DirectorySecurity AdvisoriesPricing
Sign in
Directory
openbao logoHELM

openbao

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:
Compare:

1
# Copyright (c) HashiCorp, Inc.
2
# SPDX-License-Identifier: MPL-2.0
3
4
# Available parameters and their default values for the OpenBao chart.
5
6
global:
7
# -- enabled is the master enabled switch. Setting this to true or false
8
# will enable or disable all the components within this chart by default.
9
enabled: true
10
# -- The namespace to deploy to. Defaults to the `helm` installation namespace.
11
namespace: ""
12
# -- Image pull secret to use for registry authentication.
13
# Alternatively, the value may be specified as an array of strings.
14
imagePullSecrets: []
15
# imagePullSecrets:
16
# - name: image-pull-secret
17
18
# -- TLS for end-to-end encrypted transport
19
tlsDisable: true
20
# -- External openbao server address for the injector and CSI provider to use.
21
# Setting this will disable deployment of an OpenBao server.
22
externalBaoAddr: ""
23
# -- Deprecated: Please use global.externalBaoAddr instead.
24
externalVaultAddr: ""
25
# -- If deploying to OpenShift
26
openshift: false
27
serverTelemetry:
28
# -- Enable integration with the Prometheus Operator
29
# See the top level serverTelemetry section below before enabling this feature.
30
prometheusOperator: false
31
injector:
32
# -- True if you want to enable openbao agent injection. @default: global.enabled
33
enabled: "-"
34
replicas: 1
35
# -- Configures the port the injector should listen on
36
port: 8080
37
# -- If multiple replicas are specified, by default a leader will be determined
38
# so that only one injector attempts to create TLS certificates.
39
leaderElector:
40
enabled: true
41
# -- If true, will enable a node exporter metrics endpoint at /metrics.
42
metrics:
43
enabled: false
44
# -- Deprecated: Please use injector.externalBaoAddr instead.
45
externalVaultAddr: ""
46
# -- External openbao server address for the injector to use.
47
externalBaoAddr: ""
48
# image sets the repo and tag of the vault-k8s image to use for the injector.
49
image:
50
# -- image registry to use for k8s image
51
registry: chainreg.biz
52
# -- image repo to use for k8s image
53
repository: scratch-images/test-tmp/openbao-k8s-fips
54
# -- image tag to use for k8s image
55
tag: 1.4.0-r32@sha256:6cd1034b51943754700e0be2ba65466a3f8f13378978360ad788720ed94fadfc
56
# -- image pull policy to use for k8s image. if tag is "latest", set to "Always"
57
pullPolicy: IfNotPresent
58
# -- agentImage sets the repo and tag of the OpenBao image to use for the OpenBao Agent
59
# containers. This should be set to the official OpenBao image. OpenBao 1.3.1+ is
60
# required.
61
agentImage:
62
# -- image registry to use for agent image
63
registry: chainreg.biz
64
# -- image repo to use for agent image
65
repository: scratch-images/test-tmp/openbao-fips
66
# -- image tag to use for agent image - defaults to chart appVersion
67
tag: 2.6.2-r1@sha256:8ab204d58f8e3ea5a71e742f2c2142d5a9f60a3bb566a956d800fd6513325e90
68
# -- image pull policy to use for agent image. if tag is "latest", set to "Always"
69
pullPolicy: IfNotPresent
70
# The default values for the injected OpenBao Agent containers.
71
agentDefaults:
72
# For more information on configuring resources, see the K8s documentation:
73
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
74
cpuLimit: "500m"
75
cpuRequest: "250m"
76
memLimit: "128Mi"
77
memRequest: "64Mi"
78
# ephemeralLimit: "128Mi"
79
# ephemeralRequest: "64Mi"
80
81
# Default template type for secrets when no custom template is specified.
82
# Possible values include: "json" and "map".
83
template: "map"
84
# Default values within Agent's template_config stanza.
85
templateConfig:
86
exitOnRetryFailure: true
87
staticSecretRenderInterval: ""
88
# Used to define custom livenessProbe settings
89
livenessProbe:
90
# -- When a probe fails, Kubernetes will try failureThreshold times before giving up
91
failureThreshold: 2
92
# -- Number of seconds after the container has started before probe initiates
93
initialDelaySeconds: 5
94
# -- How often (in seconds) to perform the probe
95
periodSeconds: 2
96
# -- Minimum consecutive successes for the probe to be considered successful after having failed
97
successThreshold: 1
98
# -- Number of seconds after which the probe times out.
99
timeoutSeconds: 5
100
# Used to define custom readinessProbe settings
101
readinessProbe:
102
# -- When a probe fails, Kubernetes will try failureThreshold times before giving up
103
failureThreshold: 2
104
# -- Number of seconds after the container has started before probe initiates
105
initialDelaySeconds: 5
106
# -- How often (in seconds) to perform the probe
107
periodSeconds: 2
108
# -- Minimum consecutive successes for the probe to be considered successful after having failed
109
successThreshold: 1
110
# -- Number of seconds after which the probe times out.
111
timeoutSeconds: 5
112
# Used to define custom startupProbe settings
113
startupProbe:
114
# -- When a probe fails, Kubernetes will try failureThreshold times before giving up
115
failureThreshold: 12
116
# -- Number of seconds after the container has started before probe initiates
117
initialDelaySeconds: 5
118
# -- How often (in seconds) to perform the probe
119
periodSeconds: 5
120
# -- Minimum consecutive successes for the probe to be considered successful after having failed
121
successThreshold: 1
122
# -- Number of seconds after which the probe times out.
123
timeoutSeconds: 5
124
# Mount Path of the OpenBao Kubernetes Auth Method.
125
authPath: "auth/kubernetes"
126
# -- Configures the log verbosity of the injector.
127
# Supported log levels include: trace, debug, info, warn, error
128
logLevel: "info"
129
# -- Configures the log format of the injector. Supported log formats: "standard", "json".
130
logFormat: "standard"
131
# Configures all OpenBao Agent sidecars to revoke their token when shutting down
132
revokeOnShutdown: false
133
webhook:
134
# Configures failurePolicy of the webhook. The "unspecified" default behaviour depends on the
135
# API Version of the WebHook.
136
# To block pod creation while the webhook is unavailable, set the policy to `Fail` below.
137
# See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#failure-policy
138
#
139
failurePolicy: Ignore
140
# matchPolicy specifies the approach to accepting changes based on the rules of
141
# the MutatingWebhookConfiguration.
142
# See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#matching-requests-matchpolicy
143
# for more details.
144
#
145
matchPolicy: Exact
146
# timeoutSeconds is the amount of seconds before the webhook request will be ignored
147
# or fails.
148
# If it is ignored or fails depends on the failurePolicy
149
# See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#timeouts
150
# for more details.
151
#
152
timeoutSeconds: 30
153
# namespaceSelector is the selector for restricting the webhook to only
154
# specific namespaces.
155
# See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#matching-requests-namespaceselector
156
# for more details.
157
# Example:
158
# namespaceSelector:
159
# matchLabels:
160
# sidecar-injector: enabled
161
namespaceSelector: {}
162
# objectSelector is the selector for restricting the webhook to only
163
# specific labels.
164
# See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#matching-requests-objectselector
165
# for more details.
166
# Example:
167
# objectSelector:
168
# matchLabels:
169
# vault-sidecar-injector: enabled
170
objectSelector: |
171
matchExpressions:
172
- key: app.kubernetes.io/name
173
operator: NotIn
174
values:
175
- {{ template "openbao.name" . }}-agent-injector
176
# matchConditions is a list of CEL expressions for restricting the webhook to only
177
# specific requests.
178
# See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#matching-requests-matchconditions
179
# for more details.
180
# Example:
181
# matchConditions:
182
# - name: has-agent-inject-annotation
183
# expression: 'has(object.metadata.annotations) && "openbao.org/agent-inject" in object.metadata.annotations'
184
matchConditions: []
185
# Extra annotations to attach to the webhook
186
annotations: {}
187
# Deprecated: please use 'webhook.failurePolicy' instead
188
# Configures failurePolicy of the webhook. The "unspecified" default behaviour depends on the
189
# API Version of the WebHook.
190
# To block pod creation while webhook is unavailable, set the policy to `Fail` below.
191
# See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#failure-policy
192
#
193
failurePolicy: Ignore
194
# Deprecated: please use 'webhook.namespaceSelector' instead
195
# namespaceSelector is the selector for restricting the webhook to only
196
# specific namespaces.
197
# See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#matching-requests-namespaceselector
198
# for more details.
199
# Example:
200
# namespaceSelector:
201
# matchLabels:
202
# sidecar-injector: enabled
203
namespaceSelector: {}
204
# Deprecated: please use 'webhook.objectSelector' instead
205
# objectSelector is the selector for restricting the webhook to only
206
# specific labels.
207
# See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#matching-requests-objectselector
208
# for more details.
209
# Example:
210
# objectSelector:
211
# matchLabels:
212
# vault-sidecar-injector: enabled
213
objectSelector: {}
214
# Deprecated: please use 'webhook.annotations' instead
215
# Extra annotations to attach to the webhook
216
webhookAnnotations: {}
217
certs:
218
# secretName is the name of the secret that has the TLS certificate and
219
# private key to serve the injector webhook. If this is null, then the
220
# injector will default to its automatic management mode that will assign
221
# a service account to the injector to generate its own certificates.
222
secretName: null
223
# caBundle is a base64-encoded PEM-encoded certificate bundle for the CA
224
# that signed the TLS certificate that the webhook serves. This must be set
225
# if secretName is non-null unless an external service like cert-manager is
226
# keeping the caBundle updated.
227
caBundle: ""
228
# certName and keyName are the names of the files within the secret for
229
# the TLS cert and private key, respectively. These have reasonable
230
# defaults but can be customized if necessary.
231
certName: tls.crt
232
keyName: tls.key
233
# Security context for the pod template and the injector container
234
# The default pod securityContext is:
235
# runAsNonRoot: true
236
# runAsGroup: {{ .Values.injector.gid | default 1000 }}
237
# runAsUser: {{ .Values.injector.uid | default 100 }}
238
# fsGroup: {{ .Values.injector.gid | default 1000 }}
239
# seccompProfile:
240
# type: RuntimeDefault
241
# and for container is
242
# allowPrivilegeEscalation: false
243
# capabilities:
244
# drop:
245
# - ALL
246
securityContext:
247
pod: {}
248
container: {}
249
resources: {}
250
# resources:
251
# requests:
252
# memory: 256Mi
253
# cpu: 250m
254
# limits:
255
# memory: 256Mi
256
# cpu: 250m
257
258
# extraEnvironmentVars is a list of extra environment variables to set in the
259
# injector deployment.
260
extraEnvironmentVars: {}
261
# KUBERNETES_SERVICE_HOST: kubernetes.default.svc
262
263
# Affinity Settings for injector pods
264
# This can either be a multi-line string or YAML matching the PodSpec's affinity field.
265
# Commenting out or setting as empty the affinity variable, will allow
266
# deployment of multiple replicas to single node services such as Minikube.
267
affinity: |
268
podAntiAffinity:
269
requiredDuringSchedulingIgnoredDuringExecution:
270
- labelSelector:
271
matchLabels:
272
app.kubernetes.io/name: {{ template "openbao.name" . }}-agent-injector
273
app.kubernetes.io/instance: "{{ .Release.Name }}"
274
component: webhook
275
topologyKey: kubernetes.io/hostname
276
# Topology settings for injector pods
277
# ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
278
# This should be either a multi-line string or YAML matching the topologySpreadConstraints array
279
# in a PodSpec.
280
topologySpreadConstraints: []
281
# Toleration Settings for injector pods
282
# This should be either a multi-line string or YAML matching the Toleration array
283
# in a PodSpec.
284
tolerations: []
285
# nodeSelector labels for server pod assignment, formatted as a multi-line string or YAML map.
286
# ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#nodeselector
287
# Example:
288
# nodeSelector:
289
# beta.kubernetes.io/arch: amd64
290
nodeSelector: {}
291
# Priority class for injector pods
292
priorityClassName: ""
293
# Extra annotations to attach to the injector pods
294
# This can either be YAML or a YAML-formatted multi-line templated string map
295
# of the annotations to apply to the injector pods
296
annotations: {}
297
# Extra labels to attach to the agent-injector
298
# This should be a YAML map of the labels to apply to the injector
299
extraLabels: {}
300
# Should the injector pods run on the host network (useful when using
301
# an alternate CNI in EKS)
302
hostNetwork: false
303
# Injector service specific config
304
service:
305
# Extra annotations to attach to the injector service
306
annotations: {}
307
# Extra labels for the service definition.
308
# This should be a YAML map of the labels to apply to the injector service
309
extraLabels: {}
310
# Injector serviceAccount specific config
311
serviceAccount:
312
# Extra annotations to attach to the injector serviceAccount
313
annotations: {}
314
# A disruption budget limits the number of pods of a replicated application
315
# that are down simultaneously from voluntary disruptions
316
podDisruptionBudget: {}
317
# podDisruptionBudget:
318
# maxUnavailable: 1
319
320
# strategy for updating the deployment. This can be a multi-line string or a
321
# YAML map.
322
strategy: {}
323
# strategy: |
324
# rollingUpdate:
325
# maxSurge: 25%
326
# maxUnavailable: 25%
327
# type: RollingUpdate
328
server:
329
# If true, or "-" with global.enabled true, OpenBao server will be installed.
330
# See openbao.mode in _helpers.tpl for implementation details.
331
enabled: "-"
332
# Resource requests, limits, etc. for the server cluster placement. This
333
# should map directly to the value of the resources field for a PodSpec.
334
# By default no direct resource request is made.
335
image:
336
# -- image registry to use for server image
337
registry: chainreg.biz
338
# -- image repo to use for server image
339
repository: scratch-images/test-tmp/openbao-fips
340
# -- image tag to use for server image - defaults to chart appVersion
341
tag: 2.6.2-r1@sha256:8ab204d58f8e3ea5a71e742f2c2142d5a9f60a3bb566a956d800fd6513325e90
342
# -- image pull policy to use for server image. if tag is "latest", set to "Always"
343
pullPolicy: IfNotPresent
344
# Configure the Update Strategy Type for the StatefulSet
345
# See https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#update-strategies
346
updateStrategyType: "OnDelete"
347
# Configure the pod management policy for the StatefulSet
348
# See https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#pod-management-policies
349
podManagementPolicy: "OrderedReady"
350
# Configure the logging verbosity for the OpenBao server.
351
# Supported log levels include: trace, debug, info, warn, error
352
logLevel: ""
353
# Configure the logging format for the OpenBao server.
354
# Supported log formats include: standard, json
355
logFormat: ""
356
resources: {}
357
# resources:
358
# requests:
359
# memory: 256Mi
360
# cpu: 250m
361
# limits:
362
# memory: 256Mi
363
# cpu: 250m
364
365
# Ingress allows ingress services to be created to allow external access
366
# from Kubernetes to access OpenBao pods.
367
# If deployment is on OpenShift, the following block is ignored.
368
# In order to expose the service, use the route section below
369
ingress:
370
enabled: false
371
labels: {}
372
# traffic: external
373
annotations: {}
374
# |
375
# kubernetes.io/ingress.class: nginx
376
# kubernetes.io/tls-acme: "true"
377
# or
378
# kubernetes.io/ingress.class: nginx
379
# kubernetes.io/tls-acme: "true"
380
381
# Optionally use ingressClassName instead of deprecated annotation.
382
# See: https://kubernetes.io/docs/concepts/services-networking/ingress/#deprecated-annotation
383
ingressClassName: ""
384
# As of Kubernetes 1.19, all Ingress Paths must have a pathType configured. The default value below should be sufficient in most cases.
385
# See: https://kubernetes.io/docs/concepts/services-networking/ingress/#path-types for other possible values.
386
pathType: Prefix
387
# When HA mode is enabled and K8s service registration is being used,
388
# configure the ingress to point to the OpenBao active service.
389
activeService: true
390
hosts:
391
- host: chart-example.local
392
paths: []
393
## Extra paths to prepend to the host configuration. This is useful when working with annotation based services.
394
extraPaths: []
395
# - path: /*
396
# backend:
397
# service:
398
# name: ssl-redirect
399
# port:
400
# number: use-annotation
401
tls: []
402
# - secretName: chart-example-tls
403
# hosts:
404
# - chart-example.local
405
# Gateway consolidates configuration related to the Kubernetes Gateway API
406
# Currently, only creating a TLSRoute is supported
407
# See: https://gateway-api.sigs.k8s.io/
408
gateway:
409
# Configures a TLSRoute for the OpenBao server. This can be enabled independently of the ingress configuration to allow for side-by-side scenarios for migration.
410
tlsRoute:
411
enabled: false
412
labels: {}
413
# traffic: external
414
annotations: {}
415
# external-dns.alpha.kubernetes.io/hostname: chart-example.local
416
417
hosts: []
418
# - chart-example.local
419
420
# Allows overriding the TLSRoutes apiVersion in case a different version of Gateway API is installed on the cluster.
421
apiVersion: gateway.networking.k8s.io/v1alpha3
422
# When HA mode is enabled and K8s service registration is being used,
423
# configure the ingress to point to the OpenBao active service.
424
activeService: true
425
# List of ParentRefs. As the helm chart configures no gateways itself,
426
# this should be set to at least one gateway with one or more TLS listeners
427
parentRefs: []
428
# - name: my-gw
429
# namespace: gateway-namespace
430
# # sectionName is optional to fix to a specific listener
431
# sectionName: listener-name
432
# Configures a HTTPRoute for the OpenBao server. This can be enabled independently of the ingress configuration to allow for side-by-side scenarios for migration.
433
# WARNING: Terminating TLS before reaching the OpenBao Server is not recommended and may break things like certificate authentication. Prefer usage of `TLSRoute`.
434
httpRoute:
435
enabled: false
436
labels: {}
437
# traffic: external
438
annotations: {}
439
# external-dns.alpha.kubernetes.io/hostname: chart-example.local
440
441
hosts:
442
- chart-example.local
443
# Allows overriding the HTTPRoute apiVersion in case a different version of Gateway API is installed on the cluster.
444
apiVersion: gateway.networking.k8s.io/v1
445
# When HA mode is enabled and K8s service registration is being used,
446
# configure the ingress to point to the OpenBao active service.
447
activeService: true
448
# List of ParentRefs. As the helm chart configures no gateways itself,
449
# this should be set to at least one gateway with one or more HTTP listeners
450
parentRefs: []
451
# - name: my-gw
452
# namespace: gateway-namespace
453
# # sectionName is optional to fix to a specific listener
454
# sectionName: listener-name
455
456
matches:
457
path:
458
type: PathPrefix
459
value: '/'
460
timeouts: {}
461
# request: 10s #Maximum time the Gateway waits to complete the full client request and response cycle.
462
# backendRequest: 10s # Maximum time the Gateway waits for a response from the backend service.
463
filters: []
464
# - type: RequestHeaderModifier
465
# requestHeaderModifier:
466
# set:
467
# - name: X-Forwarded-Proto
468
# value: https
469
# If TLS is enable on server (see global.tlsDisable) the gateway must be configured
470
# with BackendTLSPolicy to correctly handles TLS connection with server in case TLS termination happens at gateway
471
tlsPolicy:
472
enabled: false
473
labels: {}
474
# traffic: external
475
annotations: {}
476
# external-dns.alpha.kubernetes.io/hostname: chart-example.local
477
478
# Allows overriding the BackendTLSPolicy apiVersion in case a different version of Gateway API is installed on the cluster.
479
apiVersion: gateway.networking.k8s.io/v1
480
# When HA mode is enabled and K8s service registration is being used,
481
# configure the ingress to point to the OpenBao active service.
482
activeService: true
483
# Identifies an API object to apply the policy to.
484
# If no one is specified the default is to target the OpenBao service
485
targetRefs: []
486
validation: {}
487
# caCertificateRefs:
488
# - kind: ConfigMap
489
# group: ""
490
# name: vault-ca
491
# hostAliases is a list of aliases to be added to /etc/hosts. Specified as a YAML list.
492
hostAliases: []
493
# - ip: 127.0.0.1
494
# hostnames:
495
# - chart-example.local
496
497
# OpenShift only - create a route to expose the service
498
# By default the created route will be of type passthrough
499
route:
500
enabled: false
501
# When HA mode is enabled and K8s service registration is being used,
502
# configure the route to point to the OpenBao active service.
503
activeService: true
504
labels: {}
505
annotations: {}
506
host: chart-example.local
507
# tls will be passed directly to the route's TLS config, which
508
# can be used to configure other termination methods that terminate
509
# TLS at the router
510
tls:
511
termination: passthrough
512
# authDelegator enables a cluster role binding to be attached to the service
513
# account. This cluster role binding can be used to setup Kubernetes auth
514
# method. See https://openbao.org/docs/auth/kubernetes
515
authDelegator:
516
enabled: true
517
# -- extraInitContainers is a list of init containers. Specified as a YAML list.
518
# This is useful if you need to run a script to provision TLS certificates or
519
# write out configuration files in a dynamic way.
520
extraInitContainers: []
521
# # This example installs a plugin pulled from github into the /usr/local/libexec/vault/oauthapp folder,
522
# # which is defined in the volumes value.
523
# - name: oauthapp
524
# image: "alpine"
525
# command: [sh, -c]
526
# args:
527
# - cd /tmp &&
528
# wget https://github.com/puppetlabs/vault-plugin-secrets-oauthapp/releases/download/v1.2.0/vault-plugin-secrets-oauthapp-v1.2.0-linux-amd64.tar.xz -O oauthapp.xz &&
529
# tar -xf oauthapp.xz &&
530
# mv vault-plugin-secrets-oauthapp-v1.2.0-linux-amd64 /usr/local/libexec/vault/oauthapp &&
531
# chmod +x /usr/local/libexec/vault/oauthapp
532
# volumeMounts:
533
# - name: plugins
534
# mountPath: /usr/local/libexec/vault
535
536
# extraContainers is a list of sidecar containers. Specified as a YAML list.
537
extraContainers: null
538
# -- shareProcessNamespace enables process namespace sharing between OpenBao and the extraContainers
539
# This is useful if OpenBao must be signaled, e.g. to send a SIGHUP for a log rotation
540
shareProcessNamespace: false
541
# -- extraArgs is a string containing additional OpenBao server arguments.
542
extraArgs: ""
543
# -- extraPorts is a list of extra ports. Specified as a YAML list.
544
# This is useful if you need to add additional ports to the statefulset in dynamic way.
545
extraPorts: []
546
# - containerPort: 8300
547
# name: http-monitoring
548
549
# Used to define custom readinessProbe settings
550
readinessProbe:
551
enabled: true
552
# If you need to use a http path instead of the default exec
553
# path: /v1/sys/health?standbyok=true
554
555
# Port number on which readinessProbe will be checked.
556
port: 8200
557
# When a probe fails, Kubernetes will try failureThreshold times before giving up
558
failureThreshold: 2
559
# Number of seconds after the container has started before probe initiates
560
initialDelaySeconds: 5
561
# How often (in seconds) to perform the probe
562
periodSeconds: 5
563
# Minimum consecutive successes for the probe to be considered successful after having failed
564
successThreshold: 1
565
# Number of seconds after which the probe times out.
566
timeoutSeconds: 3
567
# Used to enable a livenessProbe for the pods
568
livenessProbe:
569
enabled: false
570
# Used to define a liveness exec command. If provided, exec is preferred to httpGet (path) as the livenessProbe handler.
571
execCommand: []
572
# - /bin/sh
573
# - -c
574
# - /openbao/userconfig/mylivenessscript/run.sh
575
# Path for the livenessProbe to use httpGet as the livenessProbe handler
576
path: "/v1/sys/health?standbyok=true"
577
# Port number on which livenessProbe will be checked if httpGet is used as the livenessProbe handler
578
port: 8200
579
# When a probe fails, Kubernetes will try failureThreshold times before giving up
580
failureThreshold: 2
581
# Number of seconds after the container has started before probe initiates
582
initialDelaySeconds: 60
583
# How often (in seconds) to perform the probe
584
periodSeconds: 5
585
# Minimum consecutive successes for the probe to be considered successful after having failed
586
successThreshold: 1
587
# Number of seconds after which the probe times out.
588
timeoutSeconds: 3
589
# Optional duration in seconds the pod needs to terminate gracefully.
590
# See: https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/
591
terminationGracePeriodSeconds: 10
592
# Used to set the sleep time during the preStop step
593
preStopSleepSeconds: 5
594
# Used to define commands to run after the pod is ready.
595
# This can be used to automate processes such as initialization
596
# or bootstrapping auth methods.
597
postStart: []
598
# - /bin/sh
599
# - -c
600
# - /openbao/userconfig/myscript/run.sh
601
602
# extraEnvironmentVars is a list of extra environment variables to set with the stateful set. These could be
603
# used to include variables required for auto-unseal.
604
extraEnvironmentVars: {}
605
# GOOGLE_REGION: global
606
# GOOGLE_PROJECT: myproject
607
# GOOGLE_APPLICATION_CREDENTIALS: /openbao/userconfig/myproject/myproject-creds.json
608
609
# extraSecretEnvironmentVars is a list of extra environment variables to set with the stateful set.
610
# These variables take value from existing Secret objects.
611
extraSecretEnvironmentVars: []
612
# - envName: AWS_SECRET_ACCESS_KEY
613
# secretName: openbao
614
# secretKey: AWS_SECRET_ACCESS_KEY
615
616
# Deprecated: please use 'volumes' instead.
617
# extraVolumes is a list of extra volumes to mount. These will be exposed
618
# to OpenBao in the path `/openbao/userconfig/<name>/`. The value below is
619
# an array of objects, examples are shown below.
620
extraVolumes: []
621
# - type: secret (or "configMap")
622
# name: my-secret
623
# path: null # default is `/openbao/userconfig`
624
625
# volumes is a list of volumes made available to all containers. These are rendered
626
# via toYaml rather than pre-processed like the extraVolumes value.
627
# The purpose is to make it easy to share volumes between containers.
628
volumes: null
629
# - name: plugins
630
# emptyDir: {}
631
632
# volumeMounts is a list of volumeMounts for the main server container. These are rendered
633
# via toYaml rather than pre-processed like the extraVolumes value.
634
# The purpose is to make it easy to share volumes between containers.
635
volumeMounts: null
636
# - mountPath: /usr/local/libexec/vault
637
# name: plugins
638
# readOnly: true
639
640
# Affinity Settings
641
# Commenting out or setting as empty the affinity variable, will allow
642
# deployment to single node services such as Minikube
643
# This should be either a multi-line string or YAML matching the PodSpec's affinity field.
644
affinity: |
645
podAntiAffinity:
646
requiredDuringSchedulingIgnoredDuringExecution:
647
- labelSelector:
648
matchLabels:
649
app.kubernetes.io/name: {{ template "openbao.name" . }}
650
app.kubernetes.io/instance: "{{ .Release.Name }}"
651
component: server
652
topologyKey: kubernetes.io/hostname
653
# Topology settings for server pods
654
# ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
655
# This should be either a multi-line string or YAML matching the topologySpreadConstraints array
656
# in a PodSpec.
657
topologySpreadConstraints: []
658
# Toleration Settings for server pods
659
# This should be either a multi-line string or YAML matching the Toleration array
660
# in a PodSpec.
661
tolerations: []
662
# nodeSelector labels for server pod assignment, formatted as a multi-line string or YAML map.
663
# ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#nodeselector
664
# Example:
665
# nodeSelector:
666
# beta.kubernetes.io/arch: amd64
667
nodeSelector: {}
668
# Enables network policy for server pods
669
networkPolicy:
670
enabled: false
671
egress: []
672
# egress:
673
# - to:
674
# - ipBlock:
675
# cidr: 10.0.0.0/24
676
# ports:
677
# - protocol: TCP
678
# port: 443
679
ingress:
680
- from:
681
- namespaceSelector: {}
682
ports:
683
- port: 8200
684
protocol: TCP
685
- port: 8201
686
protocol: TCP
687
# Priority class for server pods
688
priorityClassName: ""
689
# Extra labels to attach to the server pods
690
# This should be a YAML map of the labels to apply to the server pods
691
extraLabels: {}
692
# Extra annotations to attach to the server pods
693
# This can either be YAML or a YAML-formatted multi-line templated string map
694
# of the annotations to apply to the server pods
695
annotations: {}
696
# Add an annotation to the server configmap and the statefulset pods,
697
# vaultproject.io/config-checksum, that is a hash of the OpenBao configuration.
698
# This can be used together with an OnDelete deployment strategy to help
699
# identify which pods still need to be deleted during a deployment to pick up
700
# any configuration changes.
701
configAnnotation: false
702
# Enables a headless service to be used by the OpenBao Statefulset
703
service:
704
enabled: true
705
# Enable or disable the openbao-active service, which selects OpenBao pods that
706
# have labeled themselves as the cluster leader with `openbao-active: "true"`.
707
active:
708
enabled: true
709
# Extra annotations for the service definition. This can either be YAML or a
710
# YAML-formatted multi-line templated string map of the annotations to apply
711
# to the active service.
712
annotations: {}
713
# Extra labels for the service definition.
714
# This should be a YAML map of the labels to apply to the active service
715
extraLabels: {}
716
# Enable or disable the openbao-standby service, which selects OpenBao pods that
717
# have labeled themselves as a cluster follower with `openbao-active: "false"`.
718
standby:
719
enabled: true
720
# Extra annotations for the service definition. This can either be YAML or a
721
# YAML-formatted multi-line templated string map of the annotations to apply
722
# to the standby service.
723
annotations: {}
724
# Extra labels for the service definition.
725
# This should be a YAML map of the labels to apply to the standby service
726
extraLabels: {}
727
headless:
728
# Extra annotations for the headless service definition. This can either be YAML or a
729
# YAML-formatted multi-line templated string map of the annotations to apply
730
# to the headless service.
731
annotations: {}
732
# If enabled, the service selectors will include `app.kubernetes.io/instance: {{ .Release.Name }}`
733
# When disabled, services may select OpenBao pods not deployed from the chart.
734
# Does not affect the headless openbao-internal service with `ClusterIP: None`
735
instanceSelector:
736
enabled: true
737
# clusterIP controls whether a Cluster IP address is attached to the
738
# OpenBao service within Kubernetes. By default, the OpenBao service will
739
# be given a Cluster IP address, set to None to disable. When disabled
740
# Kubernetes will create a "headless" service. Headless services can be
741
# used to communicate with pods directly through DNS instead of a round-robin
742
# load balancer.
743
# clusterIP: None
744
745
# Configures the service type for the main OpenBao service. Can be ClusterIP
746
# or NodePort.
747
# type: ClusterIP
748
749
# The IP family and IP families options are to set the behaviour in a dual-stack environment.
750
# Omitting these values will let the service fall back to whatever the CNI dictates the defaults
751
# should be.
752
#
753
# Configures the service's supported IP family policy, can be either:
754
# SingleStack: Single-stack service. The control plane allocates a cluster IP for the Service, using the first configured service cluster IP range.
