DirectorySecurity AdvisoriesPricing
Sign in
Directory
external-secrets logoHELM

external-secrets

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:
Compare:

1
global:
2
nodeSelector: {}
3
tolerations: []
4
topologySpreadConstraints: []
5
# - maxSkew: 1
6
# topologyKey: topology.kubernetes.io/zone
7
# whenUnsatisfiable: ScheduleAnyway
8
# matchLabelKeys:
9
# - pod-template-hash
10
# - maxSkew: 1
11
# topologyKey: kubernetes.io/hostname
12
# whenUnsatisfiable: DoNotSchedule
13
# matchLabelKeys:
14
# - pod-template-hash
15
affinity: {}
16
# -- Global hostAliases to be applied to all deployments
17
hostAliases: []
18
# -- Global pod labels to be applied to all deployments
19
podLabels: {}
20
# -- Global pod annotations to be applied to all deployments
21
podAnnotations: {}
22
# -- Global imagePullSecrets to be applied to all deployments
23
imagePullSecrets: []
24
# -- Global image repository to be applied to all deployments
25
repository: ""
26
compatibility:
27
openshift:
28
# -- Manages the securityContext properties to make them compatible with OpenShift.
29
# Possible values:
30
# auto - Apply configurations if it is detected that OpenShift is the target platform.
31
# force - Always apply configurations.
32
# disabled - No modification applied.
33
adaptSecurityContext: auto
34
replicaCount: 1
35
bitwarden-sdk-server:
36
enabled: false
37
namespaceOverride: ""
38
# -- Specifies the amount of historic ReplicaSets k8s should keep (see https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#clean-up-policy)
39
revisionHistoryLimit: 10
40
image:
41
repository: chainreg.biz/chainguard-private/external-secrets-fips
42
pullPolicy: IfNotPresent
43
# -- The image tag to use. The default is the chart appVersion.
44
tag: 2.12.0-r0@sha256:9beedc32407d9f85b95124f23daaafc8f30bc5fc57037eebb413a245825f0f4d
45
# -- The flavour of tag you want to use
46
# There are different image flavours available, like distroless and ubi.
47
# Please see GitHub release notes for image tags for these flavors.
48
# By default, the distroless image is used.
49
flavour: ""
50
# -- If set, install and upgrade CRDs through helm chart.
51
installCRDs: true
52
crds:
53
# -- If true, create CRDs for Cluster External Secret. If set to false you must also set processClusterExternalSecret: false.
54
createClusterExternalSecret: true
55
# -- If true, create CRDs for Cluster Secret Store. If set to false you must also set processClusterStore: false.
56
createClusterSecretStore: true
57
# -- If true, create CRDs for Secret Store. If set to false you must also set processSecretStore: false.
58
createSecretStore: true
59
# -- If true, create CRDs for Cluster Generator. If set to false you must also set processClusterGenerator: false.
60
createClusterGenerator: true
61
# -- If true, create CRDs for Cluster Push Secret. If set to false you must also set processClusterPushSecret: false.
62
createClusterPushSecret: true
63
# -- If true, create CRDs for Push Secret. If set to false you must also set processPushSecret: false.
64
createPushSecret: true
65
annotations: {}
66
conversion:
67
# -- Conversion is disabled by default as we stopped supporting v1alpha1.
68
enabled: false
69
# -- If true, enable v1beta1 API version serving for ExternalSecret, ClusterExternalSecret, SecretStore, and ClusterSecretStore CRDs.
70
# v1beta1 is deprecated. Only enable this for backward compatibility if you have existing v1beta1 resources.
71
# Warning: This flag will be removed on 2026.05.01.
72
unsafeServeV1Beta1: false
73
imagePullSecrets: []
74
nameOverride: ""
75
fullnameOverride: ""
76
namespaceOverride: ""
77
# -- Additional labels added to all helm chart resources.
78
commonLabels: {}
79
# -- If true, external-secrets will perform leader election between instances to ensure no more
80
# than one instance of external-secrets operates at a time.
81
# Should be enabled when replicaCount or certController.replicaCount is greater than 1.
82
leaderElect: false
83
# -- ID of the lease object used for leader election.
84
# Leave empty to use the default ('external-secrets-controller').
85
# Set to a unique value when running multiple independent ESO deployments in the same namespace.
86
# @default -- "external-secrets-controller"
87
leaderElectionID: ""
88
# -- Duration that non-leader candidates will wait to force acquire leadership.
89
# Increase this along with renewDeadline to tolerate a busy or briefly unavailable API server
90
# (for example during control plane maintenance) without churning leadership.
91
# Leave empty to use the controller default ('15s').
92
# @default -- "15s"
93
leaderElectionLeaseDuration: ""
94
# -- Duration that the acting leader will retry refreshing leadership before giving up.
95
# Must be less than leaderElectionLeaseDuration.
96
# Leave empty to use the controller default ('10s').
97
# @default -- "10s"
98
leaderElectionRenewDeadline: ""
99
# -- Duration the leader election client waits between tries of actions.
100
# Leave empty to use the controller default ('2s').
101
# @default -- "2s"
102
leaderElectionRetryPeriod: ""
103
# -- If set external secrets will filter matching
104
# Secret Stores with the appropriate controller values.
105
controllerClass: ""
106
# -- If true external secrets will use recommended kubernetes
107
# annotations as prometheus metric labels.
108
extendedMetricLabels: false
109
# -- If set external secrets are only reconciled in the
110
# provided namespace
111
scopedNamespace: ""
112
# -- If true, create scoped RBAC roles and implicitly disable cluster-scoped
113
# controllers. Scoped to scopedNamespace if set, otherwise to .Release.Namespace.
114
scopedRBAC: false
115
# -- If true the OpenShift finalizer permissions will be added to RBAC
116
openshiftFinalizers: true
117
# -- If true the system:auth-delegator ClusterRole will be added to RBAC
118
systemAuthDelegator: false
119
# -- if true, the operator will process cluster external secret. Else, it will ignore them.
120
# When enabled, this adds update/patch permissions on namespaces to handle finalizers for proper
121
# cleanup during namespace deletion, preventing race conditions with ExternalSecrets.
122
processClusterExternalSecret: true
123
# -- if true, the operator will process cluster push secret. Else, it will ignore them.
124
processClusterPushSecret: true
125
# -- if true, the operator will process cluster store. Else, it will ignore them.
126
processClusterStore: true
127
# -- if true, the operator will process secret store. Else, it will ignore them.
128
processSecretStore: true
129
# -- Default time duration between reconciling (Cluster)SecretStores.
130
storeRequeueInterval: ""
131
# -- if true, the operator will process cluster generator. Else, it will ignore them.
132
processClusterGenerator: true
133
# -- if true, the operator will process push secret. Else, it will ignore them.
134
processPushSecret: true
135
# -- Enable support for generic targets (ConfigMaps, Custom Resources).
136
# Warning: Using generic target. Make sure access policies and encryption are properly configured.
137
# When enabled, this grants the controller permissions to create/update/delete
138
# ConfigMaps and optionally other resource types specified in generic.resources.
139
genericTargets:
140
# -- Enable generic target support
141
enabled: false
142
# -- List of additional resource types to grant permissions for.
143
# Each entry should specify apiGroup, resources, and verbs.
144
# Example:
145
# resources:
146
# - apiGroup: "argoproj.io"
147
# resources: ["applications"]
148
# verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
149
resources: []
150
# -- Specifies whether an external secret operator deployment be created.
151
createOperator: true
152
# -- if true, HTTP2 will be enabled for the services created by all controllers, curently metrics and webhook.
153
enableHTTP2: false
154
# -- TLS security profile settings applied to all controller, webhook, and certController deployments.
155
# These can be overridden per-component via webhook.tls and certController.tls.
156
tls:
157
# -- Minimum TLS version supported (e.g. "1.2" or "1.3"). If empty, the Go CLI default applies.
158
# +docs:property
159
minVersion: ""
160
# -- Comma-separated list of TLS cipher suites (TLS_CIPHER_SUITE names).
161
# Does not apply to TLS 1.3. If empty, Go defaults apply.
162
# +docs:property
163
ciphers: ""
164
# -- Ordered list of TLS key exchange curves (e.g. X25519, CurveP256, or decimal CurveID).
165
# If empty, Go defaults apply.
166
# +docs:property
167
curvePreferences: []
168
# -- Vault token cache configuration
169
vault:
170
# -- Enable Vault token cache. External secrets will reuse the Vault token without creating a new one on each request.
171
enableTokenCache: false
172
# -- Maximum size of Vault token cache. Only used if enableTokenCache is true.
173
tokenCacheSize: 262144
174
# -- Specifies the number of concurrent ExternalSecret Reconciles external-secret executes at
175
# a time.
176
concurrent: 1
177
# -- Specifies Log Params to the External Secrets Operator
178
log:
179
level: info
180
timeEncoding: epoch
181
service:
182
# -- Set the ip family policy to configure dual-stack see [Configure dual-stack](https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services)
183
ipFamilyPolicy: ""
184
# -- Sets the families that should be supported and the order in which they should be applied to ClusterIP as well. Can be IPv4 and/or IPv6.
