Files
kubernetes/passbolt/values.yaml
T
2026-03-17 15:05:32 +00:00

471 lines
16 KiB
YAML
Raw Blame History

This file contains invisible Unicode characters
This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# This is a YAML-formatted file.
# Declare variables to be passed into your templates.
## Dependencies configuration parameters
## Redis dependency parameters
# -- Install redis as a depending chart
redisDependencyEnabled: true
# -- Install mariadb as a depending chart
mariadbDependencyEnabled: true
# -- Install postgresql as a depending chart
postgresqlDependencyEnabled: false
# Configure postgresql as a dependency chart
# postgresql:
# global:
# security:
# # -- Allow insecure images on bitnami charts. Required as per when using bitnamilegacy https://github.com/bitnami/charts/issues/30850
# allowInsecureImages: true
# image:
# # -- Pin PostgreSQL image to bitnamilegacy image repository.
# repository: bitnamilegacy/postgresql
# auth:
# # -- Configure postgresql auth username
# username: CHANGEME
# # -- Configure postgresql auth password
# password: CHANGEME
# # -- Configure postgresql auth database
# database: passbolt
global:
imageRegistry: ""
imagePullSecrets: []
# Configure redis dependency chart
redis:
global:
security:
# -- Allow insecure images on bitnami charts. Required as per when using bitnamilegacy https://github.com/bitnami/charts/issues/30850
allowInsecureImages: true
image:
# -- Pin redis image to bitnamilegacy image repository.
repository: bitnamilegacy/redis
auth:
# -- Enable redis authentication
enabled: true
# -- Configure redis password
password: "CHANGEME"
sentinel:
image:
# -- Pin redis-sentinel image to bitnamilegacy image repository.
repository: bitnamilegacy/redis-sentinel
# -- Enable redis sentinel
enabled: true
## MariaDB dependency parameters
# Configure mariadb as a dependency chart
mariadb:
global:
security:
# -- Allow insecure images on bitnami charts. Required as per when using bitnamilegacy https://github.com/bitnami/charts/issues/30850
allowInsecureImages: true
image:
# -- Pin redis image to bitnamilegacy image repository.
repository: bitnamilegacy/mariadb
# -- Configure mariadb architecture
architecture: replication
auth:
# -- Configure mariadb auth root password
rootPassword: root
# -- Configure mariadb auth username
username: pbadmin
# -- Configure mariadb auth password
password: DW"C_/9jTTkMjwj<'%
# -- Configure mariadb auth database
database: passboltdb
# -- Configure mariadb auth replicationPassword
replicationPassword: w(*4Ewj:m`K/Ai^/qb
# -- Configure parameters for the primary instance.
primary:
# -- Configure persistence options.
persistence:
# -- Enable persistence on MariaDB primary replicas using a `PersistentVolumeClaim`. If false, use emptyDir
enabled: true
# -- Name of an existing `PersistentVolumeClaim` for MariaDB primary replicas. When it's set the rest of persistence parameters are ignored.
existingClaim: ""
# -- Subdirectory of the volume to mount at
subPath: ""
# -- Primary persistent volume storage Class
storageClass: ""
# -- Labels for the PVC
labels: {}
# -- Primary persistent volume claim annotations
annotations: {}
# -- Primary persistent volume access Modes
accessModes:
- ReadWriteOnce
# -- Primary persistent volume size
size: 8Gi
# -- Selector to match an existing Persistent Volume
selector: {}
# -- Configure parameters for the secondary instance.
secondary:
# -- Configure persistence options.
persistence:
# -- Enable persistence on MariaDB secondary replicas using a `PersistentVolumeClaim`. If false, use emptyDir
enabled: true
# -- Subdirectory of the volume to mount at
subPath: ""
# -- Secondary persistent volume storage Class
storageClass: ""
# -- Labels for the PVC
labels: {}
# -- Secondary persistent volume claim annotations
annotations: {}
# -- Secondary persistent volume access Modes
accessModes:
- ReadWriteOnce
# -- Secondary persistent volume size
size: 8Gi
# -- Selector to match an existing Persistent Volume
selector: {}
## Passbolt configuration
## Passbolt container and sidecar parameters
app:
# -- Configure pasbolt deployment init container that waits for database
databaseInitContainer:
# -- Toggle pasbolt deployment init container that waits for database
enabled: true
# initImage:
# # -- Configure pasbolt deployment init container image client for database
# client: mariadb
# registry: ""
# # -- Configure pasbolt deployment image repsitory
# repository: mariadb
# # -- Configure pasbolt deployment image pullPolicy
# pullPolicy: IfNotPresent
# # -- Overrides the image tag whose default is the chart appVersion.
# tag: latest
image:
# -- Configure pasbolt deployment image repsitory
registry: ""
repository: passbolt/passbolt
# -- Configure pasbolt deployment image pullPolicy
pullPolicy: IfNotPresent
# -- Overrides the image tag whose default is the chart appVersion.
tag: 5.9.0-1-ce
# Allowed options: mariadb, mysql or postgresql
database:
kind: mariadb
# -- Configure ssl on mariadb/mysql clients
# -- In case this is enabled, you will be responsible for creating and mounting the certificates and
# -- additional configutions on both the client and the server.
# ssl: off
cache:
# Use CACHE_CAKE_DEFAULT_* variables to configure the connection to redis instance
# on the passboltEnv configuration section
redis:
# -- By enabling redis the chart will mount a configuration file on /etc/passbolt/app.php
# That instructs passbolt to store sessions on redis and to use it as a general cache.
enabled: true
sentinelProxy:
# -- Inject a haproxy sidecar container configured as a proxy to redis sentinel
# Make sure that CACHE_CAKE_DEFAULT_SERVER is set to '127.0.0.1' to use the proxy
enabled: true
# -- Configure redis sentinel proxy image
image:
registry: ""
# -- Configure redis sentinel image repository
repository: haproxy
# -- Configure redis sentinel image tag
tag: "latest"
# -- Configure redis sentinel container resources
resources: {}
# -- Configure the passbolt deployment resources
extraPodLabels: {}
resources: {}
tls:
# -- If autogenerate is true, the chart will generate a secret with a certificate for APP_FULL_BASE_URL hostname
# -- if autogenerate is false, existingSecret should be filled with an existing tls kind secret name
# @ignored
autogenerate: true
# existingSecret: ""
# -- Configure additional containers to be added to the pod
extraContainers: []
# -- Enable email cron
cronJobEmail:
enabled: true
schedule: "* * * * *"
extraPodLabels: {}
## Passbolt environment parameters
# -- Pro subscription key in base64 only if you are using pro version
# subscriptionKey:
# -- Configure passbolt subscription key path
# subscription_keyPath: /etc/passbolt/subscription_key.txt
# -- Configure passbolt gpg directory
gpgPath: /etc/passbolt/gpg
# -- Gpg server private key in base64
gpgServerKeyPrivate: ""
# -- Gpg server public key in base64
gpgServerKeyPublic: ""
# -- Name of the existing secret for the GPG server keypair. The secret must contain the `serverkey.asc` and `serverkey_private.asc` keys.
gpgExistingSecret: ""
