1# Copyright (c) HashiCorp, Inc.
2# SPDX-License-Identifier: MPL-2.0
4# Available parameters and their default values for the OpenBao chart.
7 # -- enabled is the master enabled switch. Setting this to true or false
8 # will enable or disable all the components within this chart by default.
10 # -- The namespace to deploy to. Defaults to the `helm` installation namespace.
12 # -- Image pull secret to use for registry authentication.
13 # Alternatively, the value may be specified as an array of strings.
16 # - name: image-pull-secret
18 # -- TLS for end-to-end encrypted transport
20 # -- External openbao server address for the injector and CSI provider to use.
21 # Setting this will disable deployment of an OpenBao server.
23 # -- Deprecated: Please use global.externalBaoAddr instead.
25 # -- If deploying to OpenShift
28 # -- Enable integration with the Prometheus Operator
29 # See the top level serverTelemetry section below before enabling this feature.
30 prometheusOperator: false
32 # -- True if you want to enable openbao agent injection. @default: global.enabled
35 # -- Configures the port the injector should listen on
37 # -- If multiple replicas are specified, by default a leader will be determined
38 # so that only one injector attempts to create TLS certificates.
41 # -- If true, will enable a node exporter metrics endpoint at /metrics.
44 # -- Deprecated: Please use injector.externalBaoAddr instead.
46 # -- External openbao server address for the injector to use.
48 # image sets the repo and tag of the vault-k8s image to use for the injector.
50 # -- image registry to use for k8s image
51 registry: chainreg.biz
52 # -- image repo to use for k8s image
53 repository: scratch-images/test-tmp/openbao-k8s-fips
54 # -- image tag to use for k8s image
55 tag: 1.4.0-r32@sha256:6cd1034b51943754700e0be2ba65466a3f8f13378978360ad788720ed94fadfc
56 # -- image pull policy to use for k8s image. if tag is "latest", set to "Always"
57 pullPolicy: IfNotPresent
58 # -- agentImage sets the repo and tag of the OpenBao image to use for the OpenBao Agent
59 # containers. This should be set to the official OpenBao image. OpenBao 1.3.1+ is
62 # -- image registry to use for agent image
63 registry: chainreg.biz
64 # -- image repo to use for agent image
65 repository: scratch-images/test-tmp/openbao-fips
66 # -- image tag to use for agent image - defaults to chart appVersion
67 tag: 2.6.2-r1@sha256:8ab204d58f8e3ea5a71e742f2c2142d5a9f60a3bb566a956d800fd6513325e90
68 # -- image pull policy to use for agent image. if tag is "latest", set to "Always"
69 pullPolicy: IfNotPresent
70 # The default values for the injected OpenBao Agent containers.
72 # For more information on configuring resources, see the K8s documentation:
73 # https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
78 # ephemeralLimit: "128Mi"
79 # ephemeralRequest: "64Mi"
81 # Default template type for secrets when no custom template is specified.
82 # Possible values include: "json" and "map".
84 # Default values within Agent's template_config stanza.
86 exitOnRetryFailure: true
87 staticSecretRenderInterval: ""
88 # Used to define custom livenessProbe settings
90 # -- When a probe fails, Kubernetes will try failureThreshold times before giving up
92 # -- Number of seconds after the container has started before probe initiates
93 initialDelaySeconds: 5
94 # -- How often (in seconds) to perform the probe
96 # -- Minimum consecutive successes for the probe to be considered successful after having failed
98 # -- Number of seconds after which the probe times out.
100 # Used to define custom readinessProbe settings
102 # -- When a probe fails, Kubernetes will try failureThreshold times before giving up
104 # -- Number of seconds after the container has started before probe initiates
105 initialDelaySeconds: 5
106 # -- How often (in seconds) to perform the probe
108 # -- Minimum consecutive successes for the probe to be considered successful after having failed
110 # -- Number of seconds after which the probe times out.
112 # Used to define custom startupProbe settings
114 # -- When a probe fails, Kubernetes will try failureThreshold times before giving up
116 # -- Number of seconds after the container has started before probe initiates
117 initialDelaySeconds: 5
118 # -- How often (in seconds) to perform the probe
120 # -- Minimum consecutive successes for the probe to be considered successful after having failed
122 # -- Number of seconds after which the probe times out.
124 # Mount Path of the OpenBao Kubernetes Auth Method.
125 authPath: "auth/kubernetes"
126 # -- Configures the log verbosity of the injector.
127 # Supported log levels include: trace, debug, info, warn, error
129 # -- Configures the log format of the injector. Supported log formats: "standard", "json".
130 logFormat: "standard"
131 # Configures all OpenBao Agent sidecars to revoke their token when shutting down
132 revokeOnShutdown: false
134 # Configures failurePolicy of the webhook. The "unspecified" default behaviour depends on the
135 # API Version of the WebHook.
136 # To block pod creation while the webhook is unavailable, set the policy to `Fail` below.
137 # See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#failure-policy
139 failurePolicy: Ignore
140 # matchPolicy specifies the approach to accepting changes based on the rules of
141 # the MutatingWebhookConfiguration.
142 # See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#matching-requests-matchpolicy
146 # timeoutSeconds is the amount of seconds before the webhook request will be ignored
148 # If it is ignored or fails depends on the failurePolicy
149 # See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#timeouts
153 # namespaceSelector is the selector for restricting the webhook to only
154 # specific namespaces.
155 # See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#matching-requests-namespaceselector
160 # sidecar-injector: enabled
161 namespaceSelector: {}
162 # objectSelector is the selector for restricting the webhook to only
164 # See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#matching-requests-objectselector
169 # vault-sidecar-injector: enabled
172 - key: app.kubernetes.io/name
175 - {{ template "openbao.name" . }}-agent-injector
176 # matchConditions is a list of CEL expressions for restricting the webhook to only
178 # See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#matching-requests-matchconditions
182 # - name: has-agent-inject-annotation
183 # expression: 'has(object.metadata.annotations) && "openbao.org/agent-inject" in object.metadata.annotations'
185 # Extra annotations to attach to the webhook
187 # Deprecated: please use 'webhook.failurePolicy' instead
188 # Configures failurePolicy of the webhook. The "unspecified" default behaviour depends on the
189 # API Version of the WebHook.
