This repository has been archived on 2024-02-11. You can view files and clone it, but cannot push or open issues or pull requests.
valinor/kubernetes/apps/kube-system/cilium/app/helmrelease.yaml

76 lines
1.9 KiB
YAML
Raw Normal View History

2023-10-02 13:41:45 -05:00
---
# yaml-language-server: $schema=https://raw.githubusercontent.com/fluxcd-community/flux2-schemas/main/helmrelease-helm-v2beta2.json
apiVersion: helm.toolkit.fluxcd.io/v2beta2
2023-10-02 13:41:45 -05:00
kind: HelmRelease
metadata:
name: cilium
namespace: kube-system
spec:
interval: 30m
chart:
spec:
chart: cilium
2023-12-13 18:06:07 -06:00
version: 1.14.5
2023-10-02 13:41:45 -05:00
sourceRef:
kind: HelmRepository
name: cilium
namespace: flux-system
maxHistory: 2
install:
remediation:
retries: 3
upgrade:
cleanupOnFail: true
remediation:
retries: 3
uninstall:
keepHistory: false
values:
cluster:
name: valinor
id: 1
2023-12-29 17:51:53 -06:00
hubble:
relay:
enabled: true
ui:
enabled: true
2024-01-08 17:27:14 -06:00
metrics:
2024-01-08 17:30:28 -06:00
# enabled: "{dns,drop,tcp,flow,port-distribution,icmp,httpV2:exemplars=true;labelsContext=source_ip,source_namespace,source_workload,destination_ip,destination_namespace,destination_workload,traffic_direction}"
2024-01-08 17:27:14 -06:00
enableOpenMetrics: true
prometheus:
enabled: true
operator:
prometheus:
enabled: true
2023-10-02 13:41:45 -05:00
ipam:
mode: kubernetes
2024-01-08 13:26:25 -06:00
policyEnforcementMode: always # enforce network policies
2024-01-08 17:50:59 -06:00
policyAuditMode: true # do not block traffic
2024-01-08 13:26:25 -06:00
hostFirewall:
enabled: true # enable host policies
extraConfig:
allow-localhost: policy # enable policies for localhost
2023-10-02 13:41:45 -05:00
kubeProxyReplacement: true
securityContext:
capabilities:
ciliumAgent:
- CHOWN
- KILL
- NET_ADMIN
- NET_RAW
- IPC_LOCK
- SYS_ADMIN
- SYS_RESOURCE
- DAC_OVERRIDE
- FOWNER
- SETGID
- SETUID
cleanCiliumState:
- NET_ADMIN
- SYS_ADMIN
- SYS_RESOURCE
2023-12-10 22:04:29 -06:00
k8sServiceHost: ${K8S_SERVICE_ENDPOINT}
k8sServicePort: 6443
2023-10-02 13:41:45 -05:00
rollOutCiliumPods: true