1# "_internal_defaults_do_not_set" is a workaround for Helm limitations. Users should NOT set "._internal_defaults_do_not_set" explicitly, but rather directly set the fields internally.
2# For instance, instead of `--set _internal_defaults_do_not_set.foo=bar``, just set `--set foo=bar`.
3image: istio-install-cni
5 hub: chainreg.biz/chainguard-private
6 tag: 1.31.1-r2@sha256:aab0a1b8b275c079ffd5e1765f8c55673d00b13f6c51a837f9243f4240150412
8_internal_defaults_do_not_set:
14 # Same as `global.logging.level`, but will override it if set
17 # Configuration file to insert istio-cni plugin configuration
18 # by default this will be the first file found in the cni-conf-dir
20 # cniConfFileName: 10-calico.conflist
22 # CNI-and-platform specific path defaults.
23 # These may need to be set to platform-specific values, consult
24 # overrides for your platform in `manifests/helm-profiles/platform-*.yaml`
25 cniBinDir: /opt/cni/bin
26 cniConfDir: /etc/cni/net.d
28 cniNetnsDir: "/var/run/netns"
29 # If Istio owned CNI config is enabled, defaults to 02-istio-cni.conflist
30 istioOwnedCNIConfigFileName: ""
31 istioOwnedCNIConfig: false
34 # Allows user to set custom affinity for the DaemonSet
36 # Additional labels to apply on the daemonset level
38 # Custom annotations on pod level, if you need them
40 # Additional labels to apply on the pod level
42 # Deploy the config files as plugin chain (value "true") or as standalone files in the conf dir (value "false")?
43 # Some k8s flavors (e.g. OpenShift) do not support the chain approach, set to false if this is the case
45 # Custom configuration happens based on the CNI provider.
46 # Possible values: "default", "multus"
48 # Configure ambient settings
50 # If enabled, ambient redirection will be enabled
52 # If ambient is enabled, this selector will be used to identify the ambient-enabled pods
55 matchLabels: {istio.io/dataplane-mode: ambient}
58 - {key: istio.io/dataplane-mode, operator: NotIn, values: [none]}
60 matchLabels: {istio.io/dataplane-mode: ambient}
61 # Set ambient config dir path: defaults to /etc/ambient-config
63 # If enabled, and ambient is enabled, DNS redirection will be enabled
65 # If enabled, and ambient is enabled, enables ipv6 support
67 # If enabled, and ambient is enabled, the CNI agent will reconcile incompatible iptables rules and chains at startup.
68 # This is enabled by default
69 reconcileIptablesOnStartup: true
70 # If enabled, and ambient is enabled, the CNI agent will always share the network namespace of the host node it is running on
71 shareHostNetworkNamespace: false
72 # If enabled, the CNI agent will retry checking if a pod is ambient enabled when there are errors
73 enableAmbientDetectionRetry: false
78 # Repair controller has 3 modes. Pick which one meets your use cases. Note only one may be used.
79 # This defines the action the controller will take when a pod is detected as broken.
81 # labelPods will label all pods with <brokenPodLabelKey>=<brokenPodLabelValue>.
82 # This is only capable of identifying broken pods; the user is responsible for fixing them (generally, by deleting them).
83 # Note this gives the DaemonSet a relatively high privilege, as modifying pod metadata/status can have wider impacts.
85 # deletePods will delete any broken pod. These will then be rescheduled, hopefully onto a node that is fully ready.
86 # Note this gives the DaemonSet a relatively high privilege, as it can delete any Pod.
88 # repairPods will dynamically repair any broken pod by setting up the pod networking configuration even after it has started.
89 # Note the pod will be crashlooping, so this may take a few minutes to become fully functional based on when the retry occurs.
90 # This requires no RBAC privilege, but does require `securityContext.privileged/CAP_SYS_ADMIN`.
92 initContainerName: "istio-validation"
93 brokenPodLabelKey: "cni.istio.io/uninitialized"
94 brokenPodLabelValue: "true"
95 # Set to `type: RuntimeDefault` to use the default profile if available.
97 # SELinux options to set in the istio-cni-node pods. You may need to set this to `type: spc_t` for some platforms.
99 # Use `useAppArmorAnnotation: true` to set up appArmor profile via `container.apparmor.security.beta.kubernetes.io` annotation.
100 # This is required for Kubernetes 1.29 (and earlier) which does not support setting appArmorProfile in the
101 # securityContext. Otherwise, appArmor profile will be set via appArmorProfile setting in securityContext.
102 useAppArmorAnnotation: true
111 # Make sure istio-cni-node gets scheduled on all nodes.
114 # Mark the pod as a critical add-on for rescheduling.
115 - key: CriticalAddonsOnly
119 # K8s DaemonSet update strategy.
120 # https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/daemon-set-v1/#DaemonSetSpec).
125 # Sets the per-pod terminationGracePeriodSeconds setting.
126 # A higher value gives more time for CNI cleanup during rolling updates,
127 # preventing "failed to find plugin istio-cni" errors.
128 # Default K8s value is 30 seconds.
129 terminationGracePeriodSeconds: 30
130 # Revision is set as 'version' label and part of the resource names when installing multiple control planes.
132 # For Helm compatibility.
135 # Default hub for Istio images.
136 # Releases are published to docker hub under 'istio' project.
137 # Dev builds from prow are on registry.istio.io/testing
138 hub: registry.istio.io/testing
139 # Default tag for Istio images.
141 # Variant of the image to use.
142 # Currently supported are: [debug, distroless]
144 # Specify image pull policy if default behavior isn't desired.
145 # Default behavior: latest images will be Always else IfNotPresent.
147 # change cni scope level to control logging out of istio-cni-node DaemonSet
151 # When enabled, default NetworkPolicy resources will be created
154 # ImagePullSecrets for all ServiceAccount, list of secrets in the same namespace
155 # to use for pulling any images in pods that reference this ServiceAccount.
156 # For components that don't use ServiceAccounts (i.e. grafana, servicegraph, tracing)
157 # ImagePullSecrets will be added to the corresponding Deployment(StatefulSet) objects.
158 # Must be set for any cluster configured with private docker registry.
160 # - private-registry-key
162 # Default resources allocated
167 # In order to use native nftable rules instead of iptable rules, set this flag to true.
168 nativeNftables: false
169 # resourceScope controls what resources will be processed by helm.
170 # This is useful when installing Istio on a cluster where some resources need to be owned by a cluster administrator and some can be owned by the mesh administrator.
172 # - all: all resources are processed
173 # - cluster: only cluster-scoped resources are processed
174 # - namespace: only namespace-scoped resources are processed
176 # A `key: value` mapping of environment variables to add to the pod