190 # To block pod creation while webhook is unavailable, set the policy to `Fail` below.
191 # See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#failure-policy
193 failurePolicy: Ignore
194 # Deprecated: please use 'webhook.namespaceSelector' instead
195 # namespaceSelector is the selector for restricting the webhook to only
196 # specific namespaces.
197 # See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#matching-requests-namespaceselector
202 # sidecar-injector: enabled
203 namespaceSelector: {}
204 # Deprecated: please use 'webhook.objectSelector' instead
205 # objectSelector is the selector for restricting the webhook to only
207 # See https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#matching-requests-objectselector
212 # vault-sidecar-injector: enabled
214 # Deprecated: please use 'webhook.annotations' instead
215 # Extra annotations to attach to the webhook
216 webhookAnnotations: {}
218 # secretName is the name of the secret that has the TLS certificate and
219 # private key to serve the injector webhook. If this is null, then the
220 # injector will default to its automatic management mode that will assign
221 # a service account to the injector to generate its own certificates.
223 # caBundle is a base64-encoded PEM-encoded certificate bundle for the CA
224 # that signed the TLS certificate that the webhook serves. This must be set
225 # if secretName is non-null unless an external service like cert-manager is
226 # keeping the caBundle updated.
228 # certName and keyName are the names of the files within the secret for
229 # the TLS cert and private key, respectively. These have reasonable
230 # defaults but can be customized if necessary.
233 # Security context for the pod template and the injector container
234 # The default pod securityContext is:
236 # runAsGroup: {{ .Values.injector.gid | default 1000 }}
237 # runAsUser: {{ .Values.injector.uid | default 100 }}
238 # fsGroup: {{ .Values.injector.gid | default 1000 }}
240 # type: RuntimeDefault
241 # and for container is
242 # allowPrivilegeEscalation: false
258 # extraEnvironmentVars is a list of extra environment variables to set in the
259 # injector deployment.
260 extraEnvironmentVars: {}
261 # KUBERNETES_SERVICE_HOST: kubernetes.default.svc
263 # Affinity Settings for injector pods
264 # This can either be a multi-line string or YAML matching the PodSpec's affinity field.
265 # Commenting out or setting as empty the affinity variable, will allow
266 # deployment of multiple replicas to single node services such as Minikube.
269 requiredDuringSchedulingIgnoredDuringExecution:
272 app.kubernetes.io/name: {{ template "openbao.name" . }}-agent-injector
273 app.kubernetes.io/instance: "{{ .Release.Name }}"
275 topologyKey: kubernetes.io/hostname
276 # Topology settings for injector pods
277 # ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
278 # This should be either a multi-line string or YAML matching the topologySpreadConstraints array
280 topologySpreadConstraints: []
281 # Toleration Settings for injector pods
282 # This should be either a multi-line string or YAML matching the Toleration array
285 # nodeSelector labels for server pod assignment, formatted as a multi-line string or YAML map.
286 # ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#nodeselector
289 # beta.kubernetes.io/arch: amd64
291 # Priority class for injector pods
292 priorityClassName: ""
293 # Extra annotations to attach to the injector pods
294 # This can either be YAML or a YAML-formatted multi-line templated string map
295 # of the annotations to apply to the injector pods
297 # Extra labels to attach to the agent-injector
298 # This should be a YAML map of the labels to apply to the injector
300 # Should the injector pods run on the host network (useful when using
301 # an alternate CNI in EKS)
303 # Injector service specific config
305 # Extra annotations to attach to the injector service
307 # Extra labels for the service definition.
308 # This should be a YAML map of the labels to apply to the injector service
310 # Injector serviceAccount specific config
312 # Extra annotations to attach to the injector serviceAccount
314 # A disruption budget limits the number of pods of a replicated application
315 # that are down simultaneously from voluntary disruptions
316 podDisruptionBudget: {}
317 # podDisruptionBudget:
320 # strategy for updating the deployment. This can be a multi-line string or a
326 # maxUnavailable: 25%
327 # type: RollingUpdate
329 # If true, or "-" with global.enabled true, OpenBao server will be installed.
330 # See openbao.mode in _helpers.tpl for implementation details.
332 # Resource requests, limits, etc. for the server cluster placement. This
333 # should map directly to the value of the resources field for a PodSpec.
334 # By default no direct resource request is made.
336 # -- image registry to use for server image
337 registry: chainreg.biz
338 # -- image repo to use for server image
339 repository: scratch-images/test-tmp/openbao-fips
340 # -- image tag to use for server image - defaults to chart appVersion
341 tag: 2.6.2-r1@sha256:8ab204d58f8e3ea5a71e742f2c2142d5a9f60a3bb566a956d800fd6513325e90
342 # -- image pull policy to use for server image. if tag is "latest", set to "Always"
343 pullPolicy: IfNotPresent
344 # Configure the Update Strategy Type for the StatefulSet
345 # See https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#update-strategies
346 updateStrategyType: "OnDelete"
347 # Configure the pod management policy for the StatefulSet
348 # See https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#pod-management-policies
349 podManagementPolicy: "OrderedReady"
350 # Configure the logging verbosity for the OpenBao server.
351 # Supported log levels include: trace, debug, info, warn, error
353 # Configure the logging format for the OpenBao server.
354 # Supported log formats include: standard, json
365 # Ingress allows ingress services to be created to allow external access
366 # from Kubernetes to access OpenBao pods.
367 # If deployment is on OpenShift, the following block is ignored.
368 # In order to expose the service, use the route section below
375 # kubernetes.io/ingress.class: nginx
376 # kubernetes.io/tls-acme: "true"
378 # kubernetes.io/ingress.class: nginx
379 # kubernetes.io/tls-acme: "true"
381 # Optionally use ingressClassName instead of deprecated annotation.
382 # See: https://kubernetes.io/docs/concepts/services-networking/ingress/#deprecated-annotation
384 # As of Kubernetes 1.19, all Ingress Paths must have a pathType configured. The default value below should be sufficient in most cases.
385 # See: https://kubernetes.io/docs/concepts/services-networking/ingress/#path-types for other possible values.
