# This is a YAML-formatted file. # Declare variables to be passed into your templates. ## Dependencies configuration parameters ## Redis dependency parameters # -- Install redis as a depending chart redisDependencyEnabled: true # -- Install mariadb as a depending chart mariadbDependencyEnabled: true # -- Install postgresql as a depending chart postgresqlDependencyEnabled: false # Configure postgresql as a dependency chart # postgresql: # global: # security: # # -- Allow insecure images on bitnami charts. Required as per when using bitnamilegacy https://github.com/bitnami/charts/issues/30850 # allowInsecureImages: true # image: # # -- Pin PostgreSQL image to bitnamilegacy image repository. # repository: bitnamilegacy/postgresql # auth: # # -- Configure postgresql auth username # username: CHANGEME # # -- Configure postgresql auth password # password: CHANGEME # # -- Configure postgresql auth database # database: passbolt global: imageRegistry: "" imagePullSecrets: [] # Configure redis dependency chart redis: global: security: # -- Allow insecure images on bitnami charts. Required as per when using bitnamilegacy https://github.com/bitnami/charts/issues/30850 allowInsecureImages: true image: # -- Pin redis image to bitnamilegacy image repository. repository: bitnamilegacy/redis auth: # -- Enable redis authentication enabled: true # -- Configure redis password password: "CHANGEME" sentinel: image: # -- Pin redis-sentinel image to bitnamilegacy image repository. repository: bitnamilegacy/redis-sentinel # -- Enable redis sentinel enabled: true ## MariaDB dependency parameters # Configure mariadb as a dependency chart mariadb: global: security: # -- Allow insecure images on bitnami charts. Required as per when using bitnamilegacy https://github.com/bitnami/charts/issues/30850 allowInsecureImages: true image: # -- Pin redis image to bitnamilegacy image repository. repository: bitnamilegacy/mariadb # -- Configure mariadb architecture architecture: replication auth: # -- Configure mariadb auth root password rootPassword: root # -- Configure mariadb auth username username: pbadmin # -- Configure mariadb auth password password: DW"C_/9jTTkMjwj<'% # -- Configure mariadb auth database database: passboltdb # -- Configure mariadb auth replicationPassword replicationPassword: w(*4Ewj:m`K/Ai^/qb # -- Configure parameters for the primary instance. primary: # -- Configure persistence options. persistence: # -- Enable persistence on MariaDB primary replicas using a `PersistentVolumeClaim`. If false, use emptyDir enabled: true # -- Name of an existing `PersistentVolumeClaim` for MariaDB primary replicas. When it's set the rest of persistence parameters are ignored. existingClaim: "" # -- Subdirectory of the volume to mount at subPath: "" # -- Primary persistent volume storage Class storageClass: "" # -- Labels for the PVC labels: {} # -- Primary persistent volume claim annotations annotations: {} # -- Primary persistent volume access Modes accessModes: - ReadWriteOnce # -- Primary persistent volume size size: 8Gi # -- Selector to match an existing Persistent Volume selector: {} # -- Configure parameters for the secondary instance. secondary: # -- Configure persistence options. persistence: # -- Enable persistence on MariaDB secondary replicas using a `PersistentVolumeClaim`. If false, use emptyDir enabled: true # -- Subdirectory of the volume to mount at subPath: "" # -- Secondary persistent volume storage Class storageClass: "" # -- Labels for the PVC labels: {} # -- Secondary persistent volume claim annotations annotations: {} # -- Secondary persistent volume access Modes accessModes: - ReadWriteOnce # -- Secondary persistent volume size size: 8Gi # -- Selector to match an existing Persistent Volume selector: {} ## Passbolt