Files
service-catalog/manifests/helm/apisix/2.16.0/charts/apisix-ingress-controller/README.md
T
wbsong111 16321b52c7 dipup 사용 차트를 카탈로그에 동기화 (7개 갱신 + 5개 신규)
dipup 이 go:embed 로 직접 보관·관리하던 Helm 차트를 카탈로그로 옮기는 첫 단계다.
두 저장소가 각자 CVE/SBOM 파이프라인을 운영하는 이중화를 해소하려면, 먼저 카탈로그가
dipup 과 같은 차트·같은 이미지를 보게 만들어야 한다.

배경: CVE 파이프라인 구성 이전에 두 곳에서 같은 차트를 유지하기 어려워 dipup 이 별도로
차트를 관리해 왔고, 그 결과 버전이 갈라졌다. 겹치는 10개 중 버전까지 일치하는 것은
postgresql-ha·dnsup 2개뿐이었다.

## 버전 갱신 (7개) — 신규 버전 디렉토리 추가, 구버전은 보존

| 차트 | 기존 | 신규 | appVersion |
|---|---|---|---|
| apisix | 2.14.0 | 2.16.0 | 3.16.0 → 3.17.0 |
| argo-cd | 7.7.0 | 7.8.11 | v2.13.0 → v2.14.5 |
| cert-manager | v1.16.1 | v1.21.0 | 동일 |
| gitea | 12.4.0 | 12.6.0 | 1.24.6 → 1.26.1 |
| harbor | 1.16.2 | 1.19.1 | 2.12.2 → 2.15.1 |
| kyverno | 3.4.1 | 3.8.2 | v1.14.1 → v1.18.2 |
| rancher | 2.10.1 | 2.14.3 | v2.10.1 → v2.14.3 |

차트 본문은 dipup 이 임베딩한 .tgz 를 그대로 전개했다(네트워크 pull 이 아니라 dipup 이
실제 배포하는 바이트와 동일함을 보장하기 위함). BUILD-README/CUSTOM-README/custom-values
3개 파일은 구버전에서 승계했다.

## 신규 추가 (5개)

infisical-standalone 1.9.0, longhorn 109.3.1+up1.11.2, longhorn-crd 109.3.1+up1.11.2,
metallb 0.16.1, secrets-operator v0.10.33.

longhorn/longhorn-crd 는 업스트림이 아니라 Rancher 패키징 차트(109.x 라인, Rancher 2.14
계열과 짝)다. BUILD-README 의 `helm repo add` 라인은 chart_version_detector 가 파싱하는
계약이라 실제 업스트림 repo 를 검증해 기재했고, 감지기로 현재/최신 버전이 정상 조회되는
것을 확인했다.

## custom-values — 버전과 결합된 이미지 핀 정리

카탈로그 스캐너가 dipup 의 effective image 를 보게 하려면 이미지 핀이 맞아야 한다.

- **kyverno: 승계본이 3.8.2 에서 깨져 재작성.** 3.4.1 은 정리 훅이
  `registry: ~ / repository: bitnami/kubectl` 이라 bitnamilegacy 오버라이드가 맞았지만,
  3.8.2 는 `registry: ghcr.io / repository: kyverno/readiness-checker` 로 바뀌었다.
  그대로 옮기면 ghcr.io/bitnamilegacy/kubectl 이라는 없는 좌표가 된다. 해당 오버라이드를
  제거하고, 3.8.2 에서 삭제된 policyReportsCleanup 키도 함께 뺐다. 남는 조치는 tag 고정뿐
  (기본 tag 가 비어 latest 로 떨어짐 → v1.18.2 로 고정).
- apisix: 3.16.0-keycloak-authz → 3.17.0-keycloak-authz (차트 appVersion 과 함께 이동)
- gitea: image.tag 1.26.4 핀 추가 — 차트 기본 1.26.1 대비 CRITICAL 2→0, HIGH 44→12
- infisical: image.tag v0.162.7 핀 — 기본 v0.158.x 는 stale Debian base 로 OS 기인 CVE
  다수(fixable CRITICAL 53→5, HIGH 491→55). redis/postgresql 은 bitnamilegacy 좌표로.
- longhorn: 실측 기반 리소스 튜닝(manager request, guaranteedInstanceManagerCPU,
  systemManagedCSIComponentsResourceLimits). replica 수처럼 노드 수에 의존하는 값은
  넣지 않았다 — 소비 측에서 주입한다.

## 검증

12개 차트 전부 `helm template --kube-version 1.34.1` 렌더 성공. 렌더 결과 이미지가
dipup 배포 이미지와 일치함을 확인(paasup/apisix:3.17.0-keycloak-authz,
gitea:1.26.4-rootless, readiness-checker:v1.18.2, infisical:v0.162.7).