387 # When HA mode is enabled and K8s service registration is being used,
388 # configure the ingress to point to the OpenBao active service.
391 - host: chart-example.local
393 ## Extra paths to prepend to the host configuration. This is useful when working with annotation based services.
400 # number: use-annotation
402 # - secretName: chart-example-tls
404 # - chart-example.local
405 # Gateway consolidates configuration related to the Kubernetes Gateway API
406 # Currently, only creating a TLSRoute is supported
407 # See: https://gateway-api.sigs.k8s.io/
409 # Configures a TLSRoute for the OpenBao server. This can be enabled independently of the ingress configuration to allow for side-by-side scenarios for migration.
415 # external-dns.alpha.kubernetes.io/hostname: chart-example.local
418 # - chart-example.local
420 # Allows overriding the TLSRoutes apiVersion in case a different version of Gateway API is installed on the cluster.
421 apiVersion: gateway.networking.k8s.io/v1alpha3
422 # When HA mode is enabled and K8s service registration is being used,
423 # configure the ingress to point to the OpenBao active service.
425 # List of ParentRefs. As the helm chart configures no gateways itself,
426 # this should be set to at least one gateway with one or more TLS listeners
429 # namespace: gateway-namespace
430 # # sectionName is optional to fix to a specific listener
431 # sectionName: listener-name
432 # Configures a HTTPRoute for the OpenBao server. This can be enabled independently of the ingress configuration to allow for side-by-side scenarios for migration.
433 # WARNING: Terminating TLS before reaching the OpenBao Server is not recommended and may break things like certificate authentication. Prefer usage of `TLSRoute`.
439 # external-dns.alpha.kubernetes.io/hostname: chart-example.local
442 - chart-example.local
443 # Allows overriding the HTTPRoute apiVersion in case a different version of Gateway API is installed on the cluster.
444 apiVersion: gateway.networking.k8s.io/v1
445 # When HA mode is enabled and K8s service registration is being used,
446 # configure the ingress to point to the OpenBao active service.
448 # List of ParentRefs. As the helm chart configures no gateways itself,
449 # this should be set to at least one gateway with one or more HTTP listeners
452 # namespace: gateway-namespace
453 # # sectionName is optional to fix to a specific listener
454 # sectionName: listener-name
461 # request: 10s #Maximum time the Gateway waits to complete the full client request and response cycle.
462 # backendRequest: 10s # Maximum time the Gateway waits for a response from the backend service.
464 # - type: RequestHeaderModifier
465 # requestHeaderModifier:
467 # - name: X-Forwarded-Proto
469 # If TLS is enable on server (see global.tlsDisable) the gateway must be configured
470 # with BackendTLSPolicy to correctly handles TLS connection with server in case TLS termination happens at gateway
476 # external-dns.alpha.kubernetes.io/hostname: chart-example.local
478 # Allows overriding the BackendTLSPolicy apiVersion in case a different version of Gateway API is installed on the cluster.
479 apiVersion: gateway.networking.k8s.io/v1
480 # When HA mode is enabled and K8s service registration is being used,
481 # configure the ingress to point to the OpenBao active service.
483 # Identifies an API object to apply the policy to.
484 # If no one is specified the default is to target the OpenBao service
491 # hostAliases is a list of aliases to be added to /etc/hosts. Specified as a YAML list.
495 # - chart-example.local
497 # OpenShift only - create a route to expose the service
498 # By default the created route will be of type passthrough
501 # When HA mode is enabled and K8s service registration is being used,
502 # configure the route to point to the OpenBao active service.
506 host: chart-example.local
507 # tls will be passed directly to the route's TLS config, which
508 # can be used to configure other termination methods that terminate
511 termination: passthrough
512 # authDelegator enables a cluster role binding to be attached to the service
513 # account. This cluster role binding can be used to setup Kubernetes auth
514 # method. See https://openbao.org/docs/auth/kubernetes
517 # -- extraInitContainers is a list of init containers. Specified as a YAML list.
518 # This is useful if you need to run a script to provision TLS certificates or
519 # write out configuration files in a dynamic way.
520 extraInitContainers: []
521 # # This example installs a plugin pulled from github into the /usr/local/libexec/vault/oauthapp folder,
522 # # which is defined in the volumes value.
528 # wget https://github.com/puppetlabs/vault-plugin-secrets-oauthapp/releases/download/v1.2.0/vault-plugin-secrets-oauthapp-v1.2.0-linux-amd64.tar.xz -O oauthapp.xz &&
529 # tar -xf oauthapp.xz &&
530 # mv vault-plugin-secrets-oauthapp-v1.2.0-linux-amd64 /usr/local/libexec/vault/oauthapp &&
531 # chmod +x /usr/local/libexec/vault/oauthapp
534 # mountPath: /usr/local/libexec/vault
536 # extraContainers is a list of sidecar containers. Specified as a YAML list.
537 extraContainers: null
538 # -- shareProcessNamespace enables process namespace sharing between OpenBao and the extraContainers
539 # This is useful if OpenBao must be signaled, e.g. to send a SIGHUP for a log rotation
540 shareProcessNamespace: false
541 # -- extraArgs is a string containing additional OpenBao server arguments.
543 # -- extraPorts is a list of extra ports. Specified as a YAML list.
544 # This is useful if you need to add additional ports to the statefulset in dynamic way.
546 # - containerPort: 8300
547 # name: http-monitoring
549 # Used to define custom readinessProbe settings
552 # If you need to use a http path instead of the default exec
553 # path: /v1/sys/health?standbyok=true
555 # Port number on which readinessProbe will be checked.
557 # When a probe fails, Kubernetes will try failureThreshold times before giving up
559 # Number of seconds after the container has started before probe initiates
560 initialDelaySeconds: 5
561 # How often (in seconds) to perform the probe
563 # Minimum consecutive successes for the probe to be considered successful after having failed
565 # Number of seconds after which the probe times out.
567 # Used to enable a livenessProbe for the pods
570 # Used to define a liveness exec command. If provided, exec is preferred to httpGet (path) as the livenessProbe handler.