185
ipFamilies: []
186
serviceAccount:
187
# -- Specifies whether a service account should be created.
188
create: true
189
# -- Automounts the service account token in all containers of the pod
190
automount: true
191
# -- Annotations to add to the service account.
192
annotations: {}
193
# -- Extra Labels to add to the service account.
194
extraLabels: {}
195
# -- The name of the service account to use.
196
# If not set and create is true, a name is generated using the fullname template.
197
name: ""
198
rbac:
199
# -- Specifies whether role and rolebinding resources should be created.
200
create: true
201
# -- Specifies whether the namespaced leader election Role and RoleBinding are created.
202
# These are only used when leaderElect is true; set to false to omit them when running
203
# without leader election. Only takes effect when rbac.create is true.
204
leaderElection:
205
create: true
206
# -- Specifies whether the serviceaccounts/token create permission is included in the controller RBAC.
207
# When set to false, users must create per-ServiceAccount Role/RoleBinding with resourceNames constraint
208
# to grant ESO token creation for specific ServiceAccounts referenced in SecretStore specs.
209
serviceAccountTokenCreate: true
210
servicebindings:
211
# -- Specifies whether a clusterrole to give servicebindings read access should be created.
212
create: true
213
# -- Specifies whether permissions are aggregated to the view ClusterRole
214
aggregateToView: true
215
# -- Specifies whether permissions are aggregated to the edit ClusterRole
216
aggregateToEdit: true
217
# -- Specifies whether permissions are aggregated to the admin ClusterRole
218
aggregateToAdmin: true
219
## -- Extra environment variables to add to container.
220
extraEnv: []
221
## -- Map of extra arguments to pass to container.
222
extraArgs: {}
223
## -- Extra volumes to pass to pod.
224
extraVolumes: []
225
## -- Extra Kubernetes objects to deploy with the helm chart
226
extraObjects: []
227
## -- Extra volumes to mount to the container.
228
extraVolumeMounts: []
229
## -- Extra init containers to add to the pod.
230
extraInitContainers: []
231
## -- Extra containers to add to the pod.
232
extraContainers: []
233
# -- Annotations to add to Deployment
234
deploymentAnnotations: {}
235
# -- Set deployment strategy
236
strategy: {}
237
# -- Annotations to add to Pod
238
podAnnotations: {}
239
podLabels: {}
240
podSecurityContext:
241
enabled: true
242
# fsGroup: 2000
243
securityContext:
244
allowPrivilegeEscalation: false
245
capabilities:
246
drop:
247
- ALL
248
enabled: true
249
readOnlyRootFilesystem: true
250
runAsNonRoot: true
251
runAsUser: 1000
252
seccompProfile:
253
type: RuntimeDefault
254
resources: {}
255
# requests:
256
# cpu: 10m
257
# memory: 32Mi
258
259
serviceMonitor:
260
# -- Specifies whether to create a ServiceMonitor resource for collecting Prometheus metrics
261
enabled: false
262
# -- How should we react to missing CRD "`monitoring.coreos.com/v1/ServiceMonitor`"
263
#
264
# Possible values:
265
# - `skipIfMissing`: Only render ServiceMonitor resources if CRD is present, skip if missing.
266
# - `failIfMissing`: Fail Helm install if CRD is not present.
267
# - `alwaysRender` : Always render ServiceMonitor resources, do not check for CRD.
268
269
# @schema
270
# enum:
271
# - skipIfMissing
272
# - failIfMissing
273
# - alwaysRender
274
# @schema
275
renderMode: skipIfMissing # @schema enum: [skipIfMissing, failIfMissing, alwaysRender]
276
# -- namespace where you want to install ServiceMonitors
277
namespace: ""
278
# -- Additional labels
279
additionalLabels: {}
280
# -- Interval to scrape metrics
281
interval: 30s
282
# -- Timeout if metrics can't be retrieved in given time interval
283
scrapeTimeout: 25s
284
# -- Let prometheus add an exported_ prefix to conflicting labels
285
honorLabels: false
286
# -- Metric relabel configs to apply to samples before ingestion. [Metric Relabeling](https://prometheus.io/docs/prometheus/latest/configuration/configuration/#metric_relabel_configs)
287
metricRelabelings: []
288
# - action: replace
289
# regex: (.*)
290
# replacement: $1
291
# sourceLabels:
292
# - exported_namespace
293
# targetLabel: namespace
294
295
# -- Relabel configs to apply to samples before ingestion. [Relabeling](https://prometheus.io/docs/prometheus/latest/configuration/configuration/#relabel_config)
296
relabelings: []
297
# - sourceLabels: [__meta_kubernetes_pod_node_name]
298
# separator: ;
299
# regex: ^(.*)$
300
# targetLabel: nodename
301
# replacement: $1
302
# action: replace
303
metrics:
304
listen:
305
port: 8080
306
auth:
307
# -- Enable Kubernetes RBAC-based authentication for metrics endpoint. Requires metrics.listen.secure to be true. Default value is false.
