mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 14:27:59 +00:00
misc: added missing helm configs
This commit is contained in:
@@ -45,11 +45,21 @@ The operator can be install via [Helm](https://helm.sh) or [kubectl](https://git
|
|||||||
|
|
||||||
The operator can be configured to watch and manage secrets in a specific namespace instead of having cluster-wide access.
|
The operator can be configured to watch and manage secrets in a specific namespace instead of having cluster-wide access.
|
||||||
|
|
||||||
|
**Note**: For multiple namespace-scoped installations, only the first installation should install CRDs. Subsequent installations should set `installCRDs: false` to avoid conflicts.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
helm install operator infisical-helm-charts/secrets-operator \
|
# First namespace installation (with CRDs)
|
||||||
--namespace your-namespace \
|
helm install operator-namespace1 infisical-helm-charts/secrets-operator \
|
||||||
--set scopedNamespace=your-namespace \
|
--namespace first-namespace \
|
||||||
|
--set scopedNamespace=first-namespace \
|
||||||
--set scopedRBAC=true
|
--set scopedRBAC=true
|
||||||
|
|
||||||
|
# Subsequent namespace installations
|
||||||
|
helm install operator-namespace2 infisical-helm-charts/secrets-operator \
|
||||||
|
--namespace another-namespace \
|
||||||
|
--set scopedNamespace=another-namespace \
|
||||||
|
--set scopedRBAC=true \
|
||||||
|
--set installCRDs=false
|
||||||
```
|
```
|
||||||
|
|
||||||
When scoped to a namespace, the operator will:
|
When scoped to a namespace, the operator will:
|
||||||
@@ -61,14 +71,19 @@ The operator can be install via [Helm](https://helm.sh) or [kubectl](https://git
|
|||||||
The default configuration gives cluster-wide access:
|
The default configuration gives cluster-wide access:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
|
installCRDs: true # Install CRDs (set to false for additional namespace installations)
|
||||||
scopedNamespace: "" # Empty for cluster-wide access
|
scopedNamespace: "" # Empty for cluster-wide access
|
||||||
scopedRBAC: false # Cluster-wide permissions
|
scopedRBAC: false # Cluster-wide permissions
|
||||||
```
|
```
|
||||||
|
|
||||||
|
If you want to install operators in multiple namespaces simultaneously:
|
||||||
|
- Make sure to set `installCRDs: false` for all but one of the installations to avoid conflicts, as CRDs are cluster-wide resources.
|
||||||
|
- Use unique release names for each installation (e.g., operator-namespace1, operator-namespace2).
|
||||||
|
|
||||||
</Tab>
|
</Tab>
|
||||||
<Tab title="Kubectl">
|
<Tab title="Kubectl">
|
||||||
For production deployments, it is highly recommended to set the version of the Kubernetes operator manually instead of pointing to the latest version.
|
For production deployments, it is highly recommended to set the version of the Kubernetes operator manually instead of pointing to the latest version.
|
||||||
Doing so will help you avoid accidental updates to the newest release which may introduce unintended breaking changes. View all application versions [here](https://hub.docker.com/r/infisical/kubernetes-operator/tags).
|
Doing so will help you avoid accidental updates to the newest release which may introduce unintended breaking changes. View all application versions [here](https://hub.docker.com/r/infisical/kubernetes-operator/tags).
|
||||||
|
|
||||||
The command below will install the most recent version of the Kubernetes operator.
|
The command below will install the most recent version of the Kubernetes operator.
|
||||||
However, to set the version manually, download the manifest and set the image tag version of `infisical/kubernetes-operator` according to your desired version.
|
However, to set the version manually, download the manifest and set the image tag version of `infisical/kubernetes-operator` according to your desired version.
|
||||||
@@ -714,6 +729,7 @@ Define secret keys and their corresponding templates.
|
|||||||
Each data value uses a Golang template with access to all secrets retrieved from the specified scope.
|
Each data value uses a Golang template with access to all secrets retrieved from the specified scope.