574 # - /openbao/userconfig/mylivenessscript/run.sh
575 # Path for the livenessProbe to use httpGet as the livenessProbe handler
576 path: "/v1/sys/health?standbyok=true"
577 # Port number on which livenessProbe will be checked if httpGet is used as the livenessProbe handler
579 # When a probe fails, Kubernetes will try failureThreshold times before giving up
581 # Number of seconds after the container has started before probe initiates
582 initialDelaySeconds: 60
583 # How often (in seconds) to perform the probe
585 # Minimum consecutive successes for the probe to be considered successful after having failed
587 # Number of seconds after which the probe times out.
589 # Optional duration in seconds the pod needs to terminate gracefully.
590 # See: https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/
591 terminationGracePeriodSeconds: 10
592 # Used to set the sleep time during the preStop step
593 preStopSleepSeconds: 5
594 # Used to define commands to run after the pod is ready.
595 # This can be used to automate processes such as initialization
596 # or bootstrapping auth methods.
600 # - /openbao/userconfig/myscript/run.sh
602 # extraEnvironmentVars is a list of extra environment variables to set with the stateful set. These could be
603 # used to include variables required for auto-unseal.
604 extraEnvironmentVars: {}
605 # GOOGLE_REGION: global
606 # GOOGLE_PROJECT: myproject
607 # GOOGLE_APPLICATION_CREDENTIALS: /openbao/userconfig/myproject/myproject-creds.json
609 # extraSecretEnvironmentVars is a list of extra environment variables to set with the stateful set.
610 # These variables take value from existing Secret objects.
611 extraSecretEnvironmentVars: []
612 # - envName: AWS_SECRET_ACCESS_KEY
613 # secretName: openbao
614 # secretKey: AWS_SECRET_ACCESS_KEY
616 # Deprecated: please use 'volumes' instead.
617 # extraVolumes is a list of extra volumes to mount. These will be exposed
618 # to OpenBao in the path `/openbao/userconfig/<name>/`. The value below is
619 # an array of objects, examples are shown below.
621 # - type: secret (or "configMap")
623 # path: null # default is `/openbao/userconfig`
625 # volumes is a list of volumes made available to all containers. These are rendered
626 # via toYaml rather than pre-processed like the extraVolumes value.
627 # The purpose is to make it easy to share volumes between containers.
632 # volumeMounts is a list of volumeMounts for the main server container. These are rendered
633 # via toYaml rather than pre-processed like the extraVolumes value.
634 # The purpose is to make it easy to share volumes between containers.
636 # - mountPath: /usr/local/libexec/vault
641 # Commenting out or setting as empty the affinity variable, will allow
642 # deployment to single node services such as Minikube
643 # This should be either a multi-line string or YAML matching the PodSpec's affinity field.
646 requiredDuringSchedulingIgnoredDuringExecution:
649 app.kubernetes.io/name: {{ template "openbao.name" . }}
650 app.kubernetes.io/instance: "{{ .Release.Name }}"
652 topologyKey: kubernetes.io/hostname
653 # Topology settings for server pods
654 # ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
655 # This should be either a multi-line string or YAML matching the topologySpreadConstraints array
657 topologySpreadConstraints: []
658 # Toleration Settings for server pods
659 # This should be either a multi-line string or YAML matching the Toleration array
662 # nodeSelector labels for server pod assignment, formatted as a multi-line string or YAML map.
663 # ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#nodeselector
666 # beta.kubernetes.io/arch: amd64
668 # Enables network policy for server pods
681 - namespaceSelector: {}
687 # Priority class for server pods
688 priorityClassName: ""
689 # Extra labels to attach to the server pods
690 # This should be a YAML map of the labels to apply to the server pods
692 # Extra annotations to attach to the server pods
693 # This can either be YAML or a YAML-formatted multi-line templated string map
694 # of the annotations to apply to the server pods
696 # Add an annotation to the server configmap and the statefulset pods,
697 # vaultproject.io/config-checksum, that is a hash of the OpenBao configuration.
698 # This can be used together with an OnDelete deployment strategy to help
699 # identify which pods still need to be deleted during a deployment to pick up
700 # any configuration changes.
701 configAnnotation: false
702 # Enables a headless service to be used by the OpenBao Statefulset
705 # Enable or disable the openbao-active service, which selects OpenBao pods that
706 # have labeled themselves as the cluster leader with `openbao-active: "true"`.
709 # Extra annotations for the service definition. This can either be YAML or a
710 # YAML-formatted multi-line templated string map of the annotations to apply
711 # to the active service.
713 # Extra labels for the service definition.
714 # This should be a YAML map of the labels to apply to the active service
716 # Enable or disable the openbao-standby service, which selects OpenBao pods that
717 # have labeled themselves as a cluster follower with `openbao-active: "false"`.
720 # Extra annotations for the service definition. This can either be YAML or a
721 # YAML-formatted multi-line templated string map of the annotations to apply
722 # to the standby service.
724 # Extra labels for the service definition.
725 # This should be a YAML map of the labels to apply to the standby service
728 # Extra annotations for the headless service definition. This can either be YAML or a
729 # YAML-formatted multi-line templated string map of the annotations to apply
730 # to the headless service.
732 # If enabled, the service selectors will include `app.kubernetes.io/instance: {{ .Release.Name }}`
733 # When disabled, services may select OpenBao pods not deployed from the chart.
734 # Does not affect the headless openbao-internal service with `ClusterIP: None`
737 # clusterIP controls whether a Cluster IP address is attached to the
738 # OpenBao service within Kubernetes. By default, the OpenBao service will
739 # be given a Cluster IP address, set to None to disable. When disabled
740 # Kubernetes will create a "headless" service. Headless services can be
741 # used to communicate with pods directly through DNS instead of a round-robin
745 # Configures the service type for the main OpenBao service. Can be ClusterIP
749 # The IP family and IP families options are to set the behaviour in a dual-stack environment.
750 # Omitting these values will let the service fall back to whatever the CNI dictates the defaults
753 # Configures the service's supported IP family policy, can be either:
754 # SingleStack: Single-stack service. The control plane allocates a cluster IP for the Service, using the first configured service cluster IP range.
755 # PreferDualStack: Allocates IPv4 and IPv6 cluster IPs for the Service.
756 # RequireDualStack: Allocates Service .spec.ClusterIPs from both IPv4 and IPv6 address ranges.