308
enabled: false
309
secure:
310
enabled: false
311
# -- if those are not set or invalid, self-signed certs will be generated
312
# -- TLS cert directory path
313
certDir: /etc/tls
314
# -- TLS cert file path
315
certFile: /etc/tls/tls.crt
316
# -- TLS key file path
317
keyFile: /etc/tls/tls.key
318
service:
319
# -- Enable if you use another monitoring tool than Prometheus to scrape the metrics
320
enabled: false
321
# -- Metrics service port to scrape
322
port: 8080
323
# -- Additional service annotations
324
annotations: {}
325
grafanaDashboard:
326
# -- If true creates a Grafana dashboard.
327
enabled: false
328
# -- Namespace where the dashboard ConfigMap should be created.
329
# Resolution order: grafanaDashboard.namespace, then namespaceOverride, then the release namespace.
330
namespace: ""
331
# -- Label that ConfigMaps should have to be loaded as dashboards.
332
sidecarLabel: "grafana_dashboard"
333
# -- Label value that ConfigMaps should have to be loaded as dashboards.
334
sidecarLabelValue: "1"
335
# -- Annotations that ConfigMaps can have to get configured in Grafana,
336
# See: sidecar.dashboards.folderAnnotation for specifying the dashboard folder.
337
# https://github.com/grafana/helm-charts/tree/main/charts/grafana
338
annotations: {}
339
# -- Extra labels to add to the Grafana dashboard ConfigMap.
340
extraLabels: {}
341
livenessProbe:
342
# -- Enabled determines if the liveness probe should be used or not. By default it's disabled.
343
enabled: false
344
# -- The body of the liveness probe settings.
345
spec:
346
# -- Bind address for the health server used by both liveness and readiness probes (--live-addr flag).
347
address: ""
348
# -- Port for the health server used by both liveness and readiness probes (--live-addr flag).
349
port: 8082
350
# -- Specify the maximum amount of time to wait for a probe to respond before considering it fails.
351
timeoutSeconds: 5
352
# -- Number of consecutive probe failures that should occur before considering the probe as failed.
353
failureThreshold: 5
354
# -- Period in seconds for K8s to start performing probes.
355
periodSeconds: 10
356
# -- Number of successful probes to mark probe successful.
357
successThreshold: 1
358
# -- Delay in seconds for the container to start before performing the initial probe.
359
initialDelaySeconds: 10
360
# -- Handler for liveness probe.
361
httpGet:
362
# -- Set this value to 'live' (for named port) or an an integer for liveness probes.
363
# @schema type: [string, integer]
364
port: live
365
# -- Path for liveness probe.
366
path: /healthz
367
readinessProbe:
368
# -- Determines whether the readiness probe is enabled. Disabled by default. Enabling this will auto-start the health server (--live-addr) even if livenessProbe is disabled. Health server address/port are configured via livenessProbe.spec.address and livenessProbe.spec.port.
369
enabled: false
370
# -- The body of the readiness probe settings (standard Kubernetes probe spec).
371
spec:
372
# -- Specify the maximum amount of time to wait for a probe to respond before considering it fails.
373
timeoutSeconds: 5
374
# -- Number of consecutive probe failures that should occur before considering the probe as failed.
375
failureThreshold: 3
376
# -- Period in seconds for K8s to start performing probes.
377
periodSeconds: 10
378
# -- Number of successful probes to mark probe successful.
379
successThreshold: 1
380
# -- Delay in seconds for the container to start before performing the initial probe.
381
initialDelaySeconds: 10
382
# -- Handler for readiness probe.
383
httpGet:
384
# -- Set this value to 'live' (for named port) or an integer for readiness probes.
385
# @schema type: [string, integer]
386
port: live
387
# -- Path for readiness probe.
388
path: /readyz
389
nodeSelector: {}
390
tolerations: []
391
topologySpreadConstraints: []
392
affinity: {}
393
# -- Pod priority class name.
394
priorityClassName: ""
395
# -- Pod scheduler name.
396
schedulerName: ""
397
# -- Pod runtime class name.
398
runtimeClassName: ""
399
# -- Pod disruption budget - for more details see https://kubernetes.io/docs/concepts/workloads/pods/disruptions/
400
podDisruptionBudget:
401
enabled: false
402
minAvailable: 1 # @schema type:[integer, string]
403
nameOverride: ""
404
# maxUnavailable: "50%"
405
# -- Run the controller on the host network
406
hostNetwork: false
407
# -- (bool) Specifies if controller pod should use hostUsers or not. If hostNetwork is true, hostUsers should be too. Only available in Kubernetes ≥ 1.33.