configuration ## Passbolt container and sidecar parameters app: # -- Configure pasbolt deployment init container that waits for database databaseInitContainer: # -- Toggle pasbolt deployment init container that waits for database enabled: true # initImage: # # -- Configure pasbolt deployment init container image client for database # client: mariadb # registry: "" # # -- Configure pasbolt deployment image repsitory # repository: mariadb # # -- Configure pasbolt deployment image pullPolicy # pullPolicy: IfNotPresent # # -- Overrides the image tag whose default is the chart appVersion. # tag: latest image: # -- Configure pasbolt deployment image repsitory registry: "" repository: passbolt/passbolt # -- Configure pasbolt deployment image pullPolicy pullPolicy: IfNotPresent # -- Overrides the image tag whose default is the chart appVersion. tag: 5.9.0-1-ce # Allowed options: mariadb, mysql or postgresql database: kind: mariadb # -- Configure ssl on mariadb/mysql clients # -- In case this is enabled, you will be responsible for creating and mounting the certificates and # -- additional configutions on both the client and the server. # ssl: off cache: # Use CACHE_CAKE_DEFAULT_* variables to configure the connection to redis instance # on the passboltEnv configuration section redis: # -- By enabling redis the chart will mount a configuration file on /etc/passbolt/app.php # That instructs passbolt to store sessions on redis and to use it as a general cache. enabled: true sentinelProxy: # -- Inject a haproxy sidecar container configured as a proxy to redis sentinel # Make sure that CACHE_CAKE_DEFAULT_SERVER is set to '127.0.0.1' to use the proxy enabled: true # -- Configure redis sentinel proxy image image: registry: "" # -- Configure redis sentinel image repository repository: haproxy # -- Configure redis sentinel image tag tag: "latest" # -- Configure redis sentinel container resources resources: {} # -- Configure the passbolt deployment resources extraPodLabels: {} resources: {} tls: # -- If autogenerate is true, the chart will generate a secret with a certificate for APP_FULL_BASE_URL hostname # -- if autogenerate is false, existingSecret should be filled with an existing tls kind secret name # @ignored autogenerate: true # existingSecret: "" # -- Configure additional containers to be added to the pod extraContainers: [] # -- Enable email cron cronJobEmail: enabled: true schedule: "* * * * *" extraPodLabels: {} ## Passbolt environment parameters # -- Pro subscription key in base64 only if you are using pro version # subscriptionKey: # -- Configure passbolt subscription key path # subscription_keyPath: /etc/passbolt/subscription_key.txt # -- Configure passbolt gpg directory gpgPath: /etc/passbolt/gpg # -- Gpg server private key in base64 gpgServerKeyPrivate: "" # -- Gpg server public key in base64 gpgServerKeyPublic: "" # -- Name of the existing secret for the GPG server keypair. The secret must contain the `serverkey.asc` and `serverkey_private.asc` keys. gpgExistingSecret: "" # -- Name of the existing secret for the JWT server keypair. The secret must contain the `jwt.key` and `jwt.pem` keys. jwtExistingSecret: "" # -- Configure passbolt jwt directory jwtPath: /etc/passbolt/jwt # -- JWT server private key in base64 jwtServerPrivate: "" # -- JWT server public key in base64 jwtServerPublic: "" # -- Forces overwrite JWT keys jwtCreateKeysForced: false jobCreateJwtKeys: extraPodLabels: {} jobCreateGpgKeys: extraPodLabels: {} passboltEnv: plain: # -- Configure passbolt privacy url PASSBOLT_LEGAL_PRIVACYPOLICYURL: https://www.passbolt.com/privacy # -- Configure passbolt fullBaseUrl APP_FULL_BASE_URL: https://passbolt.realm.local # -- Configure passbolt to force ssl PASSBOLT_SSL_FORCE: true # -- Toggle passbolt public