# -- Name of the existing secret for the JWT server keypair. The secret must contain the `jwt.key` and `jwt.pem` keys.
jwtExistingSecret: ""
# -- Configure passbolt jwt directory
jwtPath: /etc/passbolt/jwt
# -- JWT server private key in base64
jwtServerPrivate: ""
# -- JWT server public key in base64
jwtServerPublic: ""
# -- Forces overwrite JWT keys
jwtCreateKeysForced: false
jobCreateJwtKeys:
extraPodLabels: {}
jobCreateGpgKeys:
extraPodLabels: {}
passboltEnv:
plain:
# -- Configure passbolt privacy url
PASSBOLT_LEGAL_PRIVACYPOLICYURL: https://www.passbolt.com/privacy
# -- Configure passbolt fullBaseUrl
APP_FULL_BASE_URL: https://passbolt.realm.local
# -- Configure passbolt to force ssl
PASSBOLT_SSL_FORCE: true
# -- Toggle passbolt public registration
PASSBOLT_REGISTRATION_PUBLIC: true
# -- Configure passbolt cake cache server
CACHE_DEFAULT_HOST: 127.0.0.1
# -- Configure passbolt cake core cache server
CACHE_CAKECORE_HOST: 127.0.0.1
# -- Configure passbolt cake model cache server
CACHE_CAKEMODEL_HOST: 127.0.0.1
# -- Configure passbolt cake cache server port
CACHE_DEFAULT_PORT: 6379
# -- Configure passbolt cake core cache server port
CACHE_CAKECORE_PORT: 6379
# -- Configure passbolt cake model cache server port
CACHE_CAKEMODEL_PORT: 6379
# -- Configure passbolt cake session storage, either php, cake, database or cache
SESSION_DEFAULTS: cache
# -- Configure passbolt cake cache class
CACHE_DEFAULT_CLASSNAME: Redis
# -- Configure passbolt cake model cache class
CACHE_CAKEMODEL_CLASSNAME: Redis
# -- Configure passbolt cake core cache class
CACHE_CAKECORE_CLASSNAME: Redis
# -- Configure passbolt default email service port
EMAIL_TRANSPORT_DEFAULT_PORT: 587
# -- Toggle passbolt debug mode
DEBUG: false
# -- Configure email used on gpg key. This is used when automatically creating a new gpg server key and when automatically calculating the fingerprint.
PASSBOLT_KEY_EMAIL: passbolt@solusar.de
# -- Toggle passbolt selenium mode
PASSBOLT_SELENIUM_ACTIVE: false
# -- Configure passbolt license path
PASSBOLT_PLUGINS_LICENSE_LICENSE: /etc/passbolt/subscription_key.txt
# -- Configure passbolt default email from
EMAIL_DEFAULT_FROM: no-reply@passbolt.realm.local
# -- Configure passbolt default email from name
EMAIL_DEFAULT_FROM_NAME: Passbolt
# -- Configure passbolt default email host
EMAIL_TRANSPORT_DEFAULT_HOST: 127.0.0.1
# -- Configure passbolt default email timeout
EMAIL_TRANSPORT_DEFAULT_TIMEOUT: 30
# -- Toggle passbolt tls
EMAIL_TRANSPORT_DEFAULT_TLS: true
# -- Configure passbolt jwt private key path
PASSBOLT_JWT_SERVER_KEY: /var/www/passbolt/config/jwt/jwt.key
# -- Configure passbolt jwt public key path
PASSBOLT_JWT_SERVER_PEM: /var/www/passbolt/config/jwt/jwt.pem
# -- Toggle passbolt jwt authentication
PASSBOLT_PLUGINS_JWT_AUTHENTICATION_ENABLED: true
# -- Download Command for kubectl
KUBECTL_DOWNLOAD_CMD: ""
# -- Set to false to supress warnings when running passbolt commands as non webserver user, mainly for Openshift
PASSBOLT_SECURITY_DISPLAY_NON_WEBUSER_WARNING: true
secret:
# -- Configure passbolt cake cache password
CACHE_DEFAULT_PASSWORD: ={K=X=6UcS~s^Pa,a,
# -- Configure passbolt cake core cache password
CACHE_CAKECORE_PASSWORD: U!L9Ue%"`_-+{.u"vQ
# -- Configure passbolt cake model cache password
CACHE_CAKEMODEL_PASSWORD: V!K'_6}Q\%PSufj$eV
# -- Configure passbolt default database password
DATASOURCES_DEFAULT_PASSWORD: DW"C_/9jTTkMjwj<'%
# -- Configure passbolt default database username
DATASOURCES_DEFAULT_USERNAME: pbadmin
# -- Configure passbolt default database
DATASOURCES_DEFAULT_DATABASE: passboltdb
# -- Configure passbolt default email service username
EMAIL_TRANSPORT_DEFAULT_USERNAME: admin@solusar.de
# -- Configure passbolt default email service password
EMAIL_TRANSPORT_DEFAULT_PASSWORD: #gentoo#
# -- Configure passbolt server gpg key fingerprint
# PASSBOLT_GPG_SERVER_KEY_FINGERPRINT:
# -- Configure passbolt security salt.
# SECURITY_SALT:
# -- Environment variables to add to the passbolt pods
extraEnv: []
# -- Environment variables from secrets or configmaps to add to the passbolt pods
extraEnvFrom:
[]
# - secretRef:
# name: passbolt-secret
## Overrides the plain value in the case of not wanting to provide the config from values
## Do this ONLY if you know what you are doing
configMapName: ""
