File tree Expand file tree Collapse file tree 5 files changed +41
-1
lines changed
Expand file tree Collapse file tree 5 files changed +41
-1
lines changed Original file line number Diff line number Diff line change 1111 addr: 0.0.0.0:8000
1212 timeout: 1s
1313 grpc:
14+ {{- if .Values.cas.tlsConfig.secret.name }}
15+ tls_config:
16+ certificate: /data/server-certs/tls.crt
17+ private_key: /data/server-certs/tls.key
18+ {{- end }}
1419 addr: 0.0.0.0:9000
1520 timeout: 1s
1621 http_metrics:
17- addr: 0.0.0.0:5000
22+ addr: 0.0.0.0:5000
Original file line number Diff line number Diff line change 6262 - name : gcp-secretmanager-serviceaccountkey
6363 mountPath : /gcp-secrets
6464 {{- end }}
65+ {{- if .Values.cas.tlsConfig.secret.name }}
66+ - name : server-certs
67+ mountPath : /data/server-certs
68+ {{- end }}
6569 volumes :
6670 - name : config
6771 projected :
7377 - name : jwt-public-key
7478 secret :
7579 secretName : {{ include "chainloop.cas.fullname" . }}-jwt-public-key
80+ {{- if .Values.cas.tlsConfig.secret.name }}
81+ - name : server-certs
82+ secret :
83+ secretName : {{ .Values.cas.tlsConfig.secret.name }}
84+ {{- end }}
7685 {{- if eq "gcpSecretManager" .Values.secretsBackend.backend }}
7786 - name : gcp-secretmanager-serviceaccountkey
7887 secret :
Original file line number Diff line number Diff line change 2424 grpc:
2525 addr: 0.0.0.0:9000
2626 timeout: 10s
27+ {{- if .Values.controlplane.tlsConfig.secret.name }}
28+ tls_config:
29+ certificate: /data/server-certs/tls.crt
30+ private_key: /data/server-certs/tls.key
31+ {{- end }}
2732 cas_server:
2833 grpc:
2934 addr: {{ printf "%s-api:%.0f" (include "chainloop.cas.fullname" .) .Values.cas.serviceAPI.port }}
Original file line number Diff line number Diff line change 8585 mountPath : /tmp
8686 - name : jwt-cas-private-key
8787 mountPath : /secrets
88+ {{- if .Values.controlplane.tlsConfig.secret.name }}
89+ - name : server-certs
90+ mountPath : /data/server-certs
91+ {{- end }}
8892 {{- if eq "gcpSecretManager" .Values.secretsBackend.backend }}
8993 - name : gcp-secretmanager-serviceaccountkey
9094 mountPath : /gcp-secrets
@@ -103,6 +107,11 @@ spec:
103107 - name : jwt-cas-private-key
104108 secret :
105109 secretName : {{ include "chainloop.controlplane.fullname" . }}-jwt-cas
110+ {{- if .Values.controlplane.tlsConfig.secret.name }}
111+ - name : server-certs
112+ secret :
113+ secretName : {{ .Values.controlplane.tlsConfig.secret.name }}
114+ {{- end }}
106115 {{- if eq "gcpSecretManager" .Values.secretsBackend.backend }}
107116 - name : gcp-secretmanager-serviceaccountkey
108117 secret :
Original file line number Diff line number Diff line change @@ -103,6 +103,12 @@ controlplane:
103103 # Overrides the image tag whose default is the chart appVersion.
104104 # tag: latest
105105
106+ # # @param controlplane.secret.name name of a secret containing TLS certificate to be used by the controlplane grpc server.
107+ tlsConfig :
108+ secret :
109+ # the secret must contains 2 keys: tls.crt and tls.key respectively containing the certificate and private key.
110+ name : " "
111+
106112 # # @param controlplane.pluginsDir Directory where to look for plugins
107113 pluginsDir : /plugins
108114
@@ -443,6 +449,12 @@ cas:
443449 # Overrides the image tag whose default is the chart appVersion.
444450 # tag: latest
445451
452+ # # @param cas.tlsConfig.secret.name name of a secret containing TLS certificate to be used by the controlplane grpc server.
453+ tlsConfig :
454+ secret :
455+ # the secret must contains 2 keys: tls.crt and tls.key respectively containing the certificate and private key.
456+ name : " "
457+
446458 # # @skip cas.serviceAccount
447459 serviceAccount :
448460 # Specifies whether a service account should be created
You can’t perform that action at this time.
0 commit comments