Skip to content

Commit 48e4c47

Browse files
updating params
1 parent f0b1a05 commit 48e4c47

3 files changed

Lines changed: 87 additions & 0 deletions

File tree

deployments/kubernetes/chart/reloader/values.yaml

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -212,6 +212,19 @@ reloader:
212212
# secret: "my.company.com/secret"
213213
custom_annotations: {}
214214

215+
# Vault trigger (webhook-style) configuration defaults
216+
vaultTrigger:
217+
enabled: false
218+
rotationToken: ""
219+
220+
# Vault watcher (polling) configuration defaults
221+
vaultWatcher:
222+
enabled: false
223+
address: ""
224+
token: ""
225+
pollInterval: ""
226+
skipTLSVerify: false
227+
215228
serviceMonitor:
216229
# Deprecated: Service monitor will be removed in future releases of reloader in favour of Pod monitor
217230
# Enabling this requires service to be enabled as well, or no endpoints will be found
Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,26 @@
1+
apiVersion: helm.cattle.io/v1
2+
kind: HelmChart
3+
metadata:
4+
name: reloader
5+
namespace: stakater
6+
spec:
7+
targetNamespace: stakater
8+
chart: reloader
9+
# Set this to the chart version you published to your GitHub Pages repo
10+
version: 0.1.8
11+
repo: https://NodeOps-app.github.io/Reloader
12+
valuesContent: |
13+
reloader:
14+
logLevel: info
15+
vaultTrigger:
16+
enabled: false
17+
vaultWatcher:
18+
enabled: true
19+
address: "https://vault.example.com" # change to your Vault URL
20+
pollInterval: "45s"
21+
# Do NOT set token here; read from secret below via env mapping
22+
deployment:
23+
env:
24+
existing:
25+
vault-creds: # Secret name (must exist in targetNamespace)
26+
VAULT_TOKEN: VAULT_TOKEN # env var name : secret key
Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,48 @@
1+
apiVersion: helm.cattle.io/v1
2+
kind: HelmChart
3+
metadata:
4+
name: secrets-store-csi-driver
5+
namespace: kube-system
6+
spec:
7+
targetNamespace: kube-system
8+
repo: https://kubernetes-sigs.github.io/secrets-store-csi-driver/charts
9+
chart: secrets-store-csi-driver
10+
# Pin a known stable version; update as needed
11+
version: 1.4.0
12+
valuesContent: |
13+
syncSecret.enabled: true
14+
enableSecretRotation: true
15+
rotationPollInterval: 2m
16+
logLevel: info
17+
linux:
18+
enabled: true
19+
windows:
20+
enabled: false
21+
---
22+
apiVersion: helm.cattle.io/v1
23+
kind: HelmChart
24+
metadata:
25+
name: vault-csi-provider
26+
namespace: kube-system
27+
spec:
28+
targetNamespace: kube-system
29+
# HashiCorp's Helm repo (contains Vault chart; provider is typically configured via manifests, adjust if using custom chart)
30+
repo: https://helm.releases.hashicorp.com
31+
chart: vault
32+
# Minimal Vault install acting as a provider; adjust for HA or external Vault if not needed.
33+
version: 0.28.0
34+
valuesContent: |
35+
global:
36+
enabled: false # disable server components if using external Vault
37+
server:
38+
enabled: false
39+
csi:
40+
enabled: true
41+
# When using external Vault, set address via env or secret
42+
image:
43+
tag: latest
44+
resources: {}
45+
injector:
46+
enabled: false
47+
ui:
48+
enabled: false

0 commit comments

Comments
 (0)