mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 21:27:31 +00:00
update helm docs for self install
This commit is contained in:
@@ -24,65 +24,75 @@ Before you can deploy the Helm chart, you must fill out the required environment
|
|||||||
Refer to the available [environment variables](../../self-hosting/configuration/envars) to learn more
|
Refer to the available [environment variables](../../self-hosting/configuration/envars) to learn more
|
||||||
|
|
||||||
<Accordion title="values.yaml">
|
<Accordion title="values.yaml">
|
||||||
|
[View all available Helm chart values parameters](https://github.com/Infisical/infisical/tree/main/helm-charts/infisical)
|
||||||
```yaml
|
```yaml
|
||||||
#####
|
|
||||||
# INFISICAL K8 DEFAULT VALUES FILE
|
|
||||||
# PLEASE REPLACE VALUES/EDIT AS REQUIRED
|
|
||||||
#####
|
|
||||||
|
|
||||||
nameOverride: ""
|
|
||||||
|
|
||||||
frontend:
|
frontend:
|
||||||
|
enabled: true
|
||||||
name: frontend
|
name: frontend
|
||||||
podAnnotations: {}
|
podAnnotations: {}
|
||||||
deploymentAnnotations: {}
|
deploymentAnnotations: {}
|
||||||
replicaCount: 2
|
replicaCount: 2
|
||||||
image:
|
image:
|
||||||
repository: infisical/frontend
|
repository: infisical/frontend
|
||||||
pullPolicy: Always
|
tag: "latest"
|
||||||
tag: "latest" # It it highly recommended to select a specific tag for prod deployment so it is easy to rollback: https://hub.docker.com/r/infisical/frontend/tags
|
pullPolicy: IfNotPresent
|
||||||
# kubeSecretRef: some-kube-secret-name
|
kubeSecretRef: ""
|
||||||
service:
|
service:
|
||||||
# type of the frontend service
|
|
||||||
type: ClusterIP
|
|
||||||
# define the nodePort if service type is NodePort
|
|
||||||
# nodePort:
|
|
||||||
annotations: {}
|
annotations: {}
|
||||||
|
type: ClusterIP
|
||||||
|
nodePort: ""
|
||||||
|
|
||||||
|
frontendEnvironmentVariables:
|
||||||
|
SITE_URL: infisical.local
|
||||||
|
|
||||||
backend:
|
backend:
|
||||||
|
enabled: true
|
||||||
name: backend
|
name: backend
|
||||||
podAnnotations: {}
|
podAnnotations: {}
|
||||||
deploymentAnnotations: {}
|
deploymentAnnotations: {}
|
||||||
replicaCount: 2
|
replicaCount: 2
|
||||||
image:
|
image:
|
||||||
repository: infisical/backend
|
repository: infisical/backend
|
||||||
pullPolicy: Always
|
|
||||||
tag: "latest" # It it highly recommended to select a specific tag for prod deployment so it is easy to rollback: https://hub.docker.com/r/infisical/backend/tags
|
|
||||||
# kubeSecretRef: some-kube-secret-name
|
|
||||||
service:
|
|
||||||
annotations: {}
|
|
||||||
|
|
||||||
mongodb:
|
|
||||||
name: mongodb
|
|
||||||
podAnnotations: {}
|
|
||||||
image:
|
|
||||||
repository: mongo
|
|
||||||
pullPolicy: IfNotPresent
|
|
||||||
tag: "latest"
|
tag: "latest"
|
||||||
|
pullPolicy: IfNotPresent
|
||||||
|
kubeSecretRef: ""
|
||||||
service:
|
service:
|
||||||
annotations: {}
|
annotations: {}
|
||||||
|
type: ClusterIP
|
||||||
|
nodePort: ""
|
||||||
|
|
||||||
# By default the backend will be connected to a Mongo instance in the cluster.
|
backendEnvironmentVariables:
|
||||||
# However, it is recommended to add a managed document DB connection string because the DB instance in the cluster does not have persistence yet ( data will be deleted on next deploy).