|
||||||
|
|
||||||
Secrets are structured as follows:
|
Secrets are structured as follows:
|
||||||
|
|
||||||
```golang
|
```golang
|
||||||
type TemplateSecret struct {
|
type TemplateSecret struct {
|
||||||
Value string `json:"value"`
|
Value string `json:"value"`
|
||||||
@@ -722,6 +738,7 @@ type TemplateSecret struct {
|
|||||||
```
|
```
|
||||||
|
|
||||||
#### Example template configuration:
|
#### Example template configuration:
|
||||||
|
|
||||||
```golang
|
```golang
|
||||||
managedSecretReference:
|
managedSecretReference:
|
||||||
secretName: managed-secret
|
secretName: managed-secret
|
||||||
@@ -733,19 +750,23 @@ type TemplateSecret struct {
|
|||||||
```
|
```
|
||||||
|
|
||||||
When you run the following command:
|
When you run the following command:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
kubectl get secret managed-secret -o jsonpath='{.data}'
|
kubectl get secret managed-secret -o jsonpath='{.data}'
|
||||||
```
|
```
|
||||||
|
|
||||||
You'll receive Kubernetes secrets output that includes the NEW_KEY:
|
You'll receive Kubernetes secrets output that includes the NEW_KEY:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
{... "KEY":"d29ybGQ=","NEW_KEY":"LyBoZWxsbw=="}
|
{... "KEY":"d29ybGQ=","NEW_KEY":"LyBoZWxsbw=="}
|
||||||
```
|
```
|
||||||
|
|
||||||
When you set `includeAllSecrets` as `false` the Kubernetes secrets outputs will be:
|
When you set `includeAllSecrets` as `false` the Kubernetes secrets outputs will be:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
{"NEW_KEY":"LyBoZWxsbw=="}
|
{"NEW_KEY":"LyBoZWxsbw=="}
|
||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="managedSecretReference.creationPolicy">
|
<Accordion title="managedSecretReference.creationPolicy">
|
||||||
Creation polices allow you to control whether or not owner references should be added to the managed Kubernetes secret that is generated by the Infisical operator.
|
Creation polices allow you to control whether or not owner references should be added to the managed Kubernetes secret that is generated by the Infisical operator.
|
||||||
|
|||||||
@@ -13,9 +13,9 @@ type: application
|
|||||||
# This is the chart version. This version number should be incremented each time you make changes
|
# This is the chart version. This version number should be incremented each time you make changes
|
||||||
# to the chart and its templates, including the app version.
|
# to the chart and its templates, including the app version.
|
||||||
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||||
version: v0.7.6
|
version: v0.7.7
|
||||||
# This is the version number of the application being deployed. This version number should be
|
# This is the version number of the application being deployed. This version number should be
|
||||||
# incremented each time you make changes to the application. Versions are not expected to
|
# incremented each time you make changes to the application. Versions are not expected to
|
||||||
# follow Semantic Versioning. They should reflect the version the application is using.
|
# follow Semantic Versioning. They should reflect the version the application is using.
|
||||||
# It is recommended to use it with quotes.
|
# It is recommended to use it with quotes.
|
||||||
appVersion: "v0.7.6"
|
appVersion: "v0.7.7"
|
||||||
|
|||||||
@@ -1,3 +1,4 @@
|
|||||||
|
{{- if .Values.installCRDs }}
|
||||||
apiVersion: apiextensions.k8s.io/v1
|
apiVersion: apiextensions.k8s.io/v1
|
||||||
kind: CustomResourceDefinition
|
kind: CustomResourceDefinition
|
||||||
metadata:
|
metadata:
|
||||||
@@ -424,4 +425,5 @@ status:
|
|||||||
kind: ""
|
kind: ""
|
||||||
plural: ""
|
plural: ""
|
||||||
conditions: []
|
conditions: []
|
||||||
storedVersions: []
|
storedVersions: []
|
||||||
|
{{- end }}
|
||||||
@@ -32,7 +32,7 @@ controllerManager:
|
|||||||
- ALL
|
- ALL
|
||||||
image:
|
image:
|
||||||
repository: infisical/kubernetes-operator
|
repository: infisical/kubernetes-operator
|
||||||
tag: v0.7.6
|
tag: v0.7.7
|
||||||
resources:
|
resources:
|
||||||
limits:
|
limits:
|
||||||
cpu: 500m
|
cpu: 500m
|
||||||
@@ -48,6 +48,7 @@ controllerManager:
|
|||||||
kubernetesClusterDomain: cluster.local
|
kubernetesClusterDomain: cluster.local
|
||||||
scopedNamespace: ""
|
scopedNamespace: ""
|
||||||
scopedRBAC: false
|
scopedRBAC: false
|
||||||
|
installCRDs: true
|
||||||
metricsService:
|
metricsService:
|
||||||
ports:
|
ports:
|
||||||
- name: https
|
- name: https
|
||||||
|
|||||||
Reference in New Issue
Block a user