## Overrides the secrets value in the case of not wanting to provide them in the values file.
## Do this ONLY if you know what you are doing
secretName: ""
## Passbolt deployment parameters
# -- If autoscaling is disabled this will define the number of pods to run
replicaCount: 2
# Configure autoscaling on passbolt deployment
autoscaling:
# -- Enable autoscaling on passbolt deployment
enabled: false
# -- Configure autoscaling minimum replicas
minReplicas: 1
# -- Configure autoscaling maximum replicas
maxReplicas: 100
# -- Configure autoscaling target CPU uptilization percentage
targetCPUUtilizationPercentage: 80
# targetMemoryUtilizationPercentage: 80
# -- Enable role based access control
rbacEnabled: true
# -- Configure passbolt container livenessProbe
livenessProbe:
# @ignore
httpGet:
port: https
scheme: HTTPS
path: /healthcheck/status.json
httpHeaders:
- name: Host
value: passbolt.realm.local
initialDelaySeconds: 20
periodSeconds: 10
# -- Configure passbolt container RadinessProbe
readinessProbe:
# @ignore
httpGet:
port: https
scheme: HTTPS
httpHeaders:
- name: Host
value: passbolt.realm.local
path: /healthcheck/status.json
initialDelaySeconds: 5
periodSeconds: 10
# Configure network policies to allow ingress access passbolt pods
# networkPolicy defines which labels are allowed to reach to passbolt
# and which namespaces
networkPolicy:
# -- Enable network policies to allow ingress access passbolt pods
enabled: false
# -- Configure network policies label for ingress deployment
label: app.kubernetes.io/name
# -- Configure network policies podLabel for podSelector
podLabel: ingress-nginx
# -- Configure network policies namespaceLabel for namespaceSelector
namespaceLabel: ingress-nginx
# -- Configure image pull secrets
imagePullSecrets: []
# -- Value to override the chart name on default
nameOverride: ""
# -- Value to override the whole fullName
fullnameOverride: ""
serviceAccount:
# -- Specifies whether a service account should be created
create: true
# -- Annotations to add to the service account
annotations: {}
# -- Map of annotation for passbolt server pod
podAnnotations: {}
# -- Security Context configuration for passbolt server pod
podSecurityContext:
{}
# fsGroup: 2000
service:
# -- Configure passbolt service type
type: LoadBalancer
# -- Annotations to add to the service
annotations: {}
# -- Configure the service ports
ports:
# -- Configure the HTTPS port
https:
# -- Configure passbolt HTTPS service port
port: 443
# -- Configure passbolt HTTPS service targetPort
targetPort: 443
# -- Configure passbolt HTTPS service port name
name: https
http:
# -- Configure passbolt HTTP service port
port: 80
# -- Configure passbolt HTTP service targetPort
targetPort: 80
# -- Configure passbolt HTTP service port name
name: http
# -- Preference for routing traffic to endpoints that are in the same zone as the client
# trafficDistribution: "PreferSameZone"
ingress:
# -- Enable passbolt ingress
enabled: false
# -- Configure passbolt ingress annotations
annotations: {}
# -- Configure passbolt ingress class name
# className: "nginx-example"
# -- Configure passbolt ingress hosts
hosts:
# @ignored
- host: passbolt.realm.local
paths:
- path: /
port: https
pathType: ImplementationSpecific
# -- Configure passbolt ingress tls
tls:
# If autogenerate is true, the chart will generate a secret for the given hosts
# if autogenerate is false, existingSecret should be filled with an existing tls kind secret name
# @ignored
- autogenerate: true
# existingSecret: ""
hosts:
- passbolt.realm.local
# -- Configure passbolt deployment nodeSelector
nodeSelector: {}
# -- Configure passbolt deployment tolerations
tolerations: []
# -- Configure passbolt deployment affinity
affinity: {}
# -- Add additional volumes, e.g. for overwriting config files
extraVolumes: []
# -- Add additional volume mounts, e.g. for overwriting config files
extraVolumeMounts: []
# Toggle to true if deploying on Openshift
# Removes security context specifying UID from the email cronjob
# Adds a route to use
Openshift: false