|
ENCRYPTION_KEY: MUST_REPLACE
|
||||||
# Learn about connection string type here https://www.mongodb.com/docs/manual/reference/connection-string/
|
JWT_SIGNUP_SECRET: MUST_REPLACE
|
||||||
mongodbConnection: {}
|
JWT_REFRESH_SECRET: MUST_REPLACE
|
||||||
# externalMongoDBConnectionString: <>
|
JWT_AUTH_SECRET: MUST_REPLACE
|
||||||
|
JWT_SERVICE_SECRET: MUST_REPLACE
|
||||||
|
SMTP_HOST: MUST_REPLACE
|
||||||
|
SMTP_PORT: 587
|
||||||
|
SMTP_SECURE: false
|
||||||
|
SMTP_FROM_NAME: Infisical
|
||||||
|
SMTP_FROM_ADDRESS: MUST_REPLACE
|
||||||
|
SMTP_USERNAME: MUST_REPLACE
|
||||||
|
SMTP_PASSWORD: MUST_REPLACE
|
||||||
|
SITE_URL: infisical.local
|
||||||
|
|
||||||
|
## Mongo DB persistence
|
||||||
|
mongodb:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
## By default the backend will be connected to a Mongo instance within the cluster
|
||||||
|
## However, it is recommended to add a managed document DB connection string for production-use (DBaaS)
|
||||||
|
## Learn about connection string type here https://www.mongodb.com/docs/manual/reference/connection-string/
|
||||||
|
## e.g. "mongodb://<user>:<pass>@<host>:<port>/<database-name>"
|
||||||
|
mongodbConnection:
|
||||||
|
externalMongoDBConnectionString: ""
|
||||||
|
|
||||||
ingress:
|
ingress:
|
||||||
enabled: true
|
enabled: true
|
||||||
annotations:
|
annotations:
|
||||||
kubernetes.io/ingress.class: "nginx"
|
kubernetes.io/ingress.class: "nginx"
|
||||||
hostName: example.com # replace with your domain
|
# cert-manager.io/issuer: letsencrypt-nginx
|
||||||
|
hostName: infisical.local ## <- Replace with your own domain
|
||||||
frontend:
|
frontend:
|
||||||
path: /
|
path: /
|
||||||
pathType: Prefix
|
pathType: Prefix
|
||||||
@@ -90,48 +100,12 @@ ingress:
|
|||||||
path: /api
|
path: /api
|
||||||
pathType: Prefix
|
pathType: Prefix
|
||||||
tls: []
|
tls: []
|
||||||
|
# - secretName: letsencrypt-nginx
|
||||||
|
# hosts:
|
||||||
|
# - infisical.local
|
||||||
|
|
||||||
|
mailhog:
|
||||||
## Complete Ingress example
|
enabled: false
|
||||||
# ingress:
|
|
||||||
# enabled: true
|
|
||||||
# annotations:
|
|
||||||
# kubernetes.io/ingress.class: "nginx"
|
|
||||||
# cert-manager.io/issuer: letsencrypt-nginx
|
|
||||||
# hostName: k8.infisical.com
|
|
||||||
# frontend:
|
|
||||||
# path: /
|
|
||||||
# pathType: Prefix
|
|
||||||
# backend:
|
|
||||||
# path: /api
|
|
||||||
# pathType: Prefix
|
|
||||||
# tls:
|
|
||||||
# - secretName: letsencrypt-nginx
|
|
||||||
# hosts:
|
|
||||||
# - k8.infisical.com
|
|
||||||
|
|
||||||
###
|
|
||||||
### YOU MUST FILL IN ALL SECRETS BELOW
|
|
||||||
###
|
|
||||||
backendEnvironmentVariables:
|
|
||||||
# Required keys for platform encryption/decryption ops. Replace with nacl sk keys
|
|
||||||
ENCRYPTION_KEY: MUST_REPLACE
|
|
||||||
|
|
||||||
# JWT
|
|
||||||
# Required secrets to sign JWT tokens
|
|
||||||
JWT_SIGNUP_SECRET: MUST_REPLACE
|
|
||||||
JWT_REFRESH_SECRET: MUST_REPLACE
|
|
||||||
JWT_AUTH_SECRET: MUST_REPLACE
|
|
||||||
|
|
||||||
# Mail/SMTP
|
|
||||||
# Required to send emails
|
|
||||||
SMTP_HOST: MUST_REPLACE
|
|
||||||
SMTP_NAME: MUST_REPLACE
|
|
||||||
SMTP_USERNAME: MUST_REPLACE
|
|
||||||
SMTP_PASSWORD: MUST_REPLACE
|
|
||||||
|
|
||||||
frontendEnvironmentVariables: {}
|
|
||||||
|
|
||||||
```
|
```
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user