758 # Sets the families that should be supported and the order in which they should be applied to ClusterIP as well.
759 # Can be IPv4 and/or IPv6.
761 # Do not wait for pods to be ready before including them in the services'
762 # targets. Does not apply to the headless service, which is used for
763 # cluster-internal communication.
764 publishNotReadyAddresses: true
765 # The externalTrafficPolicy can be set to either Cluster or Local
766 # and is only valid for LoadBalancer and NodePort service types.
767 # The default value is Cluster.
768 # ref: https://kubernetes.io/docs/concepts/services-networking/service/#external-traffic-policy
769 externalTrafficPolicy: Cluster
770 # If type is set to "NodePort", a specific nodePort value can be configured,
771 # will be random if left blank.
774 # When HA mode is enabled
775 # If type is set to "NodePort", a specific nodePort value can be configured,
776 # will be random if left blank.
777 # activeNodePort: 30001
779 # When HA mode is enabled
780 # If type is set to "NodePort", a specific nodePort value can be configured,
781 # will be random if left blank.
782 # standbyNodePort: 30002
784 # Port on which OpenBao server is listening
786 # Target port to which the service should be mapped to
788 # -- extraPorts is a list of extra ports. Specified as a YAML list.
789 # This is useful if you need to add additional ports to the server service in dynamic way.
795 # Extra annotations for the service definition. This can either be YAML or a
796 # YAML-formatted multi-line templated string map of the annotations to apply
799 # Extra labels for the service definition.
800 # This should be a YAML map of the labels to apply to the service
802 # This configures the OpenBao Statefulset to create a PVC for data
803 # storage when using the file or raft backend storage engines.
804 # See https://openbao.org/docs/configuration/storage to know more
807 # Size of the PVC created
809 # Location where the PVC will be mounted.
810 mountPath: "/openbao/data"
811 # Name of the storage class to use. If null it will use the
812 # configured default Storage Class.
814 # Access Mode of the storage device being used for the PVC
815 accessMode: ReadWriteOnce
816 # Annotations to apply to the PVC
818 # Labels to apply to the PVC
820 # Persistent Volume Claim (PVC) retention policy
821 # ref: https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#persistentvolumeclaim-retention
823 # persistentVolumeClaimRetentionPolicy:
824 # whenDeleted: Retain
826 persistentVolumeClaimRetentionPolicy: {}
827 # This configures the OpenBao Statefulset to create a PVC for audit
828 # logs. Once OpenBao is deployed, initialized, and unsealed, OpenBao must
829 # be configured to use this for audit logs. This will be mounted to
831 # See https://openbao.org/docs/audit to know more
834 # Size of the PVC created
836 # Location where the PVC will be mounted.
837 mountPath: "/openbao/audit"
838 # Name of the storage class to use. If null it will use the
839 # configured default Storage Class.
841 # Access Mode of the storage device being used for the PVC
842 accessMode: ReadWriteOnce
843 # Annotations to apply to the PVC
845 # Labels to apply to the PVC
847 # Run OpenBao in "dev" mode. This requires no further setup, no state management,
848 # and no initialization. This is useful for experimenting with OpenBao without
849 # needing to unseal, store keys, et. al. All data is lost on restart - do not
850 # use dev mode for anything other than experimenting.
851 # See https://openbao.org/docs/concepts/dev-server to know more
854 # Set VAULT_DEV_ROOT_TOKEN_ID value
856 # Run OpenBao in "standalone" mode. This is the default mode that will deploy if
857 # no arguments are given to helm. This requires a PVC for data storage to use
858 # the "file" backend. This mode is not highly available and should not be scaled
859 # past a single replica.
862 # config is a raw string of default configuration when using a Stateful
863 # deployment. Default is to use a PersistentVolumeClaim mounted at /openbao/data
864 # and store data there. This is only used when using a Replica count of 1, and
865 # using a stateful set. This should be HCL.
867 # Note: Configuration files are stored in ConfigMaps so sensitive data
868 # such as passwords should be either mounted through extraSecretEnvironmentVars
869 # or through a Kube secret. For more information see:
870 # https://openbao.org/docs/platform/k8s/helm/run/#protecting-sensitive-openbao-configurations
876 address = "[::]:8200"
877 cluster_address = "[::]:8201"
878 # Enable unauthenticated metrics access (necessary for Prometheus Operator)
880 # unauthenticated_metrics_access = "true"
884 path = "/openbao/data"
887 # Example configuration for using auto-unseal, using Google Cloud KMS. The
888 # GKMS keys must already exist, and the cluster must have a service account
889 # that is authorized to access GCP KMS.
891 # project = "openbao-helm-dev"
893 # key_ring = "openbao-helm-unseal-kr"
894 # crypto_key = "openbao-helm-unseal-key"
897 # Example configuration for enabling Prometheus metrics in your config.
899 # prometheus_retention_time = "30s"
900 # disable_hostname = true
902 # Run OpenBao in "HA" mode. There are no storage requirements unless the audit log
903 # persistence is required. In HA mode OpenBao will configure itself to use Consul
904 # for its storage backend. The default configuration provided will work the Consul
905 # Helm project by default. It is possible to manually configure OpenBao to use a
906 # different HA backend.
910 # Set the api_addr configuration for OpenBao HA
911 # See https://openbao.org/docs/configuration/#high-availability-parameters
912 # If set to null, this will be set to the Pod IP Address
914 # Set the cluster_addr configuration for OpenBao HA
915 # See https://openbao.org/docs/configuration/#high-availability-parameters
916 # If set to null, this will be set to https://$(HOSTNAME).{{ template "openbao.fullname" . }}-internal:8201
918 # Enables OpenBao's integrated Raft storage. Unlike the typical HA modes where
919 # OpenBao's persistence is external (such as Consul), enabling Raft mode will create
920 # persistent volumes for OpenBao to store data according to the configuration under server.dataStorage.
921 # The OpenBao cluster will coordinate leader elections and failovers internally.
923 # Enables Raft integrated storage
925 # Set the Node Raft ID to the name of the pod
927 # config is a raw string of default configuration when using a Stateful
929 # This should be HCL.
