diff --git a/charts/podinfo/README.md b/charts/podinfo/README.md index 7786e91..670840c 100644 --- a/charts/podinfo/README.md +++ b/charts/podinfo/README.md @@ -66,6 +66,7 @@ Parameter | Default | Description `hpa.requests` | `None` | Target HTTP requests per second per pod `serviceAccount.enabled` | `false` | Whether a service account should be created `serviceAccount.name` | `None` | The name of the service account to use, if not set and create is true, a name is generated using the fullname template +`securityContext` | `{}` | The security context to be set on the podinfo container `linkerd.profile.enabled` | `false` | Create Linkerd service profile `serviceMonitor.enabled` | `false` | Whether a Prometheus Operator service monitor should be created `serviceMonitor.interval` | `15s` | Prometheus scraping interval diff --git a/charts/podinfo/templates/deployment.yaml b/charts/podinfo/templates/deployment.yaml index ffb6981..6136716 100644 --- a/charts/podinfo/templates/deployment.yaml +++ b/charts/podinfo/templates/deployment.yaml @@ -34,7 +34,10 @@ spec: - name: {{ .Chart.Name }} image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" imagePullPolicy: {{ .Values.image.pullPolicy }} - {{- if (or .Values.service.hostPort .Values.tls.hostPort) }} + {{- if .Values.securityContext }} + securityContext: + {{- toYaml .Values.securityContext | nindent 12 }} + {{- else if (or .Values.service.hostPort .Values.tls.hostPort) }} securityContext: allowPrivilegeEscalation: true capabilities: diff --git a/charts/podinfo/templates/service.yaml b/charts/podinfo/templates/service.yaml index f7abfee..6014e78 100644 --- a/charts/podinfo/templates/service.yaml +++ b/charts/podinfo/templates/service.yaml @@ -5,6 +5,10 @@ metadata: name: {{ template "podinfo.fullname" . }} labels: {{- include "podinfo.labels" . | nindent 4 }} +{{- with .Values.service.annotations }} + annotations: +{{ toYaml . | indent 4 }} +{{- end }} spec: type: {{ .Values.service.type }} ports: diff --git a/charts/podinfo/values-prod.yaml b/charts/podinfo/values-prod.yaml index 59e1bac..7779f7b 100644 --- a/charts/podinfo/values-prod.yaml +++ b/charts/podinfo/values-prod.yaml @@ -1,15 +1,22 @@ -# Prod values for podinfo. +# Production values for podinfo. +# Includes Redis deployment and memory limits. replicaCount: 1 logLevel: info backend: #http://backend-podinfo:9898/echo backends: [] +image: + repository: ghcr.io/stefanprodan/podinfo + tag: 5.1.4 + pullPolicy: IfNotPresent + ui: color: "#34577c" message: "" logo: "" +# failure conditions faults: delay: false error: false @@ -18,16 +25,10 @@ faults: testFail: false testTimeout: false -h2c: - enabled: false - -image: - repository: ghcr.io/stefanprodan/podinfo - tag: 5.1.4 - pullPolicy: IfNotPresent - +# Kubernetes Service settings service: enabled: true + annotations: {} type: ClusterIP metricsPort: 9797 httpPort: 9898 @@ -36,6 +37,35 @@ service: grpcService: podinfo nodePort: 31198 +# enable h2c protocol (non-TLS version of HTTP/2) +h2c: + enabled: false + +# enable tls on the podinfo service +tls: + enabled: false + # the name of the secret used to mount the certificate key pair + secretName: + # the path where the certificate key pair will be mounted + certPath: /data/cert + # the port used to host the tls endpoint on the service + port: 9899 + # the port used to bind the tls port to the host + # NOTE: requires privileged container with NET_BIND_SERVICE capability -- this is useful for testing + # in local clusters such as kind without port forwarding + hostPort: + +# create a certificate manager certificate (cert-manager required) +certificate: + create: false + # the issuer used to issue the certificate + issuerRef: + kind: ClusterIssuer + name: self-signed + # the hostname / subject alternative names for the certificate + dnsNames: + - podinfo + # metrics-server add-on required hpa: enabled: true @@ -62,13 +92,8 @@ serviceAccount: # If not set and create is true, a name is generated using the fullname template name: -linkerd: - profile: - enabled: false - -serviceMonitor: - enabled: false - interval: 15s +# set container security context +securityContext: {} ingress: enabled: false @@ -83,6 +108,15 @@ ingress: # hosts: # - chart-example.local +linkerd: + profile: + enabled: false + +# create Prometheus Operator monitor +serviceMonitor: + enabled: false + interval: 15s + resources: limits: memory: 256Mi diff --git a/charts/podinfo/values.yaml b/charts/podinfo/values.yaml index 42ae505..4af5583 100644 --- a/charts/podinfo/values.yaml +++ b/charts/podinfo/values.yaml @@ -5,11 +5,17 @@ logLevel: info backend: #http://backend-podinfo:9898/echo backends: [] +image: + repository: ghcr.io/stefanprodan/podinfo + tag: 5.1.4 + pullPolicy: IfNotPresent + ui: color: "#34577c" message: "" logo: "" +# failure conditions faults: delay: false error: false @@ -18,16 +24,10 @@ faults: testFail: false testTimeout: false -h2c: - enabled: false - -image: - repository: ghcr.io/stefanprodan/podinfo - tag: 5.1.4 - pullPolicy: IfNotPresent - +# Kubernetes Service settings service: enabled: true + annotations: {} type: ClusterIP metricsPort: 9797 httpPort: 9898 @@ -40,6 +40,10 @@ service: # in local clusters such as kind without port forwarding hostPort: +# enable h2c protocol (non-TLS version of HTTP/2) +h2c: + enabled: false + # enable tls on the podinfo service tls: enabled: false @@ -54,7 +58,7 @@ tls: # in local clusters such as kind without port forwarding hostPort: -# create a certificate manager certificate +# create a certificate manager certificate (cert-manager required) certificate: create: false # the issuer used to issue the certificate @@ -91,13 +95,8 @@ serviceAccount: # If not set and create is true, a name is generated using the fullname template name: -linkerd: - profile: - enabled: false - -serviceMonitor: - enabled: false - interval: 15s +# set container security context +securityContext: {} ingress: enabled: false @@ -112,6 +111,15 @@ ingress: # hosts: # - chart-example.local +linkerd: + profile: + enabled: false + +# create Prometheus Operator monitor +serviceMonitor: + enabled: false + interval: 15s + resources: limits: requests: