8 repository: chainguard-private/curl
10 version: sha256:ea8277f85118f9faf6dc06c824c4158a84748c53ed4e464ce649965dc98ae8a8
11 imagePullPolicy: IfNotPresent
12initContainerResources: {}
25 registry: chainreg.biz
26 repository: chainguard-private/redis
27 pullPolicy: IfNotPresent
28 # -- 6.2.17-alpine3.21
29 version: sha256:16f4d05d1ca4d2cff05d65250ce8b11591a7e6af20549519e451464b71bc5432
40 initialDelaySeconds: 5
50 - test "$(redis-cli -h 127.0.0.1 ping)" = "PONG"
52 initialDelaySeconds: 5
62 - test "$(redis-cli -h 127.0.0.1 ping)" = "PONG"
82 registry: chainreg.biz
83 repository: chainguard-private/cloud-sql-proxy
84 # -- crane digest gcr.io/cloud-sql-connectors/cloud-sql-proxy:2.19.0-alpine
85 version: sha256:b4ae36dbaaf745bda57f9cbd3b67c52a7b779d87a8425e9362697a04b219cd95
91 allowPrivilegeEscalation: false
92 readOnlyRootFilesystem: true
108 registry: chainreg.biz
109 repository: chainguard-private/mariadb
110 pullPolicy: IfNotPresent
111 version: sha256:bcb2434b329fc728a64257cbf20c66aa0cdbb36f6f1261b48633c87605a7dc65
118 registry: chainreg.biz
119 repository: chainguard-private/rekor-server
120 pullPolicy: IfNotPresent
121 # crane digest ghcr.io/sigstore/rekor/rekor-server:v1.5.3
122 version: latest@sha256:dea8fab7659e8299b9956d2bc0b54d41d5c11bc607d90409ddd8b87aeb2c3e45
123 # -- KMS type for signing key (possible values: "" / "none", "aws")
125 # -- AWS region if using AWS KMS for signing key
126 awsKmsRegion: us-east-1
127 # -- kubernetes secret name containing IAM credentials for use with AWS KMS
128 awsKmsCredentialsSecretName: aws-kms-credentials
148 staticGlobalIP: lb-ext-ip
149 frontendConfigSpec: # https://cloud.google.com/kubernetes-engine/docs/how-to/ingress-configuration#configuring_ingress_features_through_frontendconfig_parameters
150 sslPolicy: rekor-ssl-policy
153 backendConfigSpec: # https://cloud.google.com/kubernetes-engine/docs/how-to/ingress-configuration#configuring_ingress_features_through_backendconfig_parameters
155 name: rekor-security-policy
171 initialDelaySeconds: 10
181 filename: sharding-config.yaml
184 initialDelaySeconds: 30
202 bucket: file:///var/run/attestations
208 mountPath: /var/lib/mysql
214 prometheus.io/scrape: "true"
215 prometheus.io/path: /metrics
216 prometheus.io/port: "2112"
234 registry: chainreg.biz
235 repository: chainguard-private/sigstore-scaffolding-trillian-createtree
236 pullPolicy: IfNotPresent
238 version: sha256:a7a734d2171eae30ab53ccec927bee5c06ba7f697495d04c98fba0102909382b
239 ttlSecondsAfterFinished: 3600
254# Configure backfillredis to repair indices that were not inserted into Redis.
259 registry: chainreg.biz
260 repository: chainguard-private/rekor-backfill-index
261 pullPolicy: IfNotPresent
263 version: sha256:e52ee457bdb7082ed7a556d08a0bf8709e49c6535d942b1fb717b2413150f728
264 ttlSecondsAfterFinished: 3600
268 rekorAddress: rekor.rekor-system.svc
278# Configure Trillian dependency
282 name: trillian-system
284 forceNamespace: trillian-system
285 fullnameOverride: trillian
288 name: trillian-logserver
289 fullnameOverride: trillian-logserver
293 name: trillian-logsigner
294 fullnameOverride: trillian-logsigner
296 fullnameOverride: trillian-mysql
297# Force namespace of namespaced resources