408
# @schema type: [boolean, null]
409
hostUsers:
410
# -- Setup a networkPolicy for external-secrets
411
networkPolicy:
412
# -- Specifies whether the networkPolicy should be created.
413
enabled: false
414
# -- The ingress traffic
415
# Should match the health and (optionally) metrics port
416
ingress:
417
- ports:
418
- protocol: TCP
419
# @schema type: [string, integer]
420
port: 8080 # metrics port
421
- protocol: TCP
422
# @schema type: [string, integer]
423
port: 8082 # health port
424
# -- The egress traffic
425
# The minimum egress ports required to function are:
426
# DNS (53/udp, 53/tcp)
427
# API server (80/tcp, 443/tcp, or 6443/tcp)
428
# You will need to customize this value to meet your needs
429
egress: []
430
webhook:
431
# -- Annotations to place on validating webhook configuration.
432
annotations: {}
433
# -- Specifies whether a webhook deployment be created. If set to false, crds.conversion.enabled should also be set to false otherwise the kubeapi will be hammered because the conversion is looking for a webhook endpoint.
434
create: true
435
# -- Specifies the time to check if the cert is valid
436
certCheckInterval: "5m"
437
# -- Specifies the lookaheadInterval for certificate validity
438
lookaheadInterval: ""
439
replicaCount: 1
440
# -- Specifies Log Params to the Webhook
441
log:
442
level: info
443
timeEncoding: epoch
444
# -- Specifies the amount of historic ReplicaSets k8s should keep (see https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#clean-up-policy)
445
revisionHistoryLimit: 10
446
certDir: /tmp/certs
447
# -- Webhook-specific TLS security profile overrides.
448
# When set, these override the global tls.* values for the webhook deployment.
449
tls:
450
# -- Minimum TLS version supported (e.g. "1.2" or "1.3"). If empty, the global tls.minVersion is used.
451
# +docs:property
452
minVersion: ""
453
# -- Comma-separated list of TLS cipher suites. If empty, the global tls.ciphers is used.
454
# +docs:property
455
ciphers: ""
456
# -- Ordered list of TLS key exchange curves. If empty, the global tls.curvePreferences is used.
457
# +docs:property
458
curvePreferences: []
459
# -- Specifies whether validating webhooks should be created with failurePolicy: Fail or Ignore
460
failurePolicy: Fail
461
# -- Specifies if webhook pod should use hostNetwork or not.
462
hostNetwork: false
463
# -- (bool) Specifies if webhook pod should use hostUsers or not. If hostNetwork is true, hostUsers should be too. Only available in Kubernetes ≥ 1.33.
464
# @schema type: [boolean, null]
465
hostUsers:
466
# -- Setup a networkPolicy for external-secrets webhook
467
networkPolicy:
468
# -- Specifies whether the networkPolicy should be created.
469
enabled: false
470
# -- The ingress traffic
471
# Should match the webhook, health, and (optionally) metrics port
472
ingress:
473
- ports:
474
- protocol: TCP
475
# @schema type: [string, integer]
476
port: 8080 # metrics port
477
- protocol: TCP
478
# @schema type: [string, integer]
479
port: 8081 # health port
480
- protocol: TCP
481
# @schema type: [string, integer]
482
port: 10250 # webhook port
483
# -- The egress traffic
484
# The minimum egress ports required to function are:
485
# DNS (53/udp, 53/tcp)
486
# API server (80/tcp, 443/tcp, or 6443/tcp)
487
# You will need to customize this value to meet your needs
488
egress: []
489
image:
490
repository: chainreg.biz/chainguard-private/external-secrets-fips
491
pullPolicy: IfNotPresent
492
# -- The image tag to use. The default is the chart appVersion.
493
tag: 2.12.0-r0@sha256:9beedc32407d9f85b95124f23daaafc8f30bc5fc57037eebb413a245825f0f4d
494
# -- The flavour of tag you want to use
495
flavour: ""
496
imagePullSecrets: []
497
# -- The port the webhook will listen to
498
port: 10250
499
serviceAccount:
500
# -- Specifies whether a service account should be created.
501
create: true
502
# -- Automounts the service account token in all containers of the pod
503
automount: true
504
# -- Annotations to add to the service account.
505
annotations: {}
506
# -- Extra Labels to add to the service account.
507
extraLabels: {}
508
# -- The name of the service account to use.
509
# If not set and create is true, a name is generated using the fullname template.
510
name: ""
511
nodeSelector: {}
512
# -- Specifies `hostAliases` to webhook deployment
513
hostAliases: []
514
certManager:
515
# -- Enabling cert-manager support will disable the built in secret and
516
# switch to using cert-manager (installed separately) to automatically issue
517
# and renew the webhook certificate. This chart does not install
518
# cert-manager for you, See https://cert-manager.io/docs/
519
enabled: false
520
# -- Automatically add the cert-manager.io/inject-ca-from annotation to the
521
# webhooks and CRDs. As long as you have the cert-manager CA Injector
522
# enabled, this will automatically setup your webhook's CA to the one used
523
# by cert-manager. See https://cert-manager.io/docs/concepts/ca-injector
524
addInjectorAnnotations: true
525
cert:
526
# -- Create a certificate resource within this chart. See
527
# https://cert-manager.io/docs/usage/certificate/
528
create: true
529
# -- For the Certificate created by this chart, setup the issuer. See
530
# https://cert-manager.io/docs/reference/api-docs/#cert-manager.io/v1.IssuerSpec
531
issuerRef:
532
group: cert-manager.io
533
kind: "Issuer"
534
name: "my-issuer"
535
# -- Set the requested duration (i.e. lifetime) of the Certificate. See
536
# https://cert-manager.io/docs/reference/api-docs/#cert-manager.io/v1.CertificateSpec
537
# One year by default.
538
duration: "8760h0m0s"
539
# -- Set the revisionHistoryLimit on the Certificate. See
540
# https://cert-manager.io/docs/reference/api-docs/#cert-manager.io/v1.CertificateSpec
541
# Defaults to 0 (ignored).
542
revisionHistoryLimit: 0
543
# -- How long before the currently issued certificate’s expiry
544
# cert-manager should renew the certificate. See
545
# https://cert-manager.io/docs/reference/api-docs/#cert-manager.io/v1.CertificateSpec
546
# Note that renewBefore should be greater than .webhook.lookaheadInterval
547
# since the webhook will check this far in advance that the certificate is
548
# valid.
549
renewBefore: ""
550
# -- Specific settings on the privateKey and its generation
551
privateKey: {}
552
# rotationPolicy: Always
553
# algorithm: RSA
554
# size: 2048
555
# -- Specific settings on the signatureAlgorithm used on the cert.
556
# signatureAlgorithm is only valid for cert-manager v1.18.0+
557
signatureAlgorithm: ""
558
# -- Add extra annotations to the Certificate resource.
559
annotations: {}
560
tolerations: []
561
topologySpreadConstraints: []
562
affinity: {}
563
# -- Set deployment strategy
564
strategy: {}
565
# -- Pod priority class name.
566
priorityClassName: ""
567
# -- Pod scheduler name.
568
schedulerName: ""
569
# -- Pod runtime class name.
570
runtimeClassName: ""
571
# -- Pod disruption budget - for more details see https://kubernetes.io/docs/concepts/workloads/pods/disruptions/
572
podDisruptionBudget:
573
enabled: false
574
minAvailable: 1 # @schema type:[integer, string]
575
nameOverride: ""
576
# maxUnavailable: "50%"
577
metrics:
578
listen:
579
port: 8080
580
auth:
581
# -- Enable Kubernetes RBAC-based authentication for webhook's metrics endpoint. Requires webhook.metrics.listen.secure to be true. Default value is false.
582
enabled: false
583
secure:
584
enabled: false
585
# -- if those are not set or invalid, self-signed certs will be generated
586
# -- TLS cert directory path
587
certDir: /etc/tls
588
# -- TLS cert file path
589
certFile: /etc/tls/tls.crt
590
# -- TLS key file path
591
keyFile: /etc/tls/tls.key
592
service:
593
# -- Enable if you use another monitoring tool than Prometheus to scrape the metrics
594
enabled: false
595
# -- Metrics service port to scrape
596
port: 8080
597
# -- Additional service annotations
598
annotations: {}
599
livenessProbe:
600
enabled: false
601
# -- Set this value to 'live' (for named port) or an integer for liveness probes.
602
# @schema type: [string, integer]
603
port: 8081
604
timeoutSeconds: 5
605
failureThreshold: 5
606
periodSeconds: 10
607
successThreshold: 1
608
initialDelaySeconds: 10
609
readinessProbe:
610
enabled: true
611
address: ""
612
# -- Set this value to 'ready' (for named port) or an integer for readiness probes.
613
# @schema type: [string, integer]
614
port: 8081
615
timeoutSeconds: 5
616
failureThreshold: 3
617
periodSeconds: 5
618
successThreshold: 1
619
initialDelaySeconds: 20
620
startupProbe:
621
# -- Enabled determines if the startup probe should be used or not. By default it's disabled.
622
enabled: false
623
# -- Number of seconds after the container has started before the startup probe is initiated.
624
initialDelaySeconds: 10
625
# -- How often (in seconds) to perform the startup probe.
626
periodSeconds: 10
627
# -- Number of consecutive failures before the container is restarted. The startup window is initialDelaySeconds + failureThreshold * periodSeconds.
