3 repository: chainguard-private/k8s_gateway
4 tag: 1.8.2-r12@sha256:ea377d1bef319c983e887d6aa9bb5e5b1e34d3d2af06a344b0c4611f42b94c37
5 pullPolicy: IfNotPresent
6# Reference to one or more secrets to be used when pulling images.
7# For more information, see [Pull an Image from a Private Registry](https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/).
11# - name: "image-pull-secret"
15# Prefer the hostname or IP in LoadBalancer status entries
16loadBalancerAddressPreference: hostname
17# Optional scheme for DNS server (e.g., "tls://", "https://", "grpc://")
18# Used to enable DoT (DNS over TLS), DoH (DNS over HTTPS), or gRPC protocols
19# Leave empty for standard DNS
20# See: https://coredns.io/plugins/tls/
22# Labels to apply to all resources
24# Annotations to apply to pods
26# TTL for non-apex responses (in seconds)
28# Resources (CPU, memory etc)
30# Limit what kind of resources to watch, e.g. watchedResources: ["Ingress"]
31watchedResources: ["Ingress", "Service"]
35 serviceLabelSelectors: []
36# Service name of a secondary DNS server (should be `serviceName.namespace`)
38# Enabled fallthrough for k8s_gateway
42# Override the default `serviceName.namespace` domain apex
44# Optional configuration option for DNS01 challenge that will redirect all acme
45# challenge requests to external cloud domain (e.g. managed by cert-manager)
46# See: https://cert-manager.io/docs/configuration/acme/dns01/
49 domain: dns01.clouddns.com
50# Optional plugins that will be enabled in the zone, e.g. "forward . /etc/resolve.conf"
54 # Serves a /health endpoint on :8080, required for livenessProbe
58 # Serves a /ready endpoint on :8181, required for readinessProbe
60 # Serves a /metrics endpoint on :9153, required for serviceMonitor
62 parameters: 0.0.0.0:9153
64 parameters: . /etc/resolv.conf
68# Example TLS configuration (requires scheme: "tls://" and TLS certificates)
70# parameters: /etc/coredns/tls/tls.crt /etc/coredns/tls/tls.key
86 # loadBalancerIP: 192.168.1.2
88 # clusterIP: 10.43.0.53
89 # externalTrafficPolicy: Local
92 # One of SingleStack, PreferDualStack, or RequireDualStack.
93 # ipFamilyPolicy: SingleStack
94 # List of IP families (e.g. IPv4 and/or IPv6).
95 # ref: https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services
102topologySpreadConstraints: []
105# Optional PriorityClass that will be used in the Deployment, e.g. priorityClassName: "system-cluster-critical"
110podSecurityContext: {}
114# - filename: example.db
116# domains: example.com
123# example.com. IN SOA sns.dns.icann.com. noc.dns.icann.com. 2015082541 7200 3600 1209600 3600
124# example.com. IN NS b.iana-servers.net.
125# example.com. IN NS a.iana-servers.net.
126# example.com. IN A 192.168.99.102
127# *.example.com. IN A 192.168.99.102
133# secretName: tsig-secret
137# mountPath: /etc/tsig