dipup 사용 차트를 카탈로그에 동기화 (7개 갱신 + 5개 신규)

dipup 이 go:embed 로 직접 보관·관리하던 Helm 차트를 카탈로그로 옮기는 첫 단계다.
두 저장소가 각자 CVE/SBOM 파이프라인을 운영하는 이중화를 해소하려면, 먼저 카탈로그가
dipup 과 같은 차트·같은 이미지를 보게 만들어야 한다.

배경: CVE 파이프라인 구성 이전에 두 곳에서 같은 차트를 유지하기 어려워 dipup 이 별도로
차트를 관리해 왔고, 그 결과 버전이 갈라졌다. 겹치는 10개 중 버전까지 일치하는 것은
postgresql-ha·dnsup 2개뿐이었다.

## 버전 갱신 (7개) — 신규 버전 디렉토리 추가, 구버전은 보존

| 차트 | 기존 | 신규 | appVersion |
|---|---|---|---|
| apisix | 2.14.0 | 2.16.0 | 3.16.0 → 3.17.0 |
| argo-cd | 7.7.0 | 7.8.11 | v2.13.0 → v2.14.5 |
| cert-manager | v1.16.1 | v1.21.0 | 동일 |
| gitea | 12.4.0 | 12.6.0 | 1.24.6 → 1.26.1 |
| harbor | 1.16.2 | 1.19.1 | 2.12.2 → 2.15.1 |
| kyverno | 3.4.1 | 3.8.2 | v1.14.1 → v1.18.2 |
| rancher | 2.10.1 | 2.14.3 | v2.10.1 → v2.14.3 |

차트 본문은 dipup 이 임베딩한 .tgz 를 그대로 전개했다(네트워크 pull 이 아니라 dipup 이
실제 배포하는 바이트와 동일함을 보장하기 위함). BUILD-README/CUSTOM-README/custom-values
3개 파일은 구버전에서 승계했다.

## 신규 추가 (5개)

infisical-standalone 1.9.0, longhorn 109.3.1+up1.11.2, longhorn-crd 109.3.1+up1.11.2,
metallb 0.16.1, secrets-operator v0.10.33.

longhorn/longhorn-crd 는 업스트림이 아니라 Rancher 패키징 차트(109.x 라인, Rancher 2.14
계열과 짝)다. BUILD-README 의 `helm repo add` 라인은 chart_version_detector 가 파싱하는
계약이라 실제 업스트림 repo 를 검증해 기재했고, 감지기로 현재/최신 버전이 정상 조회되는
것을 확인했다.

## custom-values — 버전과 결합된 이미지 핀 정리

카탈로그 스캐너가 dipup 의 effective image 를 보게 하려면 이미지 핀이 맞아야 한다.

- **kyverno: 승계본이 3.8.2 에서 깨져 재작성.** 3.4.1 은 정리 훅이
  `registry: ~ / repository: bitnami/kubectl` 이라 bitnamilegacy 오버라이드가 맞았지만,
  3.8.2 는 `registry: ghcr.io / repository: kyverno/readiness-checker` 로 바뀌었다.
  그대로 옮기면 ghcr.io/bitnamilegacy/kubectl 이라는 없는 좌표가 된다. 해당 오버라이드를
  제거하고, 3.8.2 에서 삭제된 policyReportsCleanup 키도 함께 뺐다. 남는 조치는 tag 고정뿐
  (기본 tag 가 비어 latest 로 떨어짐 → v1.18.2 로 고정).
- apisix: 3.16.0-keycloak-authz → 3.17.0-keycloak-authz (차트 appVersion 과 함께 이동)
- gitea: image.tag 1.26.4 핀 추가 — 차트 기본 1.26.1 대비 CRITICAL 2→0, HIGH 44→12
- infisical: image.tag v0.162.7 핀 — 기본 v0.158.x 는 stale Debian base 로 OS 기인 CVE
  다수(fixable CRITICAL 53→5, HIGH 491→55). redis/postgresql 은 bitnamilegacy 좌표로.
- longhorn: 실측 기반 리소스 튜닝(manager request, guaranteedInstanceManagerCPU,
  systemManagedCSIComponentsResourceLimits). replica 수처럼 노드 수에 의존하는 값은
  넣지 않았다 — 소비 측에서 주입한다.

## 검증

12개 차트 전부 `helm template --kube-version 1.34.1` 렌더 성공. 렌더 결과 이미지가
dipup 배포 이미지와 일치함을 확인(paasup/apisix:3.17.0-keycloak-authz,
gitea:1.26.4-rootless, readiness-checker:v1.18.2, infisical:v0.162.7).

## 범위에서 뺀 것

- **keycloak**: 카탈로그는 codecentric(app 17.0.1-legacy), dipup 은 bitnami(app 26.2.4)로
  계보가 다르다. 이슈 #1(bitnami 대체 방안 검토)의 결론이 나온 뒤 처리한다.
- **rancher-monitoring(-crd)**: 14c05f1 에서 불필요 판단으로 제거된 차트이고
  victoria-metrics 스택으로 대체 예정이라 추가하지 않는다.
- **dip-api/dip-console**: 자체 개발 차트로 각 앱 저장소가 출처다. 대조 결과 앱 저장소와
  dipup 사본이 일치해 카탈로그가 개입할 이유가 없다.
- **postgresql-ha/dnsup**: 이미 버전이 일치해 작업 대상이 아니었다.

## 후속 과제

dnsup 은 카탈로그·dipup 사본(1.0.1)이 원본(dip-console-api helm/dnsup 1.0.0)보다 앞서
있다. 1.0.1 에만 있는 service.LoadBalancerIP·service.annotations 지원을 원본으로 백포트한
뒤, 카탈로그에서 dnsup 을 제거하는 것이 자체 개발 차트 출처 원칙에 맞다.
This commit is contained in:
wbsong111
2026-08-06 09:42:24 +09:00
parent 9d5a10b09c
commit 16321b52c7
1262 changed files with 314285 additions and 0 deletions
@@ -0,0 +1,453 @@
#
# Licensed to the Apache Software Foundation (ASF) under one or more
# contributor license agreements. See the NOTICE file distributed with
# this work for additional information regarding copyright ownership.
# The ASF licenses this file to You under the Apache License, Version 2.0
# (the "License"); you may not use this file except in compliance with
# the License. You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
apiVersion: v1
kind: ConfigMap
metadata:
name: {{ include "apisix.fullname" . }}
namespace: {{ .Release.Namespace }}
data:
config.yaml: |-
#
# Licensed to the Apache Software Foundation (ASF) under one or more
# contributor license agreements. See the NOTICE file distributed with
# this work for additional information regarding copyright ownership.
# The ASF licenses this file to You under the Apache License, Version 2.0
# (the "License"); you may not use this file except in compliance with
# the License. You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
{{- if .Values.apisix.fullCustomConfig.enabled }}
{{- range $key, $value := .Values.apisix.fullCustomConfig.config }}
{{ $key }}:
{{- include "apisix.tplvalues.render" (dict "value" $value "context" $) | nindent 6 }}
{{- end }}
{{- else }}
apisix: # universal configurations
{{- if not (eq .Values.apisix.deployment.role "control_plane") }}
node_listen: # APISIX listening port
- {{ .Values.service.http.containerPort }}
{{- with .Values.service.http.additionalContainerPorts }}
{{- toYaml . | nindent 8}}
{{- end }}
{{- end }}
enable_heartbeat: true
enable_admin: {{ .Values.apisix.admin.enabled }}
enable_admin_cors: {{ .Values.apisix.admin.cors }}
enable_debug: false
{{- if or .Values.apisix.customPlugins.enabled .Values.apisix.luaModuleHook.enabled }}
extra_lua_path: {{ .Values.apisix.customPlugins.luaPath }};{{ .Values.apisix.luaModuleHook.luaPath }}
{{- end }}
enable_control: {{ .Values.control.enabled }}
{{- if .Values.control.enabled }}
control:
ip: {{ default "127.0.0.1" .Values.control.service.ip }}
port: {{ default 9090 .Values.control.service.port }}
{{- end }}
{{- if .Values.apisix.luaModuleHook.enabled }}
lua_module_hook: {{ .Values.apisix.luaModuleHook.hookPoint | quote }}
{{- end }}
enable_dev_mode: false # Sets nginx worker_processes to 1 if set to true
enable_reuseport: true # Enable nginx SO_REUSEPORT switch if set to true.
enable_ipv6: {{ .Values.apisix.enableIPv6 }} # Enable nginx IPv6 resolver
enable_http2: {{ .Values.apisix.enableHTTP2 }}
enable_server_tokens: {{ .Values.apisix.enableServerTokens }} # Whether the APISIX version number should be shown in Server header
show_upstream_status_in_response_header: {{ .Values.apisix.showUpstreamStatusInResponseHeader }} # when true, all upstream statuses are written to `X-APISIX-Upstream-Status`; otherwise only 5xx codes
{{- if or .Values.apisix.proxyProtocol.enableTcpPP .Values.apisix.proxyProtocol.enableTcpPPToUpstream .Values.apisix.proxyProtocol.listenHttpPort .Values.apisix.proxyProtocol.listenHttpsPort }}
proxy_protocol:
{{- if .Values.apisix.proxyProtocol.listenHttpPort }}
listen_http_port: {{ .Values.apisix.proxyProtocol.listenHttpPort }}
{{- end }}
{{- if .Values.apisix.proxyProtocol.listenHttpsPort }}
listen_https_port: {{ .Values.apisix.proxyProtocol.listenHttpsPort }}
{{- end }}
enable_tcp_pp: {{ .Values.apisix.proxyProtocol.enableTcpPP }}
enable_tcp_pp_to_upstream: {{ .Values.apisix.proxyProtocol.enableTcpPPToUpstream }}
{{- end }}
proxy_cache: # Proxy Caching configuration
cache_ttl: {{ .Values.apisix.proxyCache.cacheTtl }} # The default caching time if the upstream does not specify the cache time
zones: # The parameters of a cache
{{- toYaml .Values.apisix.proxyCache.zones | nindent 10 }}
delete_uri_tail_slash: {{ .Values.apisix.deleteURITailSlash }} # delete the '/' at the end of the URI
# The URI normalization in servlet is a little different from the RFC's.
# See https://github.com/jakartaee/servlet/blob/master/spec/src/main/asciidoc/servlet-spec-body.adoc#352-uri-path-canonicalization,
# which is used under Tomcat.
# Turn this option on if you want to be compatible with servlet when matching URI path.
normalize_uri_like_servlet: {{ .Values.apisix.normalizeURILikeServlet }}
# fine tune the parameters of LRU cache for some features like secret
lru:
secret:
ttl: {{ .Values.apisix.lru.secret.ttl }} # seconds
count: {{ .Values.apisix.lru.secret.count }}
neg_ttl: {{ .Values.apisix.lru.secret.neg_ttl }}
neg_count: {{ .Values.apisix.lru.secret.neg_count }}
tracing: {{ .Values.apisix.tracing }} # Enable comprehensive request lifecycle tracing (SSL/SNI, rewrite, access, header_filter, body_filter, and log).
# When disabled, OpenTelemetry collects only a single span per request.
router:
http: {{ .Values.apisix.router.http }} # radixtree_uri: match route by uri(base on radixtree)
# radixtree_host_uri: match route by host + uri(base on radixtree)
# radixtree_uri_with_parameter: match route by uri with parameters
ssl: 'radixtree_sni' # radixtree_sni: match route by SNI(base on radixtree)
{{- $proxy_mode := "" }}
{{- if and .Values.service.stream.enabled .Values.service.http.enabled }}
{{- $proxy_mode = "http&stream" }}
{{- else if .Values.service.http.enabled }}
{{- $proxy_mode = "http" }}
{{- else if .Values.service.stream.enabled }}
{{- $proxy_mode = "stream" }}
{{- end }}
proxy_mode: {{ $proxy_mode }}
{{- if or (index .Values "ingress-controller" "enabled") (and .Values.service.stream.enabled (or (gt (len .Values.service.stream.tcp) 0) (gt (len .Values.service.stream.udp) 0))) }}
stream_proxy: # TCP/UDP proxy
{{- if or (index .Values "ingress-controller" "enabled") (gt (len .Values.service.stream.tcp) 0) }}
tcp: # TCP proxy port list