628
failureThreshold: 30
629
## -- Extra environment variables to add to container.
630
extraEnv: []
631
## -- Map of extra arguments to pass to container.
632
extraArgs: {}
633
## -- Extra init containers to add to the pod.
634
extraInitContainers: []
635
## -- Extra volumes to pass to pod.
636
extraVolumes: []
637
## -- Extra volumes to mount to the container.
638
extraVolumeMounts: []
639
# -- Annotations to add to Secret
640
secretAnnotations: {}
641
# -- Annotations to add to Deployment
642
deploymentAnnotations: {}
643
# -- Annotations to add to Pod
644
podAnnotations: {}
645
podLabels: {}
646
podSecurityContext:
647
enabled: true
648
# fsGroup: 2000
649
securityContext:
650
allowPrivilegeEscalation: false
651
capabilities:
652
drop:
653
- ALL
654
enabled: true
655
readOnlyRootFilesystem: true
656
runAsNonRoot: true
657
runAsUser: 1000
658
seccompProfile:
659
type: RuntimeDefault
660
resources: {}
661
# requests:
662
# cpu: 10m
663
# memory: 32Mi
664
665
# -- Manage the service through which the webhook is reached.
666
service:
667
# -- Whether the service object should be enabled or not (it is expected to exist).
668
enabled: true
669
# -- Custom annotations for the webhook service.
670
annotations: {}
671
# -- Custom labels for the webhook service.
672
labels: {}
673
# -- The service type of the webhook service.
674
type: ClusterIP
675
# -- If the webhook service type is LoadBalancer, you can assign a specific load balancer IP here.
676
# Check the documentation of your load balancer provider to see if/how this should be used.
677
loadBalancerIP: ""
678
certController:
679
# -- Specifies whether a certificate controller deployment be created.
680
create: true
681
requeueInterval: "5m"
682
replicaCount: 1
683
# -- Restrict the cert controller's informer cache to CustomResourceDefinitions and
684
# ValidatingWebhookConfigurations carrying the `external-secrets.io/component` label.
685
# Disable this only if the CRDs it manages were installed without that label.
686
enablePartialCache: true
687
# -- Specifies Log Params to the Certificate Controller
688
log:
689
level: info
690
timeEncoding: epoch
691
# -- Specifies the amount of historic ReplicaSets k8s should keep (see https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#clean-up-policy)
692
revisionHistoryLimit: 10
693
# -- CertController-specific TLS security profile overrides.
694
# When set, these override the global tls.* values for the cert-controller deployment.
695
tls:
696
# -- Minimum TLS version supported (e.g. "1.2" or "1.3"). If empty, the global tls.minVersion is used.
697
# +docs:property
698
minVersion: ""
699
# -- Comma-separated list of TLS cipher suites. If empty, the global tls.ciphers is used.
700
# +docs:property
701
ciphers: ""
702
# -- Ordered list of TLS key exchange curves. If empty, the global tls.curvePreferences is used.
703
# +docs:property
704
curvePreferences: []
705
image:
706
repository: chainreg.biz/chainguard-private/external-secrets-fips
707
pullPolicy: IfNotPresent
708
tag: 2.12.0-r0@sha256:9beedc32407d9f85b95124f23daaafc8f30bc5fc57037eebb413a245825f0f4d
709
flavour: ""
710
imagePullSecrets: []
711
rbac:
712
# -- Specifies whether role and rolebinding resources should be created.
713
create: true
714
serviceAccount:
715
# -- Specifies whether a service account should be created.
716
create: true
717
# -- Automounts the service account token in all containers of the pod
718
automount: true
719
# -- Annotations to add to the service account.
720
annotations: {}
721
# -- Extra Labels to add to the service account.
722
extraLabels: {}
723
# -- The name of the service account to use.
724
# If not set and create is true, a name is generated using the fullname template.
725
name: ""
726
nodeSelector: {}
727
# -- Specifies `hostAliases` to cert-controller deployment
728
hostAliases: []
729
tolerations: []
730
topologySpreadConstraints: []
731
affinity: {}
732
# -- Set deployment strategy
733
strategy: {}
734
# -- Run the certController on the host network
735
hostNetwork: false
736
# -- (bool) Specifies if certController pod should use hostUsers or not. If hostNetwork is true, hostUsers should be too. Only available in Kubernetes ≥ 1.33.
