:
{{- toYaml .Values.podSecurityContext | nindent 8 }} {{- toYaml .Values.podSecurityContext | nindent 8 }}
{{- end }} {{- end }}
restartPolicy: {{ .Values.deployment.restartPolicy }}
{{- if .Values.priorityClassName }}
priorityClassName: {{ .Values.priorityClassName }}
{{- end }}
containers: containers:
- name: {{ .Chart.Name }} - name: {{ .Chart.Name }}
image: "{{ .Values.image.repository }}:{{ default .Chart.AppVersion .Values.image.tag }}" image: "{{ .Values.image.repository }}:{{ default .Chart.AppVersion .Values.image.tag }}"
@ -33,9 +46,17 @@ spec:
securityContext: securityContext:
{{- toYaml .Values.containerSecurityContext | nindent 12 }} {{- toYaml .Values.containerSecurityContext | nindent 12 }}
{{- end }} {{- end }}
{{- if .Values.deployment.command }}
command:
{{- toYaml .Values.deployment.command | nindent 12 }}
{{- end }}
{{- if .Values.deployment.args }}
args:
{{- toYaml .Values.deployment.args | nindent 12 }}
{{- end }}
ports: ports:
- name: http - name: http
containerPort: 80 containerPort: 8080
protocol: TCP protocol: TCP
livenessProbe: livenessProbe:
httpGet: httpGet:
@ -58,7 +79,6 @@ spec:
value: {{ $val | quote }} value: {{ $val | quote }}
{{- end }} {{- end }}
{{- end }} {{- end }}
- name: CLUSTERING__WORKER - name: CLUSTERING__WORKER
value: "false" value: "false"
@ -81,8 +101,12 @@ spec:
{{- toYaml .Values.nodeSelector | nindent 8 }} {{- toYaml .Values.nodeSelector | nindent 8 }}
affinity: affinity:
{{- toYaml .Values.affinity | nindent 8 }} {{- toYaml .Values.affinity | nindent 8 }}
{{- if .Values.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml .Values.topologySpreadConstraints | nindent 8 }}
{{- end }}
tolerations: tolerations:
{{- toYaml .Values.tolerations | nindent 8 }} {{- toYaml .Values.tolerations | nindent 8 }}
{{- if (.Values.deployment.serviceAccountName) }} {{- if (.Values.deployment.serviceAccountName) }}
serviceAccountName: {{ .Values.deployment.serviceAccountName}} serviceAccountName: {{ .Values.deployment.serviceAccountName}}
{{- end }} {{- end }}

14
helm/squidex7/templates/hpa.yaml

@ -0,0 +1,14 @@
{{- if .Values.autoscaling.enabled }}
apiVersion: autoscaling/v1
kind: HorizontalPodAutoscaler
metadata:
name: {{ include "squidex.fullname" . }}
spec:
maxReplicas: {{ .Values.autoscaling.maxReplicas }}
minReplicas: {{ .Values.autoscaling.minReplicas }}
scaleTargetRef:
apiVersion: apps/v1
kind: Deployment
name: {{ include "squidex.fullname" . }}
targetCPUUtilizationPercentage: {{ .Values.autoscaling.targetCPUUtilizationPercentage }}
{{- end }}

2
helm/squidex7/templates/ingress.yaml

@ -34,4 +34,4 @@ spec:
name: {{ $fullName }} name: {{ $fullName }}
port: port:
number: {{ .Values.service.port }} number: {{ .Values.service.port }}
{{- end -}} {{- end -}}

19
helm/squidex7/templates/networkpolicy.yaml

@ -0,0 +1,19 @@
{{- if .Values.networkPolicy.enabled }}
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: allow-{{ include "squidex.fullname" . }}
labels:
{{- include "squidex.labels" . | indent 4 }}
spec:
podSelector:
matchLabels:
{{- include "squidex.selectors" . | indent 6 }}
policyTypes:
- Ingress
- Egress
ingress:
{{- toYaml .Values.networkPolicy.ingressRules | nindent 4 }}
egress:
{{- toYaml .Values.networkPolicy.egressRules | nindent 4 }}
{{- end }}

20
helm/squidex7/templates/pdb.yaml

@ -0,0 +1,20 @@
{{- if .Values.podDisruptionBudget }}
apiVersion: policy/v1
kind: PodDisruptionBudget
metadata:
name: {{ include "squidex.fullname" . }}
labels:
{{- include "squidex.labels" . | indent 4 }}
spec:
{{- if .Values.podDisruptionBudget.minAvailable }}
minAvailable: {{ .Values.podDisruptionBudget.minAvailable }}
{{- end }}
{{- if .Values.podDisruptionBudget.maxUnavailable }}
maxUnavailable: {{ .Values.podDisruptionBudget.maxUnavailable }}
{{- end }}
unhealthyPodEvictionPolicy: {{ .Values.podDisruptionBudget.unhealthyPodEvictionPolicy }}
selector:
matchLabels:
{{- include "squidex.selectors" . | indent 6 }}
app.kubernetes.io/role: api
{{- end }}

