# # Licensed to the Apache Software Foundation (ASF) under one or more # contributor license agreements. See the NOTICE file distributed with # this work for additional information regarding copyright ownership. # The ASF licenses this file to You under the Apache License, Version 2.0 # (the "License"); you may not use this file except in compliance with # the License. You may obtain a copy of the License at # # http://www.apache.org/licenses/LICENSE-2.0 # # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. # See the License for the specific language governing permissions and # limitations under the License. apiVersion: v1 kind: ConfigMap metadata: name: {{ include "apisix.fullname" . }} namespace: {{ .Release.Namespace }} data: config.yaml: |- # # Licensed to the Apache Software Foundation (ASF) under one or more # contributor license agreements. See the NOTICE file distributed with # this work for additional information regarding copyright ownership. # The ASF licenses this file to You under the Apache License, Version 2.0 # (the "License"); you may not use this file except in compliance with # the License. You may obtain a copy of the License at # # http://www.apache.org/licenses/LICENSE-2.0 # # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. # See the License for the specific language governing permissions and # limitations under the License. # {{- if .Values.apisix.fullCustomConfig.enabled }} {{- range $key, $value := .Values.apisix.fullCustomConfig.config }} {{ $key }}: {{- include "apisix.tplvalues.render" (dict "value" $value "context" $) | nindent 6 }} {{- end }} {{- else }} apisix: # universal configurations {{- if not (eq .Values.apisix.deployment.role "control_plane") }} node_listen: # APISIX listening port - {{ .Values.service.http.containerPort }} {{- with .Values.service.http.additionalContainerPorts }} {{- toYaml . | nindent 8}} {{- end }} {{- end }} enable_heartbeat: true enable_admin: {{ .Values.apisix.admin.enabled }} enable_admin_cors: {{ .Values.apisix.admin.cors }} enable_debug: false {{- if or .Values.apisix.customPlugins.enabled .Values.apisix.luaModuleHook.enabled }} extra_lua_path: {{ .Values.apisix.customPlugins.luaPath }};{{ .Values.apisix.luaModuleHook.luaPath }} {{- end }} enable_control: {{ .Values.control.enabled }} {{- if .Values.control.enabled }} control: ip: {{ default "127.0.0.1" .Values.control.service.ip }} port: {{ default 9090 .Values.control.service.port }} {{- end }} {{- if .Values.apisix.luaModuleHook.enabled }} lua_module_hook: {{ .Values.apisix.luaModuleHook.hookPoint | quote }} {{- end }} enable_dev_mode: false # Sets nginx worker_processes to 1 if set to true enable_reuseport: true # Enable nginx SO_REUSEPORT switch if set to true. enable_ipv6: {{ .Values.apisix.enableIPv6 }} # Enable nginx IPv6 resolver enable_http2: {{ .Values.apisix.enableHTTP2 }} enable_server_tokens: {{ .Values.apisix.enableServerTokens }} # Whether the APISIX version number should be shown in Server header show_upstream_status_in_response_header: {{ .Values.apisix.showUpstreamStatusInResponseHeader }} # when true, all upstream statuses are written to `X-APISIX-Upstream-Status`; otherwise only 5xx codes {{- if or .Values.apisix.proxyProtocol.enableTcpPP .Values.apisix.proxyProtocol.enableTcpPPToUpstream .Values.apisix.proxyProtocol.listenHttpPort .Values.apisix.proxyProtocol.listenHttpsPort }} proxy_protocol: {{- if .Values.apisix.proxyProtocol.listenHttpPort }} listen_http_port: {{ .Values.apisix.proxyProtocol.listenHttpPort }} {{- end }} {{- if .Values.apisix.proxyProtocol.listenHttpsPort }} listen_https_port: {{ .Values.apisix.proxyProtocol.listenHttpsPort }} {{- end }} enable_tcp_pp: {{ .Values.apisix.proxyProtocol.enableTcpPP }} enable_tcp_pp_to_upstream: {{ .Values.apisix.proxyProtocol.enableTcpPPToUpstream }} {{- end }} proxy_cache: # Proxy Caching configuration