755
# PreferDualStack: Allocates IPv4 and IPv6 cluster IPs for the Service.
756
# RequireDualStack: Allocates Service .spec.ClusterIPs from both IPv4 and IPv6 address ranges.
757
ipFamilyPolicy: ""
758
# Sets the families that should be supported and the order in which they should be applied to ClusterIP as well.
759
# Can be IPv4 and/or IPv6.
760
ipFamilies: []
761
# Do not wait for pods to be ready before including them in the services'
762
# targets. Does not apply to the headless service, which is used for
763
# cluster-internal communication.
764
publishNotReadyAddresses: true
765
# The externalTrafficPolicy can be set to either Cluster or Local
766
# and is only valid for LoadBalancer and NodePort service types.
767
# The default value is Cluster.
768
# ref: https://kubernetes.io/docs/concepts/services-networking/service/#external-traffic-policy
769
externalTrafficPolicy: Cluster
770
# If type is set to "NodePort", a specific nodePort value can be configured,
771
# will be random if left blank.
772
# nodePort: 30000
773
774
# When HA mode is enabled
775
# If type is set to "NodePort", a specific nodePort value can be configured,
776
# will be random if left blank.
777
# activeNodePort: 30001
778
779
# When HA mode is enabled
780
# If type is set to "NodePort", a specific nodePort value can be configured,
781
# will be random if left blank.
782
# standbyNodePort: 30002
783
784
# Port on which OpenBao server is listening
785
port: 8200
786
# Target port to which the service should be mapped to
787
targetPort: 8200
788
# -- extraPorts is a list of extra ports. Specified as a YAML list.
789
# This is useful if you need to add additional ports to the server service in dynamic way.
790
extraPorts: []
791
# - name: metrics
792
# port: 9101
793
# targetPort: 9101
794
795
# Extra annotations for the service definition. This can either be YAML or a
796
# YAML-formatted multi-line templated string map of the annotations to apply
797
# to the service.
798
annotations: {}
799
# Extra labels for the service definition.
800
# This should be a YAML map of the labels to apply to the service
801
extraLabels: {}
802
# This configures the OpenBao Statefulset to create a PVC for data
803
# storage when using the file or raft backend storage engines.
804
# See https://openbao.org/docs/configuration/storage to know more
805
dataStorage:
806
enabled: true
807
# Size of the PVC created
808
size: 10Gi
809
# Location where the PVC will be mounted.
810
mountPath: "/openbao/data"
811
# Name of the storage class to use. If null it will use the
812
# configured default Storage Class.
813
storageClass: null
814
# Access Mode of the storage device being used for the PVC
815
accessMode: ReadWriteOnce
816
# Annotations to apply to the PVC
817
annotations: {}
818
# Labels to apply to the PVC
819
labels: {}
820
# Persistent Volume Claim (PVC) retention policy
821
# ref: https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#persistentvolumeclaim-retention
822
# Example:
823
# persistentVolumeClaimRetentionPolicy:
824
# whenDeleted: Retain
825
# whenScaled: Retain
826
persistentVolumeClaimRetentionPolicy: {}
827
# This configures the OpenBao Statefulset to create a PVC for audit
828
# logs. Once OpenBao is deployed, initialized, and unsealed, OpenBao must
829
# be configured to use this for audit logs. This will be mounted to
830
# /openbao/audit
831
# See https://openbao.org/docs/audit to know more
832
auditStorage:
833
enabled: false
834
# Size of the PVC created
835
size: 10Gi
836
# Location where the PVC will be mounted.
837
mountPath: "/openbao/audit"
838
# Name of the storage class to use. If null it will use the
839
# configured default Storage Class.
840
storageClass: null
841
# Access Mode of the storage device being used for the PVC
842
accessMode: ReadWriteOnce
843
# Annotations to apply to the PVC
844
annotations: {}
845
# Labels to apply to the PVC
846
labels: {}
847
# Run OpenBao in "dev" mode. This requires no further setup, no state management,
848
# and no initialization. This is useful for experimenting with OpenBao without
849
# needing to unseal, store keys, et. al. All data is lost on restart - do not
850
# use dev mode for anything other than experimenting.
851
# See https://openbao.org/docs/concepts/dev-server to know more
852
dev:
853
enabled: false
854
# Set VAULT_DEV_ROOT_TOKEN_ID value
855
devRootToken: "root"
856
# Run OpenBao in "standalone" mode. This is the default mode that will deploy if
857
# no arguments are given to helm. This requires a PVC for data storage to use
858
# the "file" backend. This mode is not highly available and should not be scaled
859
# past a single replica.
860
standalone:
861
enabled: "-"
862
# config is a raw string of default configuration when using a Stateful
863
# deployment. Default is to use a PersistentVolumeClaim mounted at /openbao/data
864
# and store data there. This is only used when using a Replica count of 1, and
865
# using a stateful set. This should be HCL.
866
867
# Note: Configuration files are stored in ConfigMaps so sensitive data
868
# such as passwords should be either mounted through extraSecretEnvironmentVars
869
# or through a Kube secret. For more information see:
870
# https://openbao.org/docs/platform/k8s/helm/run/#protecting-sensitive-openbao-configurations
871
config: |
872
ui = true
873
874
listener "tcp" {
875
tls_disable = 1
876
address = "[::]:8200"
877
cluster_address = "[::]:8201"
878
# Enable unauthenticated metrics access (necessary for Prometheus Operator)
879
#telemetry {
880
# unauthenticated_metrics_access = "true"
881
#}
882
}
883
storage "file" {
884
path = "/openbao/data"
885
}
886
887
# Example configuration for using auto-unseal, using Google Cloud KMS. The
888
# GKMS keys must already exist, and the cluster must have a service account
889
# that is authorized to access GCP KMS.
890
#seal "gcpckms" {
891
# project = "openbao-helm-dev"
892
# region = "global"
893
# key_ring = "openbao-helm-unseal-kr"
894
# crypto_key = "openbao-helm-unseal-key"
895
#}
896
897
# Example configuration for enabling Prometheus metrics in your config.
898
#telemetry {
899
# prometheus_retention_time = "30s"
900
# disable_hostname = true
901
#}
902
# Run OpenBao in "HA" mode. There are no storage requirements unless the audit log
903
# persistence is required. In HA mode OpenBao will configure itself to use Consul
904
# for its storage backend. The default configuration provided will work the Consul
905
# Helm project by default. It is possible to manually configure OpenBao to use a
906
# different HA backend.
907
ha:
908
enabled: false
909
replicas: 3
910
# Set the api_addr configuration for OpenBao HA
911
# See https://openbao.org/docs/configuration/#high-availability-parameters
912
# If set to null, this will be set to the Pod IP Address
913
apiAddr: null
914
# Set the cluster_addr configuration for OpenBao HA
915
# See https://openbao.org/docs/configuration/#high-availability-parameters
916
# If set to null, this will be set to https://$(HOSTNAME).{{ template "openbao.fullname" . }}-internal:8201
917
clusterAddr: null
918
# Enables OpenBao's integrated Raft storage. Unlike the typical HA modes where
919
# OpenBao's persistence is external (such as Consul), enabling Raft mode will create
920
# persistent volumes for OpenBao to store data according to the configuration under server.dataStorage.
921
# The OpenBao cluster will coordinate leader elections and failovers internally.
922
raft:
923
# Enables Raft integrated storage
924
enabled: false
925
# Set the Node Raft ID to the name of the pod
926
setNodeId: false
927
# config is a raw string of default configuration when using a Stateful
928
# deployment.
929
# This should be HCL.
930
931
# Note: Configuration files are stored in ConfigMaps so sensitive data
932
# such as passwords should be either mounted through extraSecretEnvironmentVars
933
# or through a Kube secret. For more information see:
934
# https://openbao.org/docs/platform/k8s/helm/run/#protecting-sensitive-openbao-configurations
935
config: |
936
ui = true
937
938
listener "tcp" {
939
tls_disable = 1
940
address = "[::]:8200"
941
cluster_address = "[::]:8201"
942
# Enable unauthenticated metrics access (necessary for Prometheus Operator)
943
#telemetry {
944
# unauthenticated_metrics_access = "true"
945
#}
946
}
947
948
storage "raft" {
949
path = "/openbao/data"
950
}
951
952
service_registration "kubernetes" {}
953
# config is a raw string of default configuration when using a Stateful
954
# deployment. Default is to use a Consul for its HA storage backend.
955
# This should be HCL.
956
957
# Note: Configuration files are stored in ConfigMaps so sensitive data
958
# such as passwords should be either mounted through extraSecretEnvironmentVars
959
# or through a Kube secret. For more information see:
960
# https://openbao.org/docs/platform/k8s/helm/run/#protecting-sensitive-openbao-configurations
961
config: |
962
ui = true
963
964
listener "tcp" {
965
tls_disable = 1
966
address = "[::]:8200"
967
cluster_address = "[::]:8201"
968
}
969
storage "consul" {
970
path = "openbao"
971
address = "HOST_IP:8500"
972
}
973
974
service_registration "kubernetes" {}
975
976
# Example configuration for using auto-unseal, using Google Cloud KMS. The
977
# GKMS keys must already exist, and the cluster must have a service account
978
# that is authorized to access GCP KMS.
979
#seal "gcpckms" {
980
# project = "openbao-helm-dev-246514"
981
# region = "global"
982
# key_ring = "openbao-helm-unseal-kr"
983
# crypto_key = "openbao-helm-unseal-key"
984
#}
985
986
# Example configuration for enabling Prometheus metrics.
987
# If you are using Prometheus Operator you can enable a ServiceMonitor resource below.
988
# You may wish to enable unauthenticated metrics in the listener block above.
989
#telemetry {
990
# prometheus_retention_time = "30s"
991
# disable_hostname = true
992
#}
993
# A disruption budget limits the number of pods of a replicated application
994
# that are down simultaneously from voluntary disruptions
995
disruptionBudget:
996
enabled: true
997
# maxUnavailable will default to (n/2)-1 where n is the number of
998
# replicas. If you'd like a custom value, you can specify an override here.
999
maxUnavailable: null
1000
# Definition of the serviceAccount used to run Vault.
1001
# These options are also used when using an external OpenBao server to validate
1002
# Kubernetes tokens.
1003
serviceAccount:
1004
# Specifies whether a service account should be created
1005
create: true
1006
# The name of the service account to use.
1007
# If not set and create is true, a name is generated using the fullname template
1008
name: ""
1009
# Create a Secret API object to store a non-expiring token for the service account.
1010
# Prior to v1.24.0, Kubernetes used to generate this secret for each service account by default.
1011
# Kubernetes now recommends using short-lived tokens from the TokenRequest API or projected volumes instead if possible.
1012
# For more details, see https://kubernetes.io/docs/concepts/configuration/secret/#serviceaccount-token-secrets
1013
# serviceAccount.create must be equal to 'true' in order to use this feature.
1014
createSecret: false
1015
# Extra annotations for the serviceAccount definition. This can either be
1016
# YAML or a YAML-formatted multi-line templated string map of the
1017
# annotations to apply to the serviceAccount.
1018
annotations: {}
1019
# Extra labels to attach to the serviceAccount
1020
# This should be a YAML map of the labels to apply to the serviceAccount
1021
extraLabels: {}
1022
# Enable or disable a service account role binding with the permissions required for
1023
# OpenBao's Kubernetes service_registration config option.
1024
# See https://openbao.org/docs/configuration/service-registration/kubernetes
1025
serviceDiscovery:
1026
enabled: true
1027
# Settings for the statefulSet used to run OpenBao.
1028
statefulSet:
1029
# Extra annotations for the statefulSet. This can either be YAML or a
1030
# YAML-formatted multi-line templated string map of the annotations to apply
1031
# to the statefulSet.
1032
annotations: {}
1033
# Set the pod and container security contexts.
1034
# If not set, these will default to, and for *not* OpenShift:
1035
# pod:
1036
# runAsNonRoot: true
1037
# runAsGroup: {{ .Values.server.gid | default 1000 }}
1038
# runAsUser: {{ .Values.server.uid | default 100 }}
1039
# fsGroup: {{ .Values.server.gid | default 1000 }}
1040
# seccompProfile:
1041
# type: RuntimeDefault
1042
# container:
1043
# allowPrivilegeEscalation: false
1044
#
1045
# If not set, these will default to, and for OpenShift:
1046
# pod: {}
1047
# container: {}
1048
securityContext:
1049
pod: {}
1050
container: {}
1051
# Should the server pods run on the host network
1052
hostNetwork: false
1053
# OpenBao UI
1054
ui:
1055
# True if you want to create a Service entry for the OpenBao UI.
1056
#
1057
# serviceType can be used to control the type of service created. For
1058
# example, setting this to "LoadBalancer" will create an external load
1059
# balancer (for supported K8S installations) to access the UI.
1060
enabled: false
1061
publishNotReadyAddresses: true
1062
# The service should only contain selectors for active OpenBao pod
1063
activeOpenbaoPodOnly: false
1064
serviceType: "ClusterIP"
1065
serviceNodePort: null
1066
externalPort: 8200
1067
targetPort: 8200
1068
# The IP family and IP families options are to set the behaviour in a dual-stack environment.
1069
# Omitting these values will let the service fall back to whatever the CNI dictates the defaults
1070
# should be.
1071
#
1072
# Configures the service's supported IP family, can be either:
1073
# SingleStack: Single-stack service. The control plane allocates a cluster IP for the Service, using the first configured service cluster IP range.
1074
# PreferDualStack: Allocates IPv4 and IPv6 cluster IPs for the Service.
1075
# RequireDualStack: Allocates Service .spec.ClusterIPs from both IPv4 and IPv6 address ranges.
1076
serviceIPFamilyPolicy: ""
1077
# Sets the families that should be supported and the order in which they should be applied to ClusterIP as well
1078
# Can be IPv4 and/or IPv6.
1079
serviceIPFamilies: []
1080
# The externalTrafficPolicy can be set to either Cluster or Local
1081
# and is only valid for LoadBalancer and NodePort service types.
1082
# The default value is Cluster.
1083
# ref: https://kubernetes.io/docs/concepts/services-networking/service/#external-traffic-policy
1084
externalTrafficPolicy: Cluster
1085
# loadBalancerSourceRanges:
1086
# - 10.0.0.0/16
1087
# - 1.78.23.3/32
1088
1089
# loadBalancerIP:
1090
1091
# Extra annotations to attach to the ui service
1092
# This can either be YAML or a YAML-formatted multi-line templated string map
1093
# of the annotations to apply to the ui service
1094
annotations: {}
1095
# Extra labels for the service definition.
1096
# This should be a YAML map of the labels to apply to the ui service
1097
extraLabels: {}
1098
# openbao-csi-provider
1099
csi:
1100
# -- True if you want to install an openbao-csi-provider daemonset.
1101
#
1102
# Requires installing the secrets-store-csi-driver separately, see:
1103
# https://secrets-store-csi-driver.sigs.k8s.io/getting-started/installation
1104
#
1105
# With the driver and provider installed, you can mount OpenBao secrets into volumes
1106
# similar to the OpenBao Agent injector, and you can also sync those secrets into
1107
# Kubernetes secrets.
1108
enabled: false
1109
image:
1110
# -- image registry to use for csi image
1111
registry: chainreg.biz
1112
# -- image repo to use for csi image
1113
repository: scratch-images/test-tmp/openbao-fips
1114
# -- image tag to use for csi image
1115
tag: 2.6.2-r1@sha256:8ab204d58f8e3ea5a71e742f2c2142d5a9f60a3bb566a956d800fd6513325e90
