mirror of
https://github.com/stakater/Reloader.git
synced 2026-08-23 22:16:45 +00:00
Add a third RBAC posture between watch-globally (ClusterRole) and single namespace: give Reloader an explicit list of namespaces to watch. The chart creates a namespace-scoped Role + RoleBinding in each listed namespace (no ClusterRole), and one install covers them all. Go: - new --namespaces flag / options.Namespaces - resolveWatchNamespaces() picks list -> KUBERNETES_NAMESPACE -> all - controller creation loops over the watched namespaces - namespaces-to-ignore is now only honored in global mode (watchGlobally=true); in single-namespace and scoped modes the watched set is already explicit Helm: - new reloader.namespaces value (active when watchGlobally=false); accepts either a YAML list or a comma-separated string for consistency with the sibling namespace options - reloader-watchNamespaces helper (release ns always auto-included, deduped) - shared reloader-namespaced-rules template reused per namespace - role.yaml/rolebinding.yaml range over the list; deployment passes --namespaces - --namespaces-to-ignore only rendered when watchGlobally=true - fail guard for watchGlobally=true + namespaces set Tests: unit test for resolveWatchNamespaces; scoped-namespaces e2e case. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
150 lines
4.7 KiB
Cheetah
150 lines
4.7 KiB
Cheetah
# Generated from deployments/kubernetes/templates/chart/values.yaml.tmpl
|
|
global:
|
|
## Reference to one or more secrets to be used when pulling images
|
|
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
|
|
##
|
|
imagePullSecrets: []
|
|
|
|
kubernetes:
|
|
host: https://kubernetes.default
|
|
|
|
reloader:
|
|
isArgoRollouts: false
|
|
isOpenshift: false
|
|
ignoreSecrets: false
|
|
ignoreConfigMaps: false
|
|
reloadOnCreate: false
|
|
reloadStrategy: default # Set to default, env-vars or annotations
|
|
ignoreNamespaces: "" # Comma separated list of namespaces to ignore
|
|
logFormat: "" #json
|
|
watchGlobally: true
|
|
# Scoped mode: explicit list of namespaces to watch. When non-empty (and watchGlobally
|
|
# is false), Reloader watches exactly these namespaces and the chart creates a namespace
|
|
# scoped Role + RoleBinding in each one — no ClusterRole is created. The release namespace
|
|
# is always included automatically.
|
|
# Accepts either a YAML list (e.g. ["team-a", "team-b"]) or a comma-separated string
|
|
# (e.g. "team-a,team-b")
|
|
namespaces: []
|
|
# Set to true if you have a pod security policy that enforces readOnlyRootFilesystem
|
|
readOnlyRootFileSystem: false
|
|
legacy:
|
|
rbac: false
|
|
matchLabels: {}
|
|
# Set to true to expose a prometheus counter of reloads by namespace (this metric may have high cardinality in clusters with many namespaces)
|
|
enableMetricsByNamespace: false
|
|
deployment:
|
|
replicas: 1
|
|
nodeSelector:
|
|
# cloud.google.com/gke-nodepool: default-pool
|
|
|
|
# An affinity stanza to be applied to the Deployment.
|
|
# Example:
|
|
# affinity:
|
|
# nodeAffinity:
|
|
# requiredDuringSchedulingIgnoredDuringExecution:
|
|
# nodeSelectorTerms:
|
|
# - matchExpressions:
|
|
# - key: "node-role.kubernetes.io/infra-worker"
|
|
# operator: "Exists"
|
|
affinity: {}
|
|
|
|
securityContext:
|
|
runAsNonRoot: true
|
|
runAsUser: 65534
|
|
|
|
containerSecurityContext: {}
|
|
# capabilities:
|
|
# drop:
|
|
# - ALL
|
|
# allowPrivilegeEscalation: false
|
|
# readOnlyRootFilesystem: true
|
|
|
|
# A list of tolerations to be applied to the Deployment.
|
|
# Example:
|
|
# tolerations:
|
|
# - key: "node-role.kubernetes.io/infra-worker"
|
|
# operator: "Exists"
|
|
# effect: "NoSchedule"
|
|
tolerations: []
|
|
|
|
annotations: {}
|
|
labels:
|
|
provider: stakater
|
|
group: com.stakater.platform
|
|
version: {{ getenv "VERSION" }}
|
|
image:
|
|
name: {{ getenv "DOCKER_IMAGE" }}
|
|
tag: "{{ getenv "VERSION" }}"
|
|
pullPolicy: IfNotPresent
|
|
# Support for extra environment variables.
|
|
env:
|
|
# Open supports Key value pair as environment variables.
|
|
open:
|
|
# secret supports Key value pair as environment variables. It gets the values based on keys from default reloader secret if any.
|
|
secret:
|
|
# field supports Key value pair as environment variables. It gets the values from other fields of pod.
|
|
field:
|
|
|
|
# Specify resource requests/limits for the deployment.
|
|
# Example:
|
|
# resources:
|
|
# limits:
|
|
# cpu: "100m"
|
|
# memory: "512Mi"
|
|
# requests:
|
|
# cpu: "10m"
|
|
# memory: "128Mi"
|
|
resources: {}
|
|
pod:
|
|
annotations: {}
|
|
|
|
service: {}
|
|
# labels: {}
|
|
# annotations: {}
|
|
# port: 9090
|
|
|
|
rbac:
|
|
enabled: true
|
|
labels: {}
|
|
# Service account config for the agent pods
|
|
serviceAccount:
|
|
# Specifies whether a ServiceAccount should be created
|
|
create: true
|
|
labels: {}
|
|
annotations: {}
|
|
# The name of the ServiceAccount to use.
|
|
# If not set and create is true, a name is generated using the fullname template
|
|
name:
|
|
# Optional flags to pass to the Reloader entrypoint
|
|
# Example:
|
|
# custom_annotations:
|
|
# configmap: "my.company.com/configmap"
|
|
# secret: "my.company.com/secret"
|
|
custom_annotations: {}
|
|
serviceMonitor:
|
|
# enabling this requires service to be enabled as well, or no endpoints will be found
|
|
enabled: false
|
|
# Set the namespace the ServiceMonitor should be deployed
|
|
# namespace: monitoring
|
|
# Set how frequently Prometheus should scrape
|
|
# interval: 30s
|
|
# Set labels for the ServiceMonitor, use this to define your scrape label for Prometheus Operator
|
|
# labels:
|
|
# Set timeout for scrape
|
|
# timeout: 10s
|
|
|
|
|
|
podMonitor:
|
|
# enabling this requires service to be enabled as well, or no endpoints will be found
|
|
enabled: false
|
|
# Set the namespace the podMonitor should be deployed
|
|
# namespace: monitoring
|
|
# Set how frequently Prometheus should scrape
|
|
# interval: 30s
|
|
# Set labels for the podMonitor, use this to define your scrape label for Prometheus Operator
|
|
# labels:
|
|
# Set timeout for scrape
|
|
# timeout: 10s
|
|
|
|
webhookUrl: ""
|