cache_ttl: {{ .Values.apisix.proxyCache.cacheTtl }} # The default caching time if the upstream does not specify the cache time zones: # The parameters of a cache {{- toYaml .Values.apisix.proxyCache.zones | nindent 10 }} delete_uri_tail_slash: {{ .Values.apisix.deleteURITailSlash }} # delete the '/' at the end of the URI # The URI normalization in servlet is a little different from the RFC's. # See https://github.com/jakartaee/servlet/blob/master/spec/src/main/asciidoc/servlet-spec-body.adoc#352-uri-path-canonicalization, # which is used under Tomcat. # Turn this option on if you want to be compatible with servlet when matching URI path. normalize_uri_like_servlet: {{ .Values.apisix.normalizeURILikeServlet }} # fine tune the parameters of LRU cache for some features like secret lru: secret: ttl: {{ .Values.apisix.lru.secret.ttl }} # seconds count: {{ .Values.apisix.lru.secret.count }} neg_ttl: {{ .Values.apisix.lru.secret.neg_ttl }} neg_count: {{ .Values.apisix.lru.secret.neg_count }} tracing: {{ .Values.apisix.tracing }} # Enable comprehensive request lifecycle tracing (SSL/SNI, rewrite, access, header_filter, body_filter, and log). # When disabled, OpenTelemetry collects only a single span per request. router: http: {{ .Values.apisix.router.http }} # radixtree_uri: match route by uri(base on radixtree) # radixtree_host_uri: match route by host + uri(base on radixtree) # radixtree_uri_with_parameter: match route by uri with parameters ssl: 'radixtree_sni' # radixtree_sni: match route by SNI(base on radixtree) {{- $proxy_mode := "" }} {{- if and .Values.service.stream.enabled .Values.service.http.enabled }} {{- $proxy_mode = "http&stream" }} {{- else if .Values.service.http.enabled }} {{- $proxy_mode = "http" }} {{- else if .Values.service.stream.enabled }} {{- $proxy_mode = "stream" }} {{- end }} proxy_mode: {{ $proxy_mode }} {{- if or (index .Values "ingress-controller" "enabled") (and .Values.service.stream.enabled (or (gt (len .Values.service.stream.tcp) 0) (gt (len .Values.service.stream.udp) 0))) }} stream_proxy: # TCP/UDP proxy {{- if or (index .Values "ingress-controller" "enabled") (gt (len .Values.service.stream.tcp) 0) }} tcp: # TCP proxy port list {{- if gt (len .Values.service.stream.tcp) 0}} {{- range .Values.service.stream.tcp }} {{- if kindIs "map" . }} - addr: {{ .addr }} {{- if hasKey . "tls" }} tls: {{ .tls }} {{- end }} {{- else }} - {{ . }} {{- end }} {{- end }} {{- else}} - 9100 {{- end }} {{- end }} {{- if or (index .Values "ingress-controller" "enabled") (gt (len .Values.service.stream.udp) 0) }} udp: # UDP proxy port list {{- if gt (len .Values.service.stream.udp) 0}} {{- range .Values.service.stream.udp }} - {{ . }} {{- end }} {{- else}} - 9200 {{- end }} {{- end }} {{- end }} {{- with .Values.apisix.dns.resolvers }} dns_resolver: # If not set, read from `/etc/resolv.conf` {{- range $resolver := . }} - {{ $resolver }} {{- end }} {{- end }} dns_resolver_valid: {{.Values.apisix.dns.validity}} resolver_timeout: {{.Values.apisix.dns.timeout}} enable_resolv_search_opt: {{ .Values.apisix.dns.enableResolvSearchOpt }} ssl: enable: {{ .Values.apisix.ssl.enabled }} listen: - port: {{ .Values.apisix.ssl.containerPort }} enable_http3: {{ .Values.apisix.ssl.enableHTTP3 }} {{- with .Values.apisix.ssl.additionalContainerPorts }} {{- toYaml . | nindent 10}} {{- end }} ssl_protocols: {{ .Values.apisix.ssl.sslProtocols | quote }} ssl_ciphers: {{ .Values.apisix.ssl.sslCiphers | quote }} ssl_session_tickets: {{ .Values.apisix.ssl.sslSessionTickets }} {{- if and .Values.apisix.ssl.enabled .Values.apisix.ssl.existingCASecret }} ssl_trusted_certificate: "/usr/local/apisix/conf/ssl/{{ .Values.apisix.ssl.certCAFilename }}" {{- end }} {{- if and .Values.apisix.ssl.enabled .Values.apisix.ssl.fallbackSNI }} fallback_sni: {{ .Values.apisix.ssl.fallbackSNI | quote }} {{- end }} {{- $useTraditionalYaml := and (eq .Values.apisix.deployment.role "traditional") (eq .Values.apisix.deployment.role_traditional.config_provider "yaml") }} {{- if $useTraditionalYaml }} status: ip: {{ default "127.0.0.1" .Values.apisix.status.ip }} port: {{ default "7085" (.Values.apisix.status.port | toString) }} {{- end}} {{ if .Values.apisix.trustedAddresses }} trusted_addresses: {{- toYaml .Values.apisix.trustedAddresses | nindent 8 }} {{ end }} nginx_config: # config for render the template to genarate nginx.conf error_log: "{{ .Values.apisix.nginx.logs.errorLog }}" error_log_level: "{{ .Values.apisix.nginx.logs.errorLogLevel }}" # warn,error worker_processes: "{{ .Values.apisix.nginx.workerProcesses }}" enable_cpu_affinity: {{ and true .Values.apisix.nginx.enableCPUAffinity }} worker_rlimit_nofile: {{ default "20480" .Values.apisix.nginx.workerRlimitNofile }} # the number of files a worker process can open, should be larger than worker_connections worker_shutdown_timeout: "{{ default "240s" .Values.apisix.nginx.workerShutdownTimeout }}" # timeout for a graceful shutdown of worker processes max_pending_timers: {{ default "16384" .Values.apisix.nginx.maxPendingTimers }} # increase it if you see "too many pending timers" error max_running_timers: {{ default "4096" .Values.apisix.nginx.maxRunningTimers }} # increase it if you see "lua_max_running_timers are not enough" error event: worker_connections: {{ default "10620" .Values.apisix.nginx.workerConnections }} {{- with .Values.apisix.nginx.envs }} envs: {{- range $env := . }} - {{ $env }} {{- end }} {{- end }} {{- if .Values.apisix.nginx.metaLuaSharedDicts }} meta: lua_shared_dict: {{- range $dict := .Values.apisix.nginx.metaLuaSharedDicts }} {{ $dict.name }}: {{ $dict.size }} {{- end }} {{- end }} stream: enable_access_log: {{ .Values.apisix.nginx.logs.stream.enableAccessLog }} {{- if .Values.apisix.nginx.logs.stream.enableAccessLog }} access_log: "{{ .Values.apisix.nginx.logs.stream.accessLog }}" access_log_format: '{{ .Values.apisix.nginx.logs.stream.accessLogFormat }}' access_log_format_escape: {{ .Values.apisix.nginx.logs.stream.accessLogFormatEscape }} {{- end }} http: enable_access_log: {{ .Values.apisix.nginx.logs.enableAccessLog }} {{- if .Values.apisix.nginx.logs.enableAccessLog }} access_log: "{{ .Values.apisix.nginx.logs.accessLog }}" access_log_format: '{{ .Values.apisix.nginx.logs.accessLogFormat }}' access_log_format_escape: {{ .Values.apisix.nginx.logs.accessLogFormatEscape }} {{- end }} keepalive_timeout: {{ .Values.apisix.nginx.keepaliveTimeout | quote }} client_header_timeout: {{ .Values.apisix.nginx.http.clientHeaderTimeout }} # timeout for reading client request header, then 408 (Request Time-out) error is returned to the client client_body_timeout: {{ .Values.apisix.nginx.http.clientBodyTimeout }} # timeout for reading client request body, then 408 (Request Time-out) error is returned to the client send_timeout: {{ .Values.apisix.nginx.http.sendTimeout }} # timeout for transmitting a response to the client.then the connection is closed client_max_body_size: {{ .Values.apisix.nginx.http.clientMaxBodySize }} # The maximum allowed size of the client request body. # If exceeded, the 413 (Request Entity Too Large) error is returned to the client. # Note that unlike Nginx, we don't limit the body size by default. underscores_in_headers: {{ .Values.apisix.nginx.http.underscoresInHeaders | quote }} # default enables the use of underscores in client request header fields real_ip_header: {{ .Values.apisix.nginx.http.realIpHeader | quote }} # http://nginx.org/en/docs/http/ngx_http_realip_module.html#real_ip_header real_ip_recursive: {{ .Values.apisix.nginx.http.realIpRecursive | quote }} # http://nginx.org/en/docs/http/ngx_http_realip_module.html#real_ip_recursive real_ip_from: # http://nginx.org/en/docs/http/ngx_http_realip_module.html#set_real_ip_from {{- range $ip := .Values.apisix.nginx.http.realIpFrom }} - {{ $ip | quote }} {{- end }} proxy_ssl_server_name: {{ .Values.apisix.nginx.http.proxySslServerName }} # send the server name (SNI) when establishing a TLS connection with the proxied HTTPS upstream upstream: keepalive: {{ .Values.apisix.nginx.http.upstream.keepalive }} # The maximum number of idle keepalive connections to upstream servers per worker process keepalive_requests: {{ .Values.apisix.nginx.http.upstream.keepaliveRequests }} # The maximum number of requests that can be served through one keepalive connection keepalive_timeout: {{ .Values.apisix.nginx.http.upstream.keepaliveTimeout }} # Timeout during which an idle keepalive connection to an upstream server will stay open charset: {{ .Values.apisix.nginx.http.charset }} # Adds the specified charset to the "Content-Type" response header field variables_hash_max_size: {{ .Values.apisix.nginx.http.variablesHashMaxSize }} # Sets the maximum size of the variables hash table {{- if .Values.apisix.nginx.customLuaSharedDicts }} custom_lua_shared_dict: # add custom shared cache to nginx.conf {{- range $dict := .Values.apisix.nginx.customLuaSharedDicts }} {{ $dict.name }}: {{ $dict.size }} {{- end }} {{- end }} {{- if .Values.apisix.nginx.luaSharedDicts }} lua_shared_dict: {{- range $dict := .Values.apisix.nginx.luaSharedDicts }} {{ $dict.name }}: {{ $dict.size }} {{- end }} {{- end }} {{- if .Values.apisix.nginx.configurationSnippet.main }} main_configuration_snippet: {{- toYaml .Values.apisix.nginx.configurationSnippet.main | indent 6 }} {{- end }} {{- if .Values.apisix.nginx.configurationSnippet.httpStart }} http_configuration_snippet: {{- toYaml .Values.apisix.nginx.configurationSnippet.httpStart | indent 6 }} {{- end }} {{- if .Values.apisix.nginx.configurationSnippet.httpEnd }} http_end_configuration_snippet: {{- toYaml .Values.apisix.nginx.configurationSnippet.httpEnd | indent 6 }} {{- end }} {{- if .Values.apisix.nginx.configurationSnippet.httpSrv }} http_server_configuration_snippet: {{- toYaml .Values.apisix.nginx.configurationSnippet.httpSrv | indent 6 }} {{- end }} {{- if .Values.apisix.nginx.configurationSnippet.httpAdmin }} http_admin_configuration_snippet: {{ toYaml .Values.apisix.nginx.configurationSnippet.httpAdmin | indent 6 }} {{- end }} {{- if .Values.apisix.nginx.configurationSnippet.stream }} stream_configuration_snippet: {{- toYaml .Values.apisix.nginx.configurationSnippet.stream | indent 6 }} {{- end }} graphql: max_size: {{ int .Values.apisix.graphql.maxSize }} # the maximum size limitation of graphql in bytes {{- if .Values.apisix.discovery.enabled }} discovery: {{- range $key, $value := .Values.apisix.discovery.registry }} {{- if $value }} {{ $key }}: {{- include "apisix.tplvalues.render" (dict "value" $value "context" $) | nindent 8 }} {{- else }} {{ $key }}: {} {{- end }} {{- end }} {{- end }} {{- if .Values.apisix.vault.enabled }} vault: host: {{ .Values.apisix.vault.host }} timeout: {{ .Values.apisix.vault.timeout }} token: {{ .Values.apisix.vault.token }} prefix: {{ .Values.apisix.vault.prefix }} {{- end }} {{- if .Values.apisix.plugins }} plugins: # plugin list {{- range $plugin := .Values.apisix.plugins }} {{- if ne $plugin "" }} - {{ $plugin }} {{- end }} {{- end }} {{- if .Values.apisix.customPlugins.enabled }} {{- range $plugin := .Values.apisix.customPlugins.plugins }} - {{ $plugin.name }} {{- end }} {{- end }} {{- end }} {{- if .Values.apisix.stream_plugins }} stream_plugins: {{- range $plugin := .Values.apisix.stream_plugins }} {{- if ne $plugin "" }} - {{ $plugin }} {{- end }} {{- end }} {{- end }} {{- if .Values.apisix.extPlugin.enabled }} ext-plugin: cmd: {{- range $arg := .Values.apisix.extPlugin.cmd }} - {{ $arg }} {{- end }} {{- end }} {{- if or .Values.apisix.pluginAttrs .Values.apisix.customPlugins.enabled .Values.apisix.prometheus.enabled}} {{- $pluginAttrs := include "apisix.pluginAttrs" . -}} {{- if gt (len ($pluginAttrs | fromYaml)) 0 }} plugin_attr: {{- $pluginAttrs | nindent 6 }} {{- end }} {{- end }} {{- if .Values.apisix.wasm.enabled }} wasm: plugins: {{- toYaml .Values.apisix.wasm.plugins | nindent 8 }} {{- end }} deployment: role: {{ .Values.apisix.deployment.role }} {{- if eq .Values.apisix.deployment.role "traditional" }} role_traditional: config_provider: {{ default "etcd" .Values.apisix.deployment.role_traditional.config_provider }} {{- end }} {{- if eq .Values.apisix.deployment.role "control_plane" }} role_control_plane: config_provider: etcd {{- end }} {{- if eq .Values.apisix.deployment.role "data_plane" }} role_data_plane: config_provider: {{- eq .Values.apisix.deployment.mode "standalone" | ternary "yaml" "etcd" | indent 1 }} {{- end }} {{- if not (eq .Values.apisix.deployment.role "data_plane") }} admin: {{- if .Values.etcd.enabled }} enable_admin_ui: {{ .Values.apisix.admin.enable_admin_ui }} {{- end }} allow_admin: # http://nginx.org/en/docs/http/ngx_http_access_module.html#allow {{- if .Values.apisix.admin.allow.ipList }} {{- range $ips := .Values.apisix.admin.allow.ipList }} - {{ $ips }} {{- end }} {{- else }} - 0.0.0.0/0 {{- end}} {{- if (index .Values "ingress-controller" "enabled") }} - 0.0.0.0/0 {{- end}} # - "::/64" {{- if .Values.apisix.admin.enabled }} admin_listen: ip: {{ .Values.apisix.admin.ip }} port: {{ .Values.apisix.admin.port }} {{- end }} # Default token when use API to call for Admin API. # *NOTE*: Highly recommended to modify this value to protect APISIX's Admin API. # Disabling this configuration item means that the Admin API does not # require any authentication. admin_key: # admin: can everything for configuration data - name: "admin" {{- if .Values.apisix.admin.credentials.secretName }} key: ${{"{{"}}APISIX_ADMIN_KEY{{"}}"}} {{- else }} key: {{ .Values.apisix.admin.credentials.admin }} {{- end }} role: admin # viewer: only can view configuration data - name: "viewer" {{- if .Values.apisix.admin.credentials.secretName }} key: ${{"{{"}}APISIX_VIEWER_KEY{{"}}"}} {{- else }} key: {{ .Values.apisix.admin.credentials.viewer }} {{- end }} role: viewer {{- end }} {{- if not (eq .Values.apisix.deployment.mode "standalone")}} etcd: {{- if .Values.etcd.enabled }} host: # it's possible to define multiple etcd hosts addresses of the same etcd cluster. {{- if .Values.etcd.fullnameOverride }} - "{{ include "apisix.etcd.auth.scheme" . }}://{{ .Values.etcd.fullnameOverride }}:{{ .Values.etcd.service.port }}" {{- else }} - "{{ include "apisix.etcd.auth.scheme" . }}://{{ .Release.Name }}-etcd.{{ .Release.Namespace }}.svc.{{ .Values.etcd.clusterDomain }}:{{ .Values.etcd.service.port }}" {{- end}} {{- else }} host: # it's possible to define multiple etcd hosts addresses of the same etcd cluster. {{- range $value := .Values.externalEtcd.host }} - "{{ $value }}" # multiple etcd address {{- end}} {{- end }} prefix: {{ .Values.etcd.prefix | quote }} # configuration prefix in etcd timeout: {{ .Values.etcd.timeout }} # The timeout in seconds when connect/read/write to etcd watch_timeout: {{ .Values.etcd.watchTimeout }} # The timeout in seconds when watch etcd startup_retry: {{ .Values.etcd.startupRetry }} # the number of retry to etcd during the startup {{- if and (not .Values.etcd.enabled) .Values.externalEtcd.user }} user: {{ .Values.externalEtcd.user | quote }} password: "{{ print "${{ APISIX_ETCD_PASSWORD }}" }}" {{- else if and .Values.etcd.enabled .Values.etcd.auth.rbac.create }} user: "root" password: "{{ print "${{APISIX_ETCD_PASSWORD}}" }}" {{- end }} {{- if .Values.etcd.auth.tls.enabled }} tls: cert: "/etcd-ssl/{{ .Values.etcd.auth.tls.certFilename }}" key: "/etcd-ssl/{{ .Values.etcd.auth.tls.certKeyFilename }}" verify: {{ .Values.etcd.auth.tls.verify }} sni: "{{ .Values.etcd.auth.tls.sni }}" {{- end }} {{- end }} {{- end }}