{{- if gt (len .Values.service.stream.tcp) 0}}
{{- range .Values.service.stream.tcp }}
{{- if kindIs "map" . }}
- addr: {{ .addr }}
{{- if hasKey . "tls" }}
tls: {{ .tls }}
{{- end }}
{{- else }}
- {{ . }}
{{- end }}
{{- end }}
{{- else}}
- 9100
{{- end }}
{{- end }}
{{- if or (index .Values "ingress-controller" "enabled") (gt (len .Values.service.stream.udp) 0) }}
udp: # UDP proxy port list
{{- if gt (len .Values.service.stream.udp) 0}}
{{- range .Values.service.stream.udp }}
- {{ . }}
{{- end }}
{{- else}}
- 9200
{{- end }}
{{- end }}
{{- end }}
{{- with .Values.apisix.dns.resolvers }}
dns_resolver: # If not set, read from `/etc/resolv.conf`
{{- range $resolver := . }}
- {{ $resolver }}
{{- end }}
{{- end }}
dns_resolver_valid: {{.Values.apisix.dns.validity}}
resolver_timeout: {{.Values.apisix.dns.timeout}}
enable_resolv_search_opt: {{ .Values.apisix.dns.enableResolvSearchOpt }}
ssl:
enable: {{ .Values.apisix.ssl.enabled }}
listen:
- port: {{ .Values.apisix.ssl.containerPort }}
enable_http3: {{ .Values.apisix.ssl.enableHTTP3 }}
{{- with .Values.apisix.ssl.additionalContainerPorts }}
{{- toYaml . | nindent 10}}
{{- end }}
ssl_protocols: {{ .Values.apisix.ssl.sslProtocols | quote }}
ssl_ciphers: {{ .Values.apisix.ssl.sslCiphers | quote }}
ssl_session_tickets: {{ .Values.apisix.ssl.sslSessionTickets }}
{{- if and .Values.apisix.ssl.enabled .Values.apisix.ssl.existingCASecret }}
ssl_trusted_certificate: "/usr/local/apisix/conf/ssl/{{ .Values.apisix.ssl.certCAFilename }}"
{{- end }}
{{- if and .Values.apisix.ssl.enabled .Values.apisix.ssl.fallbackSNI }}
fallback_sni: {{ .Values.apisix.ssl.fallbackSNI | quote }}
{{- end }}
{{- $useTraditionalYaml := and (eq .Values.apisix.deployment.role "traditional") (eq .Values.apisix.deployment.role_traditional.config_provider "yaml") }}
{{- if $useTraditionalYaml }}
status:
ip: {{ default "127.0.0.1" .Values.apisix.status.ip }}
port: {{ default "7085" (.Values.apisix.status.port | toString) }}
{{- end}}
{{ if .Values.apisix.trustedAddresses }}
trusted_addresses:
{{- toYaml .Values.apisix.trustedAddresses | nindent 8 }}
{{ end }}
nginx_config: # config for render the template to genarate nginx.conf
error_log: "{{ .Values.apisix.nginx.logs.errorLog }}"
error_log_level: "{{ .Values.apisix.nginx.logs.errorLogLevel }}" # warn,error
worker_processes: "{{ .Values.apisix.nginx.workerProcesses }}"
enable_cpu_affinity: {{ and true .Values.apisix.nginx.enableCPUAffinity }}
worker_rlimit_nofile: {{ default "20480" .Values.apisix.nginx.workerRlimitNofile }} # the number of files a worker process can open, should be larger than worker_connections
worker_shutdown_timeout: "{{ default "240s" .Values.apisix.nginx.workerShutdownTimeout }}" # timeout for a graceful shutdown of worker processes
max_pending_timers: {{ default "16384" .Values.apisix.nginx.maxPendingTimers }} # increase it if you see "too many pending timers" error
max_running_timers: {{ default "4096" .Values.apisix.nginx.maxRunningTimers }} # increase it if you see "lua_max_running_timers are not enough" error
event:
worker_connections: {{ default "10620" .Values.apisix.nginx.workerConnections }}
{{- with .Values.apisix.nginx.envs }}
envs:
{{- range $env := . }}
- {{ $env }}
{{- end }}
{{- end }}
{{- if .Values.apisix.nginx.metaLuaSharedDicts }}
meta:
lua_shared_dict:
