theshire/kubernetes/apps/kube-system/cilium/app/helmrelease.yaml

85 lines
1.9 KiB
YAML
Raw Normal View History

2024-01-11 15:03:54 -06:00
---
# yaml-language-server: $schema=https://raw.githubusercontent.com/fluxcd-community/flux2-schemas/main/helmrelease-helm-v2beta2.json
apiVersion: helm.toolkit.fluxcd.io/v2beta2
kind: HelmRelease
metadata:
name: cilium
namespace: kube-system
spec:
interval: 30m
chart:
spec:
chart: cilium
2024-02-01 15:00:38 -06:00
version: 1.15.0
2024-01-11 15:03:54 -06:00
sourceRef:
kind: HelmRepository
name: cilium
namespace: flux-system
maxHistory: 2
install:
remediation:
retries: 3
upgrade:
cleanupOnFail: true
remediation:
retries: 3
uninstall:
keepHistory: false
values:
cluster:
2024-01-11 17:50:28 -06:00
name: homelab
2024-01-11 15:03:54 -06:00
id: 1
hubble:
relay:
enabled: true
ui:
enabled: true
metrics:
enableOpenMetrics: true
prometheus:
enabled: true
operator:
prometheus:
enabled: true
ipam:
mode: kubernetes
policyEnforcementMode: always # enforce network policies
policyAuditMode: true # do not block traffic
hostFirewall:
enabled: true # enable host policies
extraConfig:
allow-localhost: policy # enable policies for localhost
kubeProxyReplacement: true
2024-02-15 16:54:45 -06:00
k8sServiceHost: 127.0.0.1
k8sServicePort: 7445
2024-01-11 15:03:54 -06:00
rollOutCiliumPods: true
2024-02-15 16:54:45 -06:00
cgroup:
automount:
enabled: false
hostRoot: /sys/fs/cgroup
2024-01-12 13:34:38 -06:00
bgp:
enabled: false
announce:
loadbalancerIP: true
podCIDR: false
bgpControlPlane:
enabled: true
2024-02-15 16:54:45 -06:00
securityContext:
capabilities:
ciliumAgent:
- CHOWN
- KILL
- NET_ADMIN
- NET_RAW
- IPC_LOCK
- SYS_ADMIN
- SYS_RESOURCE
- DAC_OVERRIDE
- FOWNER
- SETGID
- SETUID
cleanCiliumState:
- NET_ADMIN
- SYS_ADMIN
- SYS_RESOURCE