2
helm/squidex7/templates/service.yaml

@ -14,4 +14,4 @@ spec:
name: http name: http
selector: selector:
{{- include "squidex.selectors" . | indent 4 }} {{- include "squidex.selectors" . | indent 4 }}
app.kubernetes.io/role: api app.kubernetes.io/role: api

160
helm/squidex7/values.yaml

@ -1,18 +1,85 @@
## @section Global parameters ## @section Global parameters
## @skip labels ## @param nameOverride Override the name of the application.
nameOverride: "squidex"
## @param labels [object] Labels to add to the deployment
labels: labels:
# custom: "custom"
service: service:
## @param service.type Kubernetes Service type ## @param service.type Kubernetes Service type
## ##
type: ClusterIP type: ClusterIP
## @param service.port Kubernetes Service port ## @param service.port Kubernetes Service port
## ##
port: 80 port: 8080
deployment: deployment:
## @param deployment.replicaCount Number of instances. ## @param deployment.replicaCount Number of replicas (ignored if autoscaling enabled)
## replicaCount: 3
replicaCount: 1 worker:
## @param deployment.worker.replicaCount Number of worker instances
replicaCount: 1 # only one worker supported
## @param deployment.revisionHistoryLimit [default: 2] Number of revision history
revisionHistoryLimit: 2
## @param deployment.serviceAccountName Name of the service account to use
serviceAccountName: ""
## @param deployment.strategy.type Deployment strategy type
strategy:
type: RollingUpdate
## @param deployment.strategy.rollingUpdate.maxSurge Maximum number of pods that can be created above the desired amount
rollingUpdate:
maxSurge: 1
## @param deployment.strategy.rollingUpdate.maxUnavailable Maximum number of unavailable pods during update
maxUnavailable: 0
## @param deployment.restartPolicy Pod restart policy
restartPolicy: Always
## @param deployment.annotations Annotations to add to the deployment
annotations:
# vault.hashicorp.com/agent-pre-populate-only: "true"
# vault.hashicorp.com/agent-limits-cpu: 50m
# vault.hashicorp.com/agent-limits-mem: 64Mi
# vault.hashicorp.com/agent-requests-cpu: 10m
# vault.hashicorp.com/agent-requests-mem: 16Mi
## @param deployment.command Command to run in the container
command:
# - sh
# - -c
## @param deployment.args Arguments to pass to the container
args:
# - 'dotnet Squidex.dll'
## @param networkPolicy.enabled Enable network policies
networkPolicy:
enabled: true
## @skip networkPolicy.ingressRules
ingressRules:
- from:
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: ingress-nginx
- podSelector:
matchLabels:
app.kubernetes.io/instance: ingress-nginx
ports:
- port: 8080
protocol: TCP
## @skip networkPolicy.egressRules
egressRules:
- to:
- namespaceSelector:
matchLabels:
kubernetes.io/metadata.name: kube-system
podSelector:
matchLabels:
k8s-app: kube-dns
ports:
- port: 53
protocol: UDP
- port: 53
protocol: TCP
selectors: selectors:
## @skip selectors.component ## @skip selectors.component
## ##
@ -31,21 +98,56 @@ image:
## ##
pullPolicy: IfNotPresent pullPolicy: IfNotPresent
## @skip resources ## @param resources [object] Resource requests and limits
resources: { } resources:
limits:
memory: "1Gi"
requests:
cpu: "200m"
memory: "512Mi"
## @skip nodeSelector ## @skip nodeSelector
nodeSelector: { } nodeSelector: { }
## @skip tolerations ## @skip tolerations
tolerations: [ ] tolerations: [ ]
## @skip affinity ## @skip affinity
affinity: { } affinity:
podAntiAffinity:
preferredDuringSchedulingIgnoredDuringExecution:
- weight: 100
podAffinityTerm:
labelSelector:
matchLabels:
app.kubernetes.io/instance: squidex
app.kubernetes.io/component: squidex
topologyKey: kubernetes.io/hostname
nodeAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
nodeSelectorTerms:
- matchExpressions:
- key: kubernetes.io/arch
operator: In
values:
- amd64
- arm64
## @param topologySpreadConstraints [array] Topology spread constraints for pod scheduling
topologySpreadConstraints:
# - maxSkew: 1
# topologyKey: kubernetes.io/hostname
# whenUnsatisfiable: DoNotSchedule
# labelSelector:
# matchLabels:
# app.kubernetes.io/instance: squidex
# app.kubernetes.io/component: squidex
## @param priorityClassName [nullable] Priority class name for the pod
priorityClassName:
## @skip clusterSuffix ## @skip clusterSuffix
clusterSuffix: cluster.local clusterSuffix: cluster.local