registration PASSBOLT_REGISTRATION_PUBLIC: true # -- Configure passbolt cake cache server CACHE_DEFAULT_HOST: 127.0.0.1 # -- Configure passbolt cake core cache server CACHE_CAKECORE_HOST: 127.0.0.1 # -- Configure passbolt cake model cache server CACHE_CAKEMODEL_HOST: 127.0.0.1 # -- Configure passbolt cake cache server port CACHE_DEFAULT_PORT: 6379 # -- Configure passbolt cake core cache server port CACHE_CAKECORE_PORT: 6379 # -- Configure passbolt cake model cache server port CACHE_CAKEMODEL_PORT: 6379 # -- Configure passbolt cake session storage, either php, cake, database or cache SESSION_DEFAULTS: cache # -- Configure passbolt cake cache class CACHE_DEFAULT_CLASSNAME: Redis # -- Configure passbolt cake model cache class CACHE_CAKEMODEL_CLASSNAME: Redis # -- Configure passbolt cake core cache class CACHE_CAKECORE_CLASSNAME: Redis # -- Configure passbolt default email service port EMAIL_TRANSPORT_DEFAULT_PORT: 587 # -- Toggle passbolt debug mode DEBUG: false # -- Configure email used on gpg key. This is used when automatically creating a new gpg server key and when automatically calculating the fingerprint. PASSBOLT_KEY_EMAIL: passbolt@solusar.de # -- Toggle passbolt selenium mode PASSBOLT_SELENIUM_ACTIVE: false # -- Configure passbolt license path PASSBOLT_PLUGINS_LICENSE_LICENSE: /etc/passbolt/subscription_key.txt # -- Configure passbolt default email from EMAIL_DEFAULT_FROM: no-reply@passbolt.realm.local # -- Configure passbolt default email from name EMAIL_DEFAULT_FROM_NAME: Passbolt # -- Configure passbolt default email host EMAIL_TRANSPORT_DEFAULT_HOST: 127.0.0.1 # -- Configure passbolt default email timeout EMAIL_TRANSPORT_DEFAULT_TIMEOUT: 30 # -- Toggle passbolt tls EMAIL_TRANSPORT_DEFAULT_TLS: true # -- Configure passbolt jwt private key path PASSBOLT_JWT_SERVER_KEY: /var/www/passbolt/config/jwt/jwt.key # -- Configure passbolt jwt public key path PASSBOLT_JWT_SERVER_PEM: /var/www/passbolt/config/jwt/jwt.pem # -- Toggle passbolt jwt authentication PASSBOLT_PLUGINS_JWT_AUTHENTICATION_ENABLED: true # -- Download Command for kubectl KUBECTL_DOWNLOAD_CMD: "" # -- Set to false to supress warnings when running passbolt commands as non webserver user, mainly for Openshift PASSBOLT_SECURITY_DISPLAY_NON_WEBUSER_WARNING: true secret: # -- Configure passbolt cake cache password CACHE_DEFAULT_PASSWORD: ={K=X=6UcS~s^Pa,a, # -- Configure passbolt cake core cache password CACHE_CAKECORE_PASSWORD: U!L9Ue%"`_-+{.u"vQ # -- Configure passbolt cake model cache password CACHE_CAKEMODEL_PASSWORD: V!K'_6}Q\%PSufj$eV # -- Configure passbolt default database password DATASOURCES_DEFAULT_PASSWORD: DW"C_/9jTTkMjwj<'% # -- Configure passbolt default database username DATASOURCES_DEFAULT_USERNAME: pbadmin # -- Configure passbolt default database DATASOURCES_DEFAULT_DATABASE: passboltdb # -- Configure passbolt default email service username EMAIL_TRANSPORT_DEFAULT_USERNAME: admin@solusar.de # -- Configure passbolt default email service password EMAIL_TRANSPORT_DEFAULT_PASSWORD: #gentoo# # -- Configure passbolt server gpg key fingerprint # PASSBOLT_GPG_SERVER_KEY_FINGERPRINT: # -- Configure passbolt security salt. # SECURITY_SALT: # -- Environment variables to add to the passbolt pods extraEnv: [] # -- Environment variables from secrets or configmaps to add to the passbolt pods extraEnvFrom: [] # - secretRef: # name: passbolt-secret ## Overrides the plain value in the case of not wanting to provide the config from values ## Do this ONLY if you know what you are doing configMapName: "" ## Overrides the secrets value in the case of not wanting to provide them in the values file. ## Do this ONLY if you know what you are doing secretName: "" ## Passbolt deployment parameters # -- If autoscaling is disabled this will define the number of