931 # Note: Configuration files are stored in ConfigMaps so sensitive data
932 # such as passwords should be either mounted through extraSecretEnvironmentVars
933 # or through a Kube secret. For more information see:
934 # https://openbao.org/docs/platform/k8s/helm/run/#protecting-sensitive-openbao-configurations
940 address = "[::]:8200"
941 cluster_address = "[::]:8201"
942 # Enable unauthenticated metrics access (necessary for Prometheus Operator)
944 # unauthenticated_metrics_access = "true"
949 path = "/openbao/data"
952 service_registration "kubernetes" {}
953 # config is a raw string of default configuration when using a Stateful
954 # deployment. Default is to use a Consul for its HA storage backend.
955 # This should be HCL.
957 # Note: Configuration files are stored in ConfigMaps so sensitive data
958 # such as passwords should be either mounted through extraSecretEnvironmentVars
959 # or through a Kube secret. For more information see:
960 # https://openbao.org/docs/platform/k8s/helm/run/#protecting-sensitive-openbao-configurations
966 address = "[::]:8200"
967 cluster_address = "[::]:8201"
971 address = "HOST_IP:8500"
974 service_registration "kubernetes" {}
976 # Example configuration for using auto-unseal, using Google Cloud KMS. The
977 # GKMS keys must already exist, and the cluster must have a service account
978 # that is authorized to access GCP KMS.
980 # project = "openbao-helm-dev-246514"
982 # key_ring = "openbao-helm-unseal-kr"
983 # crypto_key = "openbao-helm-unseal-key"
986 # Example configuration for enabling Prometheus metrics.
987 # If you are using Prometheus Operator you can enable a ServiceMonitor resource below.
988 # You may wish to enable unauthenticated metrics in the listener block above.
990 # prometheus_retention_time = "30s"
991 # disable_hostname = true
993 # A disruption budget limits the number of pods of a replicated application
994 # that are down simultaneously from voluntary disruptions
997 # maxUnavailable will default to (n/2)-1 where n is the number of
998 # replicas. If you'd like a custom value, you can specify an override here.
1000 # Definition of the serviceAccount used to run Vault.
1001 # These options are also used when using an external OpenBao server to validate
1002 # Kubernetes tokens.
1004 # Specifies whether a service account should be created
1006 # The name of the service account to use.
1007 # If not set and create is true, a name is generated using the fullname template
1009 # Create a Secret API object to store a non-expiring token for the service account.
1010 # Prior to v1.24.0, Kubernetes used to generate this secret for each service account by default.
1011 # Kubernetes now recommends using short-lived tokens from the TokenRequest API or projected volumes instead if possible.
1012 # For more details, see https://kubernetes.io/docs/concepts/configuration/secret/#serviceaccount-token-secrets
1013 # serviceAccount.create must be equal to 'true' in order to use this feature.
1015 # Extra annotations for the serviceAccount definition. This can either be
1016 # YAML or a YAML-formatted multi-line templated string map of the
1017 # annotations to apply to the serviceAccount.
1019 # Extra labels to attach to the serviceAccount
1020 # This should be a YAML map of the labels to apply to the serviceAccount
1022 # Enable or disable a service account role binding with the permissions required for
1023 # OpenBao's Kubernetes service_registration config option.
1024 # See https://openbao.org/docs/configuration/service-registration/kubernetes
1027 # Settings for the statefulSet used to run OpenBao.
1029 # Extra annotations for the statefulSet. This can either be YAML or a
1030 # YAML-formatted multi-line templated string map of the annotations to apply
1031 # to the statefulSet.
1033 # Set the pod and container security contexts.
1034 # If not set, these will default to, and for *not* OpenShift:
1036 # runAsNonRoot: true
1037 # runAsGroup: {{ .Values.server.gid | default 1000 }}
1038 # runAsUser: {{ .Values.server.uid | default 100 }}
1039 # fsGroup: {{ .Values.server.gid | default 1000 }}
1041 # type: RuntimeDefault
1043 # allowPrivilegeEscalation: false
1045 # If not set, these will default to, and for OpenShift:
1051 # Should the server pods run on the host network
1055 # True if you want to create a Service entry for the OpenBao UI.
1057 # serviceType can be used to control the type of service created. For
1058 # example, setting this to "LoadBalancer" will create an external load
1059 # balancer (for supported K8S installations) to access the UI.
1061 publishNotReadyAddresses: true
1062 # The service should only contain selectors for active OpenBao pod
1063 activeOpenbaoPodOnly: false
1064 serviceType: "ClusterIP"
1065 serviceNodePort: null
1068 # The IP family and IP families options are to set the behaviour in a dual-stack environment.
1069 # Omitting these values will let the service fall back to whatever the CNI dictates the defaults
1072 # Configures the service's supported IP family, can be either:
1073 # SingleStack: Single-stack service. The control plane allocates a cluster IP for the Service, using the first configured service cluster IP range.
1074 # PreferDualStack: Allocates IPv4 and IPv6 cluster IPs for the Service.
1075 # RequireDualStack: Allocates Service .spec.ClusterIPs from both IPv4 and IPv6 address ranges.
1076 serviceIPFamilyPolicy: ""
1077 # Sets the families that should be supported and the order in which they should be applied to ClusterIP as well
1078 # Can be IPv4 and/or IPv6.
1079 serviceIPFamilies: []
1080 # The externalTrafficPolicy can be set to either Cluster or Local
1081 # and is only valid for LoadBalancer and NodePort service types.
1082 # The default value is Cluster.
1083 # ref: https://kubernetes.io/docs/concepts/services-networking/service/#external-traffic-policy
1084 externalTrafficPolicy: Cluster
1085 # loadBalancerSourceRanges:
1091 # Extra annotations to attach to the ui service
1092 # This can either be YAML or a YAML-formatted multi-line templated string map
1093 # of the annotations to apply to the ui service
1095 # Extra labels for the service definition.
1096 # This should be a YAML map of the labels to apply to the ui service
1098# openbao-csi-provider
1100 # -- True if you want to install an openbao-csi-provider daemonset.