737
# @schema type: [boolean, null]
738
hostUsers:
739
# -- Setup a networkPolicy for external-secrets certController
740
networkPolicy:
741
# -- Specifies whether the networkPolicy should be created.
742
enabled: false
743
# -- The ingress traffic
744
# Should match the health and (optionally) metrics port
745
ingress:
746
- ports:
747
- protocol: TCP
748
# @schema type: [string, integer]
749
port: 8080 # metrics port
750
- protocol: TCP
751
# @schema type: [string, integer]
752
port: 8081 # health port
753
# -- The egress traffic
754
# The minimum egress ports required to function are:
755
# DNS (53/udp, 53/tcp)
756
# API server (80/tcp, 443/tcp, or 6443/tcp)
757
# You will need to customize this value to meet your needs
758
egress: []
759
# -- Pod priority class name.
760
priorityClassName: ""
761
# -- Pod scheduler name.
762
schedulerName: ""
763
# -- Pod runtime class name.
764
runtimeClassName: ""
765
# -- Pod disruption budget - for more details see https://kubernetes.io/docs/concepts/workloads/pods/disruptions/
766
podDisruptionBudget:
767
enabled: false
768
minAvailable: 1 # @schema type:[integer, string]
769
nameOverride: ""
770
# maxUnavailable: "50%"
771
metrics:
772
listen:
773
port: 8080
774
auth:
775
# -- Enable Kubernetes RBAC-based authentication for certController's metrics endpoint. Requires certController.metrics.listen.secure to be true. Default value is false.
776
enabled: false
777
secure:
778
enabled: false
779
# -- if those are not set or invalid, self-signed certs will be generated
780
# -- TLS cert directory path
781
certDir: /etc/tls
782
# -- TLS cert file path
783
certFile: /etc/tls/tls.crt
784
# -- TLS key file path
785
keyFile: /etc/tls/tls.key
786
service:
787
# -- Enable if you use another monitoring tool than Prometheus to scrape the metrics
788
enabled: false
789
# -- Metrics service port to scrape
790
port: 8080
791
# -- Additional service annotations
792
annotations: {}
793
livenessProbe:
794
enabled: false
795
# -- Set this value to 'live' (for named port) or an integer for liveness probes.
796
# @schema type: [string, integer]
797
port: 8081
798
timeoutSeconds: 5
799
failureThreshold: 5
800
periodSeconds: 10
801
successThreshold: 1
802
initialDelaySeconds: 10
803
readinessProbe:
804
enabled: true
805
address: ""
806
# -- Set this value to 'ready' (for named port) or an integer for readiness probes.
807
# @schema type: [string, integer]
808
port: 8081
809
timeoutSeconds: 5
810
failureThreshold: 3
811
periodSeconds: 5
812
successThreshold: 1
813
initialDelaySeconds: 20
814
startupProbe:
815
# -- Enabled determines if the startup probe should be used or not. By default it's disabled.
816
enabled: false
817
# -- Number of seconds after the container has started before the startup probe is initiated.
818
initialDelaySeconds: 10
819
# -- How often (in seconds) to perform the startup probe.
820
periodSeconds: 10
821
# -- Number of consecutive failures before the container is restarted. The startup window is initialDelaySeconds + failureThreshold * periodSeconds.
822
failureThreshold: 30
823
## -- Extra environment variables to add to container.
824
extraEnv: []
825
## -- Map of extra arguments to pass to container.
826
extraArgs: {}
827
## -- Extra init containers to add to the pod.
828
extraInitContainers: []
829
## -- Extra volumes to pass to pod.
830
extraVolumes: []
831
## -- Extra volumes to mount to the container.
832
extraVolumeMounts: []
833
# -- Annotations to add to Deployment
834
deploymentAnnotations: {}
835
# -- Annotations to add to Pod
836
podAnnotations: {}
837
podLabels: {}
838
podSecurityContext:
839
enabled: true
840
# fsGroup: 2000
841
securityContext:
842
allowPrivilegeEscalation: false
843
capabilities:
844
drop:
845
- ALL
846
enabled: true
847
readOnlyRootFilesystem: true
848
runAsNonRoot: true
849
runAsUser: 1000
850
seccompProfile:
851
type: RuntimeDefault
852
resources: {}
853
# requests:
854
# cpu: 10m
855
# memory: 32Mi
856
# -- Specifies `dnsPolicy` to deployment
857
dnsPolicy: ClusterFirst
858
# -- Specifies `dnsOptions` to deployment
859
dnsConfig: {}
860
# -- Specifies `hostAliases` to deployment
861
hostAliases: []
862
# -- Any extra pod spec on the deployment
863
podSpecExtra: {}
864

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.