3image: # see: https://quay.io/repository/kiali/kiali-operator?tab=tags
4 repo: chainreg.biz/chainguard-private/kiali-operator-fips
5 tag: 2.32.0-r0@sha256:1a3f58786f05fdcf496209a26e17c267a4e2b3c33d482f054880b30b01f5cb3f
6 digest: "" # use "sha256" if tag is a sha256 hash (do NOT prefix this value with a "@")
9# Deployment options for the operator pod.
24# Configures the liveness, readiness, and startup probes of the operator pod.
25# The defaults are conservative so the operator comes up reliably on slow clusters.
26# Note that the startup probe keeps the operator unready for at least
27# probes.startup.initialDelaySeconds regardless of how fast it actually starts,
28# so lower that value if you need the operator to report ready sooner.
36 initialDelaySeconds: 30
38# This helm chart will create Kubernetes resources such as cluster roles, cluster role bindings, and service accounts.
39# For very rare use-cases, users may want to manage some of these resources manually, outside
40# of this helm chart. In cases like this, you can inform this helm chart to skip the creation of
41# those resources that you want to manage yourself.
42# For example, if you want to manage cluster roles and cluster role bindings yourself, but you still want this helm
43# chart to create service accounts, set the value of "skipResources" to an array
44# value of ["clusterrole", "clusterrolebinding"].
45# If you use this feature, you must be aware that you then bear the responsibility of
46# creating these resources yourself manually; if you do not then the installation
47# will be broken. Therefore, only use this feature if you know what you are doing.
48# Valid list item values are: "clusterrole", "clusterrolebinding", "sa"
50# metrics.enabled: set to true if you want Prometheus to collect metrics from the operator
53# debug.enabled: when true the full ansible logs are dumped after each reconciliation run
54# debug.verbosity: defines the amount of details the operator will log (higher numbers are more noisy)
55# debug.enableProfiler: when true (regardless of debug.enabled), timings for the most expensive tasks will be logged after each reconciliation loop
60# Defines where the operator will look for Kial CR resources. "" means "all namespaces".
62# Set to true if you want the operator to be able to create cluster roles. This is necessary
63# if you want to support Kiali CRs with spec.deployment.cluster_wide_access=true.
64# Setting this to "true" requires allowAllAccessibleNamespaces to be "true" also.
65# Note that this will be overriden to "true" if cr.create is true and cr.spec.deployment.cluster_wide_access=true.
66# This must be true to support impersonation on OpenShift.
67clusterRoleCreator: true
68# Set to true if you want the operator to be able to grant impersonation permissions to the
69# Kiali service account. This is only relevant on OpenShift clusters where the openshift auth
70# strategy is used with spec.auth.openshift.impersonation.enabled=true in the Kiali CR.
71# When true, the operator's own ClusterRole includes the "impersonate" verb on users and groups,
72# which is required by Kubernetes RBAC escalation rules (the operator cannot grant permissions
73# it does not itself hold). When false, impersonation permissions are omitted from the operator's
74# role entirely. Requires clusterRoleCreator to be true for this value to take effect.
75supportImpersonation: false
76# Set to true if you want to allow the operator to only be able to install Kiali in view-only-mode.
77# The purpose for this setting is to allow you to restrict the permissions given to the operator itself.
78onlyViewOnlyMode: false
79# allowAdHocKialiNamespace tells the operator to allow a user to be able to install a Kiali CR in one namespace but
80# be able to install Kiali in another namespace. In other words, it will allow the Kiali CR spec.deployment.namespace
81# to be something other than the namespace where the CR is installed. You may want to disable this if you are
82# running in a multi-tenant scenario in which you only want a user to be able to install Kiali in the same namespace
83# where the user has permissions to install a Kiali CR.
84allowAdHocKialiNamespace: true
85# allowAdHocKialiImage tells the operator to allow a user to be able to install a custom Kiali image as opposed
86# to the image the operator will install by default. In other words, it will allow the
87# Kiali CR spec.deployment.image_name and spec.deployment.image_version to be configured by the user.
88# You may want to disable this if you do not want users to install their own Kiali images.
89allowAdHocKialiImage: false
90# allowAdHocOSSMConsoleImage tells the operator to allow a user to be able to install a custom OSSMC image as opposed
91# to the image the operator will install by default. In other words, it will allow the
92# OSSMConsole CR spec.deployment.imageName and spec.deployment.imageVersion to be configured by the user.
93# You may want to disable this if you do not want users to install their own OSSMC images.
94# This is only applicable when running on OpenShift.
95allowAdHocOSSMConsoleImage: false
96# allowAdHocContainers tells the operator to allow a user to be able to install additional pod containers and initContainers to the Kiali pod.
97# In other words, it will allow the Kiali CR spec.deployment.additional_pod_containers_yaml and
98# spec.deployment.additional_pod_init_containers_yaml to be configured by the user.
99# The operator will apply a restrictive security context to user-defined containers and will prevent
100# write access to secret-backed volumes. These restrictions cannot be overridden.
101allowAdHocContainers: false
102# allowSecurityContextOverride tells the operator to allow a user to be able to fully override the Kiali
103# container securityContext. If this is false, certain securityContext settings must exist on the Kiali
104# container and any attempt to override them will be ignored.
105allowSecurityContextOverride: false
106# allowAllAccessibleNamespaces tells the operator to allow a user to be able to configure Kiali
107# to access all namespaces in the cluster via spec.deployment.cluster_wide_access=true.
108# If this is false, the user must specify an explicit set of namespaces in the Kiali CR via spec.deployment.discovery_selectors.
109# Setting this to "true" requires clusterRoleCreator to be "true" also.
110# Note that this will be overriden to "true" if cr.create is true and cr.spec.deployment.cluster_wide_access=true.
111allowAllAccessibleNamespaces: true
112# watchesFile: If specified, this determines what watches file will be used to configure the operator. There are four different
113# files that can be selected: (a) `watches-os.yaml`, (b) `watches-os-ns.yaml`, (c) `watches-k8s.yaml` or (d) `watches-k8s-ns.yaml`.
114# The first two are for OpenShift only, the last two are for non-OpenShift Kubernetes clusters. The two with "-ns" in their name
115# enable the operator to automatically update the Kiali Server with access to new namespaces as those namespaces are created in
116# the cluster. This namespace watching feature provides some advanced capabilities but is never required. It is also not
117# the default behavior and is not necessary if your Kiali CRs will have `spec.deployment.cluster_wide_access` set to `true`.
119# For what a Kiali CR spec can look like, see: https://kiali.io/docs/configuration/kialis.kiali.io/
123 # If you elect to create a Kiali CR (--set cr.create=true)
124 # and the operator is watching all namespaces (--set watchNamespace="")
125 # then this is the namespace where the CR will be created (the default will be the operator namespace).
127 # Annotations to place in the Kiali CR metadata.
131 cluster_wide_access: true