1102 # Requires installing the secrets-store-csi-driver separately, see:
1103 # https://secrets-store-csi-driver.sigs.k8s.io/getting-started/installation
1105 # With the driver and provider installed, you can mount OpenBao secrets into volumes
1106 # similar to the OpenBao Agent injector, and you can also sync those secrets into
1107 # Kubernetes secrets.
1110 # -- image registry to use for csi image
1111 registry: chainreg.biz
1112 # -- image repo to use for csi image
1113 repository: scratch-images/test-tmp/openbao-fips
1114 # -- image tag to use for csi image
1115 tag: 2.6.2-r1@sha256:8ab204d58f8e3ea5a71e742f2c2142d5a9f60a3bb566a956d800fd6513325e90
1116 # -- image pull policy to use for csi image. if tag is "latest", set to "Always"
1117 pullPolicy: IfNotPresent
1118 # -- volumes is a list of volumes made available to all containers. These are rendered
1119 # via toYaml rather than pre-processed like the extraVolumes value.
1120 # The purpose is to make it easy to share volumes between containers.
1124 # secretName: openbao-tls
1126 # -- volumeMounts is a list of volumeMounts for the main server container. These are rendered
1127 # via toYaml rather than pre-processed like the extraVolumes value.
1128 # The purpose is to make it easy to share volumes between containers.
1131 # mountPath: "/openbao/tls"
1143 # Override the default secret name for the CSI Provider's HMAC key used for
1144 # generating secret versions.
1146 # Settings for the daemonSet used to run the provider.
1151 # Extra annotations for the daemonSet. This can either be YAML or a
1152 # YAML-formatted multi-line templated string map of the annotations to apply
1155 # Provider host path (must match the CSI provider's path)
1156 providersDir: "/etc/kubernetes/secrets-store-csi-providers"
1158 kubeletRootDir: "/var/lib/kubelet"
1159 # endpoint path for the provider
1160 endpoint: "/provider/openbao.sock"
1161 # Extra labels to attach to the openbao-csi-provider daemonSet
1162 # This should be a YAML map of the labels to apply to the csi provider daemonSet
1164 # Security context for the pod template and container in the csi provider daemonSet.
1165 # The default container securityContext is:
1166 # allowPrivilegeEscalation: false
1167 # readOnlyRootFilesystem: true
1170 # type: RuntimeDefault
1174 # The provider container does not default to runAsNonRoot because it writes
1175 # its socket into the shared providers hostPath.
1180 # Extra annotations for the provider pods. This can either be YAML or a
1181 # YAML-formatted multi-line templated string map of the annotations to apply
1184 # Toleration Settings for provider pods
1185 # This should be either a multi-line string or YAML matching the Toleration array
1188 # nodeSelector labels for csi pod assignment, formatted as a multi-line string or YAML map.
1189 # ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#nodeselector
1192 # beta.kubernetes.io/arch: amd64
1195 # This should be either a multi-line string or YAML matching the PodSpec's affinity field.
1197 # Extra labels to attach to the openbao-csi-provider pod
1198 # This should be a YAML map of the labels to apply to the csi provider pod
1204 # -- image registry to use for agent image
1205 registry: chainreg.biz
1206 # -- image repo to use for agent image
1207 repository: scratch-images/test-tmp/openbao-fips
1208 # -- image tag to use for agent image - defaults to chart appVersion
1209 tag: 2.6.2-r1@sha256:8ab204d58f8e3ea5a71e742f2c2142d5a9f60a3bb566a956d800fd6513325e90
1210 # -- image pull policy to use for agent image. if tag is "latest", set to "Always"
1211 pullPolicy: IfNotPresent
1222 # Priority class for csi pods
1223 priorityClassName: ""
1225 # Extra annotations for the serviceAccount definition. This can either be
1226 # YAML or a YAML-formatted multi-line templated string map of the
1227 # annotations to apply to the serviceAccount.
1229 # Extra labels to attach to the openbao-csi-provider serviceAccount
1230 # This should be a YAML map of the labels to apply to the csi provider serviceAccount
1232 # Used to configure readinessProbe for the pods.
1234 # When a probe fails, Kubernetes will try failureThreshold times before giving up
1236 # Number of seconds after the container has started before probe initiates
1237 initialDelaySeconds: 5
1238 # How often (in seconds) to perform the probe
1240 # Minimum consecutive successes for the probe to be considered successful after having failed
1242 # Number of seconds after which the probe times out.
1244 # Used to configure livenessProbe for the pods.
1246 # When a probe fails, Kubernetes will try failureThreshold times before giving up
1248 # Number of seconds after the container has started before probe initiates
1249 initialDelaySeconds: 5
1250 # How often (in seconds) to perform the probe
1252 # Minimum consecutive successes for the probe to be considered successful after having failed
1254 # Number of seconds after which the probe times out.
1256 # Enables debug logging.
1258 # Pass arbitrary additional arguments to openbao-csi-provider.
1259 # See https://openbao.org/docs/platform/k8s/csi/configurations
1260 # for the available command line flags.
1262# OpenBao is able to collect and publish various runtime metrics.
1263# Enabling this feature requires setting adding `telemetry{}` stanza to
1264# the OpenBao configuration. There are a few examples included in the `config` sections above.
1266# For more information see:
1267# https://openbao.org/docs/configuration/telemetry
1268# https://openbao.org/docs/internals/telemetry
1270 # Enable support for the Prometheus Operator. If authorization is not required for
1271 # OpenBao's metrics endpoint, the following OpenBao server `telemetry{}` config must be included
1272 # in the `listener "tcp"{}` stanza
1274 # unauthenticated_metrics_access = "true"
1277 # See the `standalone.config` for a more complete example of this.
1279 # In addition, a top level `telemetry{}` stanza must also be included in the OpenBao configuration:
1283 # prometheus_retention_time = "30s"
1284 # disable_hostname = true
1287 # Configuration for monitoring the OpenBao server.
1289 # The Prometheus operator *must* be installed before enabling this feature,
1290 # if not the chart will fail to install due to missing CustomResourceDefinitions
1291 # provided by the operator.
1293 # Instructions on how to install the Helm chart can be found here:
1294 # https://github.com/prometheus-community/helm-charts/tree/main/charts/kube-prometheus-stack
1295 # More information can be found here:
1296 # https://github.com/prometheus-operator/prometheus-operator
1297 # https://github.com/prometheus-operator/kube-prometheus
1299 # Enable deployment of the OpenBao Server ServiceMonitor CustomResource.
1301 # Selector labels to add to the ServiceMonitor.
1302 # When empty, defaults to:
1303 # release: prometheus
1305 # -- Port which Prometheus uses when scraping metrics. If empty will use `openbao.scheme` helper for its value
1307 # -- scheme to use when Prometheus scrapes metrics. If empty will use `openbao.scheme` helper for its value
1309 # Interval at which Prometheus scrapes metrics
1311 # Timeout for Prometheus scrapes
1313 # tlsConfig used for scraping the Vault metrics API.
1315 # authorization used for scraping the Vault metrics API.
1317 # -- bearerTokenFile defines the file to read bearer token for scraping the target.
1318 # Deprecated: Use 'serverTelemetry.serviceMonitor.authorization'
1320 # scrapeClass to be used by the serviceMonitor
1323 # The Prometheus operator *must* be installed before enabling this feature,
1324 # if not the chart will fail to install due to missing CustomResourceDefinitions
1325 # provided by the operator.
1327 # Deploy the PrometheusRule custom resource for AlertManager based alerts.
1328 # Requires that AlertManager is properly deployed.
1330 # Selector labels to add to the PrometheusRules.
1331 # When empty, defaults to:
1332 # release: prometheus
1334 # Some example rules.
1336 # - alert: vault-HighResponseTime
1338 # message: The response time of OpenBao is over 500ms on average over the last 5 minutes.
1339 # expr: vault_core_handle_request{quantile="0.5", namespace="mynamespace"} > 500
1343 # - alert: vault-HighResponseTime
1345 # message: The response time of OpenBao is over 1s on average over the last 10 minutes.
1346 # expr: vault_core_handle_request{quantile="0.5", namespace="mynamespace"} > 1000
1349 # severity: critical
1351 # Enable deployment of the OpenBao Grafana dashboard.
1352 # https://grafana.com/grafana/dashboards/23725-openbao
1354 # Namespace to deploy the dashboard ConfigMap to.
1355 # Defaults to this chart's namespace.
1357 # Add `grafana_dashboard: "1"` default label
1359 # Extra labels for dashboard ConfigMap
1361 # Extra annotations for dashboard ConfigMap
1362 extraAnnotations: {}
1363# extraObjects allows you to add any extra Kubernetes manifests to this chart
1366# Defining as a Structured YAML Object Example:
1371# name: cert-manager-configmap-{{ .Release.Name }}
1373# Using a String for Advanced Templating Example:
1379# name: cert-manager-configmap-{{ include "some-other-template" }}
1381# Snapshot Agent Configuration
1383 # whether or not to enable the snapshot agent cronjob
1385 # extra Annotations for the job
1387 # concurrencyPolicy for the cronjob. Can be "Allow", "Forbid", or "Replace"
1388 concurrencyPolicy: "Forbid"
1389 # schedule of the cronjob
1390 schedule: "*/15 * * * *"
1391 restartPolicy: OnFailure
1392 # service account settings for the snapshot agent
1398 # The image settings for the snapshot agent
1400 repository: chainreg.biz/scratch-images/test-tmp/openbao-fips
1401 tag: 2.6.2-r1@sha256:8ab204d58f8e3ea5a71e742f2c2142d5a9f60a3bb566a956d800fd6513325e90
1402 # -- List of extraVolumes made available to the snapshot cronjob container.
1404 # - name: openbao-tls
1407 # secretName: openbao-tls
1409 # -- List of additional volumeMounts for the snapshot cronjob container.
1410 extraVolumeMounts: []
1411 # - mountPath: /openbao/tls/ca.crt
1416 # -- Existing Kubernetes secret with S3 Credentials.
1417 # Must contain keys called AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY.
1418 # If not provided, you must provide `snapshotAgent.extraSecretEnvironmentVars`
1419 s3CredentialsSecret: ""
1420 # configuration for the snapshot agent
1422 s3Host: "s3.eu-east-1.amazonaws.com"
1423 s3Bucket: "openbao-snapshots"
1424 s3Uri: "s3://openbao-snapshots"
1426 s3cmdExtraFlag: "-v"
1427 # The path of the Kubernetes authentication backend in OpenBao (e.g. `kubernetes`)
1428 baoAuthPath: "kubernetes"
1429 # OpenBao role to use to create the snapshot
1431 # OpenBao namespace to be used. Leave empty for non-namespace installations.
1433 # Namespace for bao authentication. If authentication namespace needs to be different to `BAO_NAMESPACE`.
1434 baoAuthNamespace: ""
1435 # Secret path to retrieve S3 credentials from. Expects the secret to have two fields: `AWS_ACCESS_KEY_ID` and `AWS_SECRET_ACCESS_KEY`
1437 # The path of the Kubernetes service account token. If unset defaults to `/var/run/secrets/kubernetes.io/serviceaccount/token`.
1439 # configuration of the CronJobs resources
1441 # -- Map of extra environment variables to set in the snapshot-agent cronjob
1442 extraEnvironmentVars: {}
1443 # BAO_CACERT: /openbao/tls/ca.crt
1445 # -- List of extra environment variables to set in the snapshot-agent cronjob
1446 # These variables take value from existing Secret objects.
1447 extraSecretEnvironmentVars: []
1448 # - envName: AWS_SECRET_ACCESS_KEY
1449 # secretName: openbao
1450 # secretKey: AWS_SECRET_ACCESS_KEY
1452 # Security context for the pod template and the snapshotAgent container
1453 # The default pod securityContext is:
1455 # type: RuntimeDefault
1456 # runAsNonRoot: true
1457 # runAsGroup: {{ .Values.snapshotAgent.gid | default 1000 }}
1458 # runAsUser: {{ .Values.snapshotAgent.uid | default 100 }}
1459 # fsGroup: {{ .Values.snapshotAgent.gid | default 1000 }}
1460 # and for container is
1461 # allowPrivilegeEscalation: false
1468 # Toleration Settings for snapshot-agent cronjob pod
1469 # This should be either a multi-line string or YAML matching the Toleration array