{{- range $dict := .Values.apisix.nginx.metaLuaSharedDicts }}
{{ $dict.name }}: {{ $dict.size }}
{{- end }}
{{- end }}
stream:
enable_access_log: {{ .Values.apisix.nginx.logs.stream.enableAccessLog }}
{{- if .Values.apisix.nginx.logs.stream.enableAccessLog }}
access_log: "{{ .Values.apisix.nginx.logs.stream.accessLog }}"
access_log_format: '{{ .Values.apisix.nginx.logs.stream.accessLogFormat }}'
access_log_format_escape: {{ .Values.apisix.nginx.logs.stream.accessLogFormatEscape }}
{{- end }}
http:
enable_access_log: {{ .Values.apisix.nginx.logs.enableAccessLog }}
{{- if .Values.apisix.nginx.logs.enableAccessLog }}
access_log: "{{ .Values.apisix.nginx.logs.accessLog }}"
access_log_format: '{{ .Values.apisix.nginx.logs.accessLogFormat }}'
access_log_format_escape: {{ .Values.apisix.nginx.logs.accessLogFormatEscape }}
{{- end }}
keepalive_timeout: {{ .Values.apisix.nginx.keepaliveTimeout | quote }}
client_header_timeout: {{ .Values.apisix.nginx.http.clientHeaderTimeout }} # timeout for reading client request header, then 408 (Request Time-out) error is returned to the client
client_body_timeout: {{ .Values.apisix.nginx.http.clientBodyTimeout }} # timeout for reading client request body, then 408 (Request Time-out) error is returned to the client
send_timeout: {{ .Values.apisix.nginx.http.sendTimeout }} # timeout for transmitting a response to the client.then the connection is closed
client_max_body_size: {{ .Values.apisix.nginx.http.clientMaxBodySize }} # The maximum allowed size of the client request body.
# If exceeded, the 413 (Request Entity Too Large) error is returned to the client.
# Note that unlike Nginx, we don't limit the body size by default.
underscores_in_headers: {{ .Values.apisix.nginx.http.underscoresInHeaders | quote }} # default enables the use of underscores in client request header fields
real_ip_header: {{ .Values.apisix.nginx.http.realIpHeader | quote }} # http://nginx.org/en/docs/http/ngx_http_realip_module.html#real_ip_header
real_ip_recursive: {{ .Values.apisix.nginx.http.realIpRecursive | quote }} # http://nginx.org/en/docs/http/ngx_http_realip_module.html#real_ip_recursive
real_ip_from: # http://nginx.org/en/docs/http/ngx_http_realip_module.html#set_real_ip_from
{{- range $ip := .Values.apisix.nginx.http.realIpFrom }}
- {{ $ip | quote }}
{{- end }}
proxy_ssl_server_name: {{ .Values.apisix.nginx.http.proxySslServerName }} # send the server name (SNI) when establishing a TLS connection with the proxied HTTPS upstream
upstream:
keepalive: {{ .Values.apisix.nginx.http.upstream.keepalive }} # The maximum number of idle keepalive connections to upstream servers per worker process
keepalive_requests: {{ .Values.apisix.nginx.http.upstream.keepaliveRequests }} # The maximum number of requests that can be served through one keepalive connection
keepalive_timeout: {{ .Values.apisix.nginx.http.upstream.keepaliveTimeout }} # Timeout during which an idle keepalive connection to an upstream server will stay open
charset: {{ .Values.apisix.nginx.http.charset }} # Adds the specified charset to the "Content-Type" response header field
variables_hash_max_size: {{ .Values.apisix.nginx.http.variablesHashMaxSize }} # Sets the maximum size of the variables hash table
{{- if .Values.apisix.nginx.customLuaSharedDicts }}
custom_lua_shared_dict: # add custom shared cache to nginx.conf