1116
# -- image pull policy to use for csi image. if tag is "latest", set to "Always"
1117
pullPolicy: IfNotPresent
1118
# -- volumes is a list of volumes made available to all containers. These are rendered
1119
# via toYaml rather than pre-processed like the extraVolumes value.
1120
# The purpose is to make it easy to share volumes between containers.
1121
volumes: []
1122
# - name: tls
1123
# secret:
1124
# secretName: openbao-tls
1125
1126
# -- volumeMounts is a list of volumeMounts for the main server container. These are rendered
1127
# via toYaml rather than pre-processed like the extraVolumes value.
1128
# The purpose is to make it easy to share volumes between containers.
1129
volumeMounts: []
1130
# - name: tls
1131
# mountPath: "/openbao/tls"
1132
# readOnly: true
1133
1134
resources: {}
1135
# resources:
1136
# requests:
1137
# cpu: 50m
1138
# memory: 128Mi
1139
# limits:
1140
# cpu: 50m
1141
# memory: 128Mi
1142
1143
# Override the default secret name for the CSI Provider's HMAC key used for
1144
# generating secret versions.
1145
hmacSecretName: ""
1146
# Settings for the daemonSet used to run the provider.
1147
daemonSet:
1148
updateStrategy:
1149
type: RollingUpdate
1150
maxUnavailable: ""
1151
# Extra annotations for the daemonSet. This can either be YAML or a
1152
# YAML-formatted multi-line templated string map of the annotations to apply
1153
# to the daemonSet.
1154
annotations: {}
1155
# Provider host path (must match the CSI provider's path)
1156
providersDir: "/etc/kubernetes/secrets-store-csi-providers"
1157
# Kubelet host path
1158
kubeletRootDir: "/var/lib/kubelet"
1159
# endpoint path for the provider
1160
endpoint: "/provider/openbao.sock"
1161
# Extra labels to attach to the openbao-csi-provider daemonSet
1162
# This should be a YAML map of the labels to apply to the csi provider daemonSet
1163
extraLabels: {}
1164
# Security context for the pod template and container in the csi provider daemonSet.
1165
# The default container securityContext is:
1166
# allowPrivilegeEscalation: false
1167
# readOnlyRootFilesystem: true
1168
# runAsGroup: 1000
1169
# seccompProfile:
1170
# type: RuntimeDefault
1171
# capabilities:
1172
# drop:
1173
# - ALL
1174
# The provider container does not default to runAsNonRoot because it writes
1175
# its socket into the shared providers hostPath.
1176
securityContext:
1177
pod: {}
1178
container: {}
1179
pod:
1180
# Extra annotations for the provider pods. This can either be YAML or a
1181
# YAML-formatted multi-line templated string map of the annotations to apply
1182
# to the pod.
1183
annotations: {}
1184
# Toleration Settings for provider pods
1185
# This should be either a multi-line string or YAML matching the Toleration array
1186
# in a PodSpec.
1187
tolerations: []
1188
# nodeSelector labels for csi pod assignment, formatted as a multi-line string or YAML map.
1189
# ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#nodeselector
1190
# Example:
1191
# nodeSelector:
1192
# beta.kubernetes.io/arch: amd64
1193
nodeSelector: {}
1194
# Affinity Settings
1195
# This should be either a multi-line string or YAML matching the PodSpec's affinity field.
1196
affinity: {}
1197
# Extra labels to attach to the openbao-csi-provider pod
1198
# This should be a YAML map of the labels to apply to the csi provider pod
1199
extraLabels: {}
1200
agent:
1201
enabled: true
1202
extraArgs: []
1203
image:
1204
# -- image registry to use for agent image
1205
registry: chainreg.biz
1206
# -- image repo to use for agent image
1207
repository: scratch-images/test-tmp/openbao-fips
1208
# -- image tag to use for agent image - defaults to chart appVersion
1209
tag: 2.6.2-r1@sha256:8ab204d58f8e3ea5a71e742f2c2142d5a9f60a3bb566a956d800fd6513325e90
1210
# -- image pull policy to use for agent image. if tag is "latest", set to "Always"
1211
pullPolicy: IfNotPresent
1212
logFormat: standard
1213
logLevel: info
1214
resources: {}
1215
# resources:
1216
# requests:
1217
# memory: 256Mi
1218
# cpu: 250m
1219
# limits:
1220
# memory: 256Mi
1221
# cpu: 250m
1222
# Priority class for csi pods
1223
priorityClassName: ""
1224
serviceAccount:
1225
# Extra annotations for the serviceAccount definition. This can either be
1226
# YAML or a YAML-formatted multi-line templated string map of the
1227
# annotations to apply to the serviceAccount.
1228
annotations: {}
1229
# Extra labels to attach to the openbao-csi-provider serviceAccount
1230
# This should be a YAML map of the labels to apply to the csi provider serviceAccount
1231
extraLabels: {}
1232
# Used to configure readinessProbe for the pods.
1233
readinessProbe:
1234
# When a probe fails, Kubernetes will try failureThreshold times before giving up
1235
failureThreshold: 2
1236
# Number of seconds after the container has started before probe initiates
1237
initialDelaySeconds: 5
1238
# How often (in seconds) to perform the probe
1239
periodSeconds: 5
1240
# Minimum consecutive successes for the probe to be considered successful after having failed
1241
successThreshold: 1
1242
# Number of seconds after which the probe times out.
1243
timeoutSeconds: 3
1244
# Used to configure livenessProbe for the pods.
1245
livenessProbe:
1246
# When a probe fails, Kubernetes will try failureThreshold times before giving up
1247
failureThreshold: 2
1248
# Number of seconds after the container has started before probe initiates
1249
initialDelaySeconds: 5
1250
# How often (in seconds) to perform the probe
1251
periodSeconds: 5
1252
# Minimum consecutive successes for the probe to be considered successful after having failed
1253
successThreshold: 1
1254
# Number of seconds after which the probe times out.
1255
timeoutSeconds: 3
1256
# Enables debug logging.
1257
debug: false
1258
# Pass arbitrary additional arguments to openbao-csi-provider.
1259
# See https://openbao.org/docs/platform/k8s/csi/configurations
1260
# for the available command line flags.
1261
extraArgs: []
1262
# OpenBao is able to collect and publish various runtime metrics.
1263
# Enabling this feature requires setting adding `telemetry{}` stanza to
1264
# the OpenBao configuration. There are a few examples included in the `config` sections above.
1265
#
1266
# For more information see:
1267
# https://openbao.org/docs/configuration/telemetry
1268
# https://openbao.org/docs/internals/telemetry
1269
serverTelemetry:
1270
# Enable support for the Prometheus Operator. If authorization is not required for
1271
# OpenBao's metrics endpoint, the following OpenBao server `telemetry{}` config must be included
1272
# in the `listener "tcp"{}` stanza
1273
# telemetry {
1274
# unauthenticated_metrics_access = "true"
1275
# }
1276
#
1277
# See the `standalone.config` for a more complete example of this.
1278
#
1279
# In addition, a top level `telemetry{}` stanza must also be included in the OpenBao configuration:
1280
#
1281
# example:
1282
# telemetry {
1283
# prometheus_retention_time = "30s"
1284
# disable_hostname = true
1285
# }
1286
#
1287
# Configuration for monitoring the OpenBao server.
1288
serviceMonitor:
1289
# The Prometheus operator *must* be installed before enabling this feature,
1290
# if not the chart will fail to install due to missing CustomResourceDefinitions
1291
# provided by the operator.
1292
#
1293
# Instructions on how to install the Helm chart can be found here:
1294
# https://github.com/prometheus-community/helm-charts/tree/main/charts/kube-prometheus-stack
1295
# More information can be found here:
1296
# https://github.com/prometheus-operator/prometheus-operator
1297
# https://github.com/prometheus-operator/kube-prometheus
1298
1299
# Enable deployment of the OpenBao Server ServiceMonitor CustomResource.
1300
enabled: false
1301
# Selector labels to add to the ServiceMonitor.
1302
# When empty, defaults to:
1303
# release: prometheus
1304
selectors: {}
1305
# -- Port which Prometheus uses when scraping metrics. If empty will use `openbao.scheme` helper for its value
1306
port: ""
1307
# -- scheme to use when Prometheus scrapes metrics. If empty will use `openbao.scheme` helper for its value
1308
scheme: ""
1309
# Interval at which Prometheus scrapes metrics
1310
interval: 30s
1311
# Timeout for Prometheus scrapes
1312
scrapeTimeout: 10s
1313
# tlsConfig used for scraping the Vault metrics API.
1314
tlsConfig: {}
1315
# authorization used for scraping the Vault metrics API.
1316
authorization: {}
1317
# -- bearerTokenFile defines the file to read bearer token for scraping the target.
1318
# Deprecated: Use 'serverTelemetry.serviceMonitor.authorization'
1319
bearerTokenFile: ~
1320
# scrapeClass to be used by the serviceMonitor
1321
scrapeClass: ""
1322
prometheusRules:
1323
# The Prometheus operator *must* be installed before enabling this feature,
1324
# if not the chart will fail to install due to missing CustomResourceDefinitions
1325
# provided by the operator.
1326
1327
# Deploy the PrometheusRule custom resource for AlertManager based alerts.
1328
# Requires that AlertManager is properly deployed.
1329
enabled: false
1330
# Selector labels to add to the PrometheusRules.
1331
# When empty, defaults to:
1332
# release: prometheus
1333
selectors: {}
1334
# Some example rules.
1335
rules: []
1336
# - alert: vault-HighResponseTime
1337
# annotations:
1338
# message: The response time of OpenBao is over 500ms on average over the last 5 minutes.
1339
# expr: vault_core_handle_request{quantile="0.5", namespace="mynamespace"} > 500
1340
# for: 5m
1341
# labels:
1342
# severity: warning
1343
# - alert: vault-HighResponseTime
1344
# annotations:
1345
# message: The response time of OpenBao is over 1s on average over the last 10 minutes.
1346
# expr: vault_core_handle_request{quantile="0.5", namespace="mynamespace"} > 1000
1347
# for: 10m
1348
# labels:
1349
# severity: critical
1350
grafanaDashboard:
1351
# Enable deployment of the OpenBao Grafana dashboard.
1352
# https://grafana.com/grafana/dashboards/23725-openbao
1353
enabled: false
1354
# Namespace to deploy the dashboard ConfigMap to.
1355
# Defaults to this chart's namespace.
1356
namespace: ""
1357
# Add `grafana_dashboard: "1"` default label
1358
defaultLabel: true
1359
# Extra labels for dashboard ConfigMap
1360
extraLabel: {}
1361
# Extra annotations for dashboard ConfigMap
1362
extraAnnotations: {}
1363
# extraObjects allows you to add any extra Kubernetes manifests to this chart
1364
extraObjects: []
1365
# Examples:
1366
# Defining as a Structured YAML Object Example:
1367
# extraObjects:
1368
# - apiVersion: v1
1369
# kind: ConfigMap
1370
# metadata:
1371
# name: cert-manager-configmap-{{ .Release.Name }}
1372
#
1373
# Using a String for Advanced Templating Example:
1374
# extraObjects:
1375
# - |
1376
# apiVersion: v1
1377
# kind: ConfigMap
1378
# metadata:
1379
# name: cert-manager-configmap-{{ include "some-other-template" }}
1380
1381
# Snapshot Agent Configuration
1382
snapshotAgent:
1383
# whether or not to enable the snapshot agent cronjob
1384
enabled: false
1385
# extra Annotations for the job
1386
annotations: {}
1387
# concurrencyPolicy for the cronjob. Can be "Allow", "Forbid", or "Replace"
1388
concurrencyPolicy: "Forbid"
1389
# schedule of the cronjob
1390
schedule: "*/15 * * * *"
1391
restartPolicy: OnFailure
1392
# service account settings for the snapshot agent
1393
serviceAccount:
1394
create: true
1395
name: ""
1396
annotations: {}
1397
extraLabels: {}
1398
# The image settings for the snapshot agent
1399
image:
1400
repository: chainreg.biz/scratch-images/test-tmp/openbao-fips
1401
tag: 2.6.2-r1@sha256:8ab204d58f8e3ea5a71e742f2c2142d5a9f60a3bb566a956d800fd6513325e90
1402
# -- List of extraVolumes made available to the snapshot cronjob container.
1403
extraVolumes: []
1404
# - name: openbao-tls
1405
# secret:
1406
# defaultMode: 420
1407
# secretName: openbao-tls
1408
1409
# -- List of additional volumeMounts for the snapshot cronjob container.
1410
extraVolumeMounts: []
1411
# - mountPath: /openbao/tls/ca.crt
1412
# name: openbao-tls
1413
# readOnly: true
1414
# subPath: ca.crt
1415
1416
# -- Existing Kubernetes secret with S3 Credentials.
1417
# Must contain keys called AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY.
1418
# If not provided, you must provide `snapshotAgent.extraSecretEnvironmentVars`
1419
s3CredentialsSecret: ""
1420
# configuration for the snapshot agent
1421
config:
1422
s3Host: "s3.eu-east-1.amazonaws.com"
1423
s3Bucket: "openbao-snapshots"
1424
s3Uri: "s3://openbao-snapshots"
1425
s3ExpireDays: "14"
1426
s3cmdExtraFlag: "-v"
1427
# The path of the Kubernetes authentication backend in OpenBao (e.g. `kubernetes`)
1428
baoAuthPath: "kubernetes"
1429
# OpenBao role to use to create the snapshot
1430
baoRole: "snapshot"
1431
# OpenBao namespace to be used. Leave empty for non-namespace installations.
1432
baoNamespace: ""
1433
# Namespace for bao authentication. If authentication namespace needs to be different to `BAO_NAMESPACE`.
1434
baoAuthNamespace: ""
1435
# Secret path to retrieve S3 credentials from. Expects the secret to have two fields: `AWS_ACCESS_KEY_ID` and `AWS_SECRET_ACCESS_KEY`
1436
baoSecretPath: ""
1437
# The path of the Kubernetes service account token. If unset defaults to `/var/run/secrets/kubernetes.io/serviceaccount/token`.
1438
tokenPath: ""
1439
# configuration of the CronJobs resources
1440
resources: {}
1441
# -- Map of extra environment variables to set in the snapshot-agent cronjob
1442
extraEnvironmentVars: {}
1443
# BAO_CACERT: /openbao/tls/ca.crt
1444
1445
# -- List of extra environment variables to set in the snapshot-agent cronjob
1446
# These variables take value from existing Secret objects.
1447
extraSecretEnvironmentVars: []
1448
# - envName: AWS_SECRET_ACCESS_KEY
1449
# secretName: openbao
1450
# secretKey: AWS_SECRET_ACCESS_KEY
1451
1452
# Security context for the pod template and the snapshotAgent container
1453
# The default pod securityContext is:
1454
# seccompProfile
1455
# type: RuntimeDefault
1456
# runAsNonRoot: true
1457
# runAsGroup: {{ .Values.snapshotAgent.gid | default 1000 }}
1458
# runAsUser: {{ .Values.snapshotAgent.uid | default 100 }}
1459
# fsGroup: {{ .Values.snapshotAgent.gid | default 1000 }}
1460
# and for container is
1461
# allowPrivilegeEscalation: false
1462
# capabilities:
1463
# drop:
1464
# - ALL
1465
securityContext:
1466
pod: {}
1467
container: {}
1468
# Toleration Settings for snapshot-agent cronjob pod
1469
# This should be either a multi-line string or YAML matching the Toleration array
1470
# in a PodSpec.
1471
tolerations: []
1472

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.