pods to run replicaCount: 2 # Configure autoscaling on passbolt deployment autoscaling: # -- Enable autoscaling on passbolt deployment enabled: false # -- Configure autoscaling minimum replicas minReplicas: 1 # -- Configure autoscaling maximum replicas maxReplicas: 100 # -- Configure autoscaling target CPU uptilization percentage targetCPUUtilizationPercentage: 80 # targetMemoryUtilizationPercentage: 80 # -- Enable role based access control rbacEnabled: true # -- Configure passbolt container livenessProbe livenessProbe: # @ignore httpGet: port: https scheme: HTTPS path: /healthcheck/status.json httpHeaders: - name: Host value: passbolt.realm.local initialDelaySeconds: 20 periodSeconds: 10 # -- Configure passbolt container RadinessProbe readinessProbe: # @ignore httpGet: port: https scheme: HTTPS httpHeaders: - name: Host value: passbolt.realm.local path: /healthcheck/status.json initialDelaySeconds: 5 periodSeconds: 10 # Configure network policies to allow ingress access passbolt pods # networkPolicy defines which labels are allowed to reach to passbolt # and which namespaces networkPolicy: # -- Enable network policies to allow ingress access passbolt pods enabled: false # -- Configure network policies label for ingress deployment label: app.kubernetes.io/name # -- Configure network policies podLabel for podSelector podLabel: ingress-nginx # -- Configure network policies namespaceLabel for namespaceSelector namespaceLabel: ingress-nginx # -- Configure image pull secrets imagePullSecrets: [] # -- Value to override the chart name on default nameOverride: "" # -- Value to override the whole fullName fullnameOverride: "" serviceAccount: # -- Specifies whether a service account should be created create: true # -- Annotations to add to the service account annotations: {} # -- Map of annotation for passbolt server pod podAnnotations: {} # -- Security Context configuration for passbolt server pod podSecurityContext: {} # fsGroup: 2000 service: # -- Configure passbolt service type type: LoadBalancer # -- Annotations to add to the service annotations: {} # -- Configure the service ports ports: # -- Configure the HTTPS port https: # -- Configure passbolt HTTPS service port port: 443 # -- Configure passbolt HTTPS service targetPort targetPort: 443 # -- Configure passbolt HTTPS service port name name: https http: # -- Configure passbolt HTTP service port port: 80 # -- Configure passbolt HTTP service targetPort targetPort: 80 # -- Configure passbolt HTTP service port name name: http # -- Preference for routing traffic to endpoints that are in the same zone as the client # trafficDistribution: "PreferSameZone" ingress: # -- Enable passbolt ingress enabled: false # -- Configure passbolt ingress annotations annotations: {} # -- Configure passbolt ingress class name # className: "nginx-example" # -- Configure passbolt ingress hosts hosts: # @ignored - host: passbolt.realm.local paths: - path: / port: https pathType: ImplementationSpecific # -- Configure passbolt ingress tls tls: # If autogenerate is true, the chart will generate a secret for the given hosts # if autogenerate is false, existingSecret should be filled with an existing tls kind secret name # @ignored - autogenerate: true # existingSecret: "" hosts: - passbolt.realm.local # -- Configure passbolt deployment nodeSelector nodeSelector: {} # -- Configure passbolt deployment tolerations tolerations: [] # -- Configure passbolt deployment affinity affinity: {} # -- Add additional volumes, e.g. for overwriting config files extraVolumes: [] # -- Add additional volume mounts, e.g. for overwriting config files extraVolumeMounts: [] # Toggle to true if deploying on Openshift # Removes security context specifying UID from the email cronjob # Adds a route to use Openshift: false