2024-01-11 15:03:54 -06:00
|
|
|
---
|
|
|
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/fluxcd-community/flux2-schemas/main/helmrelease-helm-v2beta2.json
|
|
|
|
apiVersion: helm.toolkit.fluxcd.io/v2beta2
|
|
|
|
kind: HelmRelease
|
|
|
|
metadata:
|
|
|
|
name: cilium
|
|
|
|
namespace: kube-system
|
|
|
|
spec:
|
|
|
|
interval: 30m
|
|
|
|
chart:
|
|
|
|
spec:
|
|
|
|
chart: cilium
|
2024-02-01 15:00:38 -06:00
|
|
|
version: 1.15.0
|
2024-01-11 15:03:54 -06:00
|
|
|
sourceRef:
|
|
|
|
kind: HelmRepository
|
|
|
|
name: cilium
|
|
|
|
namespace: flux-system
|
|
|
|
maxHistory: 2
|
|
|
|
install:
|
|
|
|
remediation:
|
|
|
|
retries: 3
|
|
|
|
upgrade:
|
|
|
|
cleanupOnFail: true
|
|
|
|
remediation:
|
|
|
|
retries: 3
|
|
|
|
uninstall:
|
|
|
|
keepHistory: false
|
|
|
|
values:
|
|
|
|
cluster:
|
2024-01-11 17:50:28 -06:00
|
|
|
name: homelab
|
2024-01-11 15:03:54 -06:00
|
|
|
id: 1
|
|
|
|
hubble:
|
|
|
|
relay:
|
|
|
|
enabled: true
|
|
|
|
ui:
|
|
|
|
enabled: true
|
|
|
|
metrics:
|
|
|
|
enableOpenMetrics: true
|
|
|
|
prometheus:
|
|
|
|
enabled: true
|
|
|
|
operator:
|
|
|
|
prometheus:
|
|
|
|
enabled: true
|
|
|
|
ipam:
|
|
|
|
mode: kubernetes
|
|
|
|
policyEnforcementMode: always # enforce network policies
|
|
|
|
policyAuditMode: true # do not block traffic
|
|
|
|
hostFirewall:
|
|
|
|
enabled: true # enable host policies
|
|
|
|
extraConfig:
|
|
|
|
allow-localhost: policy # enable policies for localhost
|
|
|
|
kubeProxyReplacement: true
|
2024-02-15 16:54:45 -06:00
|
|
|
k8sServiceHost: 127.0.0.1
|
|
|
|
k8sServicePort: 7445
|
2024-01-11 15:03:54 -06:00
|
|
|
rollOutCiliumPods: true
|
2024-02-15 16:54:45 -06:00
|
|
|
cgroup:
|
|
|
|
automount:
|
|
|
|
enabled: false
|
|
|
|
hostRoot: /sys/fs/cgroup
|
2024-01-12 13:34:38 -06:00
|
|
|
bgp:
|
|
|
|
enabled: false
|
|
|
|
announce:
|
|
|
|
loadbalancerIP: true
|
|
|
|
podCIDR: false
|
|
|
|
bgpControlPlane:
|
|
|
|
enabled: true
|
2024-02-15 16:54:45 -06:00
|
|
|
securityContext:
|
|
|
|
capabilities:
|
|
|
|
ciliumAgent:
|
|
|
|
- CHOWN
|
|
|
|
- KILL
|
|
|
|
- NET_ADMIN
|
|
|
|
- NET_RAW
|
|
|
|
- IPC_LOCK
|
|
|
|
- SYS_ADMIN
|
|
|
|
- SYS_RESOURCE
|
|
|
|
- DAC_OVERRIDE
|
|
|
|
- FOWNER
|
|
|
|
- SETGID
|
|
|
|
- SETUID
|
|
|
|
cleanCiliumState:
|
|
|
|
- NET_ADMIN
|
|
|
|
- SYS_ADMIN
|
|
|
|
- SYS_RESOURCE
|