{{- range $dict := .Values.apisix.nginx.customLuaSharedDicts }}
{{ $dict.name }}: {{ $dict.size }}
{{- end }}
{{- end }}
{{- if .Values.apisix.nginx.luaSharedDicts }}
lua_shared_dict:
{{- range $dict := .Values.apisix.nginx.luaSharedDicts }}
{{ $dict.name }}: {{ $dict.size }}
{{- end }}
{{- end }}
{{- if .Values.apisix.nginx.configurationSnippet.main }}
main_configuration_snippet: {{- toYaml .Values.apisix.nginx.configurationSnippet.main | indent 6 }}
{{- end }}
{{- if .Values.apisix.nginx.configurationSnippet.httpStart }}
http_configuration_snippet: {{- toYaml .Values.apisix.nginx.configurationSnippet.httpStart | indent 6 }}
{{- end }}
{{- if .Values.apisix.nginx.configurationSnippet.httpEnd }}
http_end_configuration_snippet: {{- toYaml .Values.apisix.nginx.configurationSnippet.httpEnd | indent 6 }}
{{- end }}
{{- if .Values.apisix.nginx.configurationSnippet.httpSrv }}
http_server_configuration_snippet: {{- toYaml .Values.apisix.nginx.configurationSnippet.httpSrv | indent 6 }}
{{- end }}
{{- if .Values.apisix.nginx.configurationSnippet.httpAdmin }}
http_admin_configuration_snippet: {{ toYaml .Values.apisix.nginx.configurationSnippet.httpAdmin | indent 6 }}
{{- end }}
{{- if .Values.apisix.nginx.configurationSnippet.stream }}
stream_configuration_snippet: {{- toYaml .Values.apisix.nginx.configurationSnippet.stream | indent 6 }}
{{- end }}
graphql:
max_size: {{ int .Values.apisix.graphql.maxSize }} # the maximum size limitation of graphql in bytes
{{- if .Values.apisix.discovery.enabled }}
discovery:
{{- range $key, $value := .Values.apisix.discovery.registry }}
{{- if $value }}
{{ $key }}:
{{- include "apisix.tplvalues.render" (dict "value" $value "context" $) | nindent 8 }}
{{- else }}
{{ $key }}: {}
{{- end }}
{{- end }}
{{- end }}
{{- if .Values.apisix.vault.enabled }}
vault:
host: {{ .Values.apisix.vault.host }}
timeout: {{ .Values.apisix.vault.timeout }}
token: {{ .Values.apisix.vault.token }}
prefix: {{ .Values.apisix.vault.prefix }}
{{- end }}
{{- if .Values.apisix.plugins }}
plugins: # plugin list
{{- range $plugin := .Values.apisix.plugins }}
{{- if ne $plugin "" }}
- {{ $plugin }}
{{- end }}
{{- end }}
{{- if .Values.apisix.customPlugins.enabled }}
{{- range $plugin := .Values.apisix.customPlugins.plugins }}
- {{ $plugin.name }}
{{- end }}
{{- end }}
{{- end }}
{{- if .Values.apisix.stream_plugins }}
stream_plugins:
{{- range $plugin := .Values.apisix.stream_plugins }}
{{- if ne $plugin "" }}
- {{ $plugin }}
{{- end }}
{{- end }}
{{- end }}
{{- if .Values.apisix.extPlugin.enabled }}
ext-plugin:
cmd:
{{- range $arg := .Values.apisix.extPlugin.cmd }}
- {{ $arg }}
{{- end }}
{{- end }}
{{- if or .Values.apisix.pluginAttrs .Values.apisix.customPlugins.enabled .Values.apisix.prometheus.enabled}}
{{- $pluginAttrs := include "apisix.pluginAttrs" . -}}
{{- if gt (len ($pluginAttrs | fromYaml)) 0 }}
plugin_attr: {{- $pluginAttrs | nindent 6 }}
{{- end }}
{{- end }}
{{- if .Values.apisix.wasm.enabled }}
wasm:
plugins:
{{- toYaml .Values.apisix.wasm.plugins | nindent 8 }}
{{- end }}
deployment:
role: {{ .Values.apisix.deployment.role }}
{{- if eq .Values.apisix.deployment.role "traditional" }}
role_traditional:
config_provider: {{ default "etcd" .Values.apisix.deployment.role_traditional.config_provider }}
{{- end }}
{{- if eq .Values.apisix.deployment.role "control_plane" }}