## @param runAsNonRoot ## @param runAsNonRoot Run container as non-root user.
## Set to true to run Squidex as nonroot. Defaults to false for backwards compatibility. runAsNonRoot: true
runAsNonRoot: false
## @skip podSecurityContext - object - optional ## @skip podSecurityContext - object - optional
## You can modify the security context used to run PODS in the cluster ## You can modify the security context used to run PODS in the cluster
@ -63,6 +165,7 @@ podSecurityContext:
## @skip containerSecurityContext - object - optional ## @skip containerSecurityContext - object - optional
## You can modify the security context used to run CONTAINERS in the cluster ## You can modify the security context used to run CONTAINERS in the cluster
## For information regarding which settings are required per policy see: https://kubernetes.io/docs/concepts/security/pod-security-standards/ ## For information regarding which settings are required per policy see: https://kubernetes.io/docs/concepts/security/pod-security-standards/
## readOnlyRootFilesystem: true not supported becasue of backup and restore process
## An example that follows the Restricted profile is described below: ## An example that follows the Restricted profile is described below:
# #
containerSecurityContext: containerSecurityContext:
@ -84,10 +187,15 @@ ingress:
enabled: true enabled: true
## @param ingress.ingressClassName The ingress class. ## @param ingress.ingressClassName The ingress class.
ingressClassName: nginx ingressClassName: nginx
## Squidex Ingress annotations ## @param ingress.annotations [object] Ingress annotations
# annotations: annotations:
# kubernetes.io/ingress.class: nginx # kubernetes.io/ingress.class: nginx
# kubernetes.io/tls-acme: "true" # kubernetes.io/tls-acme: "true"
nginx.ingress.kubernetes.io/proxy-body-size: 50m
nginx.ingress.kubernetes.io/proxy-buffer-size: 128k
nginx.ingress.kubernetes.io/proxy-buffers: 4 256k
nginx.ingress.kubernetes.io/proxy-busy-buffers-size: 256k
nginx.ingress.kubernetes.io/ssl-redirect: 'true'
## @param ingress.hostName The host name for the ingress. ## @param ingress.hostName The host name for the ingress.
## ##
hostName: squidex.local hostName: squidex.local
@ -119,7 +227,7 @@ env:
IDENTITY__ADMINPASSWORD: "" IDENTITY__ADMINPASSWORD: ""
## @param env.IDENTITY__ADMINRECREATE Recreate the admin if it does not exist or the password does not match ## @param env.IDENTITY__ADMINRECREATE Recreate the admin if it does not exist or the password does not match
## ##
IDENTITY__ADMINRECREATE: false # IDENTITY__ADMINRECREATE: false
## @param env.IDENTITY__ALLOWPASSWORDAUTH Enable password auth. Set this to false if you want to disable local login, leaving only 3rd party login options ## @param env.IDENTITY__ALLOWPASSWORDAUTH Enable password auth. Set this to false if you want to disable local login, leaving only 3rd party login options
## ##
IDENTITY__ALLOWPASSWORDAUTH: "true" IDENTITY__ALLOWPASSWORDAUTH: "true"
@ -205,7 +313,7 @@ env:
LOGGING__HUMAN: false LOGGING__HUMAN: false
## @param env.LOGGING__LEVEL Trace, Debug, Information, Warning, Error, Fatal ## @param env.LOGGING__LEVEL Trace, Debug, Information, Warning, Error, Fatal
## ##
LOGGING__LEVEL: INFORMATION LOGGING__LEVEL: Warning
## @param env.LOGGING__LOGREQUESTS Set to false to disable logging of http requests. ## @param env.LOGGING__LOGREQUESTS Set to false to disable logging of http requests.
## ##
LOGGING__LOGREQUESTS: true LOGGING__LOGREQUESTS: true
@ -247,7 +355,23 @@ env:
## @param env.ASPNETCORE_URLS An override to ensure that kestrel starts on a non-privileged port ## @param env.ASPNETCORE_URLS An override to ensure that kestrel starts on a non-privileged port
## ##
ASPNETCORE_URLS: http://+:80 ASPNETCORE_URLS: http://+:8080
## @param autoscaling.enabled Enable autoscaling for the deployment
autoscaling:
enabled: true
## @param autoscaling.maxReplicas Maximum number of replicas
maxReplicas: 6
## @param autoscaling.minReplicas Minimum number of replicas
minReplicas: 3
## @param autoscaling.targetCPUUtilizationPercentage Target CPU utilization percentage
targetCPUUtilizationPercentage: 85
## @param podDisruptionBudget.minAvailable Minimum number of available pods
podDisruptionBudget:
minAvailable: 1
## @param podDisruptionBudget.unhealthyPodEvictionPolicy Policy for evicting unhealthy pods
unhealthyPodEvictionPolicy: AlwaysAllow
## @section MongoDB parameters ## @section MongoDB parameters
mongodb: mongodb:

Loading…
Cancel
Save