role_control_plane:
config_provider: etcd
{{- end }}
{{- if eq .Values.apisix.deployment.role "data_plane" }}
role_data_plane:
config_provider: {{- eq .Values.apisix.deployment.mode "standalone" | ternary "yaml" "etcd" | indent 1 }}
{{- end }}
{{- if not (eq .Values.apisix.deployment.role "data_plane") }}
admin:
{{- if .Values.etcd.enabled }}
enable_admin_ui: {{ .Values.apisix.admin.enable_admin_ui }}
{{- end }}
allow_admin: # http://nginx.org/en/docs/http/ngx_http_access_module.html#allow
{{- if .Values.apisix.admin.allow.ipList }}
{{- range $ips := .Values.apisix.admin.allow.ipList }}
- {{ $ips }}
{{- end }}
{{- else }}
- 0.0.0.0/0
{{- end}}
{{- if (index .Values "ingress-controller" "enabled") }}
- 0.0.0.0/0
{{- end}}
# - "::/64"
{{- if .Values.apisix.admin.enabled }}
admin_listen:
ip: {{ .Values.apisix.admin.ip }}
port: {{ .Values.apisix.admin.port }}
{{- end }}
# Default token when use API to call for Admin API.
# *NOTE*: Highly recommended to modify this value to protect APISIX's Admin API.
# Disabling this configuration item means that the Admin API does not
# require any authentication.
admin_key:
# admin: can everything for configuration data
- name: "admin"
{{- if .Values.apisix.admin.credentials.secretName }}
key: ${{"{{"}}APISIX_ADMIN_KEY{{"}}"}}
{{- else }}
key: {{ .Values.apisix.admin.credentials.admin }}
{{- end }}
role: admin
# viewer: only can view configuration data
- name: "viewer"
{{- if .Values.apisix.admin.credentials.secretName }}
key: ${{"{{"}}APISIX_VIEWER_KEY{{"}}"}}
{{- else }}
key: {{ .Values.apisix.admin.credentials.viewer }}
{{- end }}
role: viewer
{{- end }}
{{- if not (eq .Values.apisix.deployment.mode "standalone")}}
etcd:
{{- if .Values.etcd.enabled }}
host: # it's possible to define multiple etcd hosts addresses of the same etcd cluster.
{{- if .Values.etcd.fullnameOverride }}
- "{{ include "apisix.etcd.auth.scheme" . }}://{{ .Values.etcd.fullnameOverride }}:{{ .Values.etcd.service.port }}"
{{- else }}
- "{{ include "apisix.etcd.auth.scheme" . }}://{{ .Release.Name }}-etcd.{{ .Release.Namespace }}.svc.{{ .Values.etcd.clusterDomain }}:{{ .Values.etcd.service.port }}"
{{- end}}
{{- else }}
host: # it's possible to define multiple etcd hosts addresses of the same etcd cluster.
{{- range $value := .Values.externalEtcd.host }}
- "{{ $value }}" # multiple etcd address
{{- end}}
{{- end }}
prefix: {{ .Values.etcd.prefix | quote }} # configuration prefix in etcd
timeout: {{ .Values.etcd.timeout }} # The timeout in seconds when connect/read/write to etcd
watch_timeout: {{ .Values.etcd.watchTimeout }} # The timeout in seconds when watch etcd
startup_retry: {{ .Values.etcd.startupRetry }} # the number of retry to etcd during the startup
{{- if and (not .Values.etcd.enabled) .Values.externalEtcd.user }}
user: {{ .Values.externalEtcd.user | quote }}
password: "{{ print "${{ APISIX_ETCD_PASSWORD }}" }}"
{{- else if and .Values.etcd.enabled .Values.etcd.auth.rbac.create }}
user: "root"
password: "{{ print "${{APISIX_ETCD_PASSWORD}}" }}"
{{- end }}
{{- if .Values.etcd.auth.tls.enabled }}
tls:
cert: "/etcd-ssl/{{ .Values.etcd.auth.tls.certFilename }}"
key: "/etcd-ssl/{{ .Values.etcd.auth.tls.certKeyFilename }}"
verify: {{ .Values.etcd.auth.tls.verify }}
sni: "{{ .Values.etcd.auth.tls.sni }}"
{{- end }}
{{- end }}
{{- end }}