## 범위에서 뺀 것

- **keycloak**: 카탈로그는 codecentric(app 17.0.1-legacy), dipup 은 bitnami(app 26.2.4)로
  계보가 다르다. 이슈 #1(bitnami 대체 방안 검토)의 결론이 나온 뒤 처리한다.
- **rancher-monitoring(-crd)**: 14c05f1 에서 불필요 판단으로 제거된 차트이고
  victoria-metrics 스택으로 대체 예정이라 추가하지 않는다.
- **dip-api/dip-console**: 자체 개발 차트로 각 앱 저장소가 출처다. 대조 결과 앱 저장소와
  dipup 사본이 일치해 카탈로그가 개입할 이유가 없다.
- **postgresql-ha/dnsup**: 이미 버전이 일치해 작업 대상이 아니었다.

## 후속 과제

dnsup 은 카탈로그·dipup 사본(1.0.1)이 원본(dip-console-api helm/dnsup 1.0.0)보다 앞서
있다. 1.0.1 에만 있는 service.LoadBalancerIP·service.annotations 지원을 원본으로 백포트한
뒤, 카탈로그에서 dnsup 을 제거하는 것이 자체 개발 차트 출처 원칙에 맞다.
2026-08-06 09:42:24 +09:00

10 KiB

Apache APISIX ingress controller

APISIX Ingress controller for Kubernetes using Apache APISIX as a high performance reverse proxy and load balancer.

If you have installed multiple ingress controller, add the kubernetes.io/ingress.class: apisix annotation to your Ingress resources.

This chart bootstraps an apisix-ingress-controller deployment on a Kubernetes cluster using the Helm package manager.

Prerequisites

Apisix ingress controller requires Kubernetes version 1.16+.

Get Repo Info

helm repo add apisix https://apache.github.io/apisix-helm-chart
helm repo update

Install Chart

Important: only helm3 is supported

helm install [RELEASE_NAME] apisix/apisix-ingress-controller --namespace ingress-apisix --create-namespace

The command deploys apisix-ingress-controller on the Kubernetes cluster in the default configuration.

See configuration below.

See helm install for command documentation.

Uninstall Chart

helm uninstall [RELEASE_NAME] --namespace ingress-apisix

This removes all the Kubernetes components associated with the chart and deletes the release.

See helm uninstall for command documentation.

Upgrading Chart

helm upgrade [RELEASE_NAME] [CHART] --install

See helm upgrade for command documentation.

Configuration

See Customizing the Chart Before Installing. To see all configurable options with detailed comments, visit the chart's values.yaml, or run these configuration commands:

helm show values apisix/apisix-ingress-controller

Pod priority

priorityClassName field referenced a name of a created PriorityClass object. Check here for more details.

Security context

A security context provides us with a way to define privilege and access control for a Pod or even at the container level.

Check here to see the SecurityContext resource with more detail.

Check also here to see a full explanation and some examples to configure the security context.

Right below you have an example of the security context configuration. In this case, we define that all the processes in the container will run with user ID 1000.

...

spec:
  securityContext:
    runAsUser: 1000
    runAsGroup: 3000
...

The same for the group definition, where we define the primary group of 3000 for all processes.

It's quite important to know, if the runAsGroup is omited, the primary group will be root(0), which in some cases goes against some security policies.

To define this configuration at the pod level, you need to set:

    --set podSecurityContext.runAsUser=«VALUE»
    --set podSecurityContext.runAsGroup=«VALUE»
    ...

The same for container level, you need to set:

    --set securityContext.runAsUser=«VALUE»
    --set SecurityContext.runAsGroup=«VALUE»
    ...

Values

Key Type Default Description
apisix.adminService.name string "apisix-admin"
apisix.adminService.namespace string "apisix-ingress"
apisix.adminService.port int 9180
autoscaling.enabled bool false
autoscaling.minReplicas int 1
config.controllerName string "apisix.apache.org/apisix-ingress-controller"
config.disableGatewayAPI bool false
config.enableHTTP2 bool false
config.execADCTimeout string "15s"
config.kubernetes.defaultIngressClass bool false
config.kubernetes.ingressClass string "apisix"
config.leaderElection.disable bool false
config.leaderElection.id string "apisix-ingress-controller-leader"
config.leaderElection.leaseDuration string "15s"
config.leaderElection.renewDeadline string "10s"
config.leaderElection.retryPeriod string "2s"
config.listenerPortMatchMode string "auto"
config.logLevel string "info"
config.metricsAddr string ":8080"
config.probeAddr string ":8081"
config.provider.initSyncDelay string "20m"
config.provider.syncPeriod string "1m"
config.provider.type string "apisix"
config.secureMetrics bool false
deployment.adcContainer object {"config":{"logLevel":"info"},"image":{"repository":"ghcr.io/api7/adc","tag":"0.26.0"}} Set adc sidecar container configuration
deployment.affinity object {}
deployment.annotations object {} Add annotations to Apache APISIX ingress controller resource
deployment.image.pullPolicy string "IfNotPresent"
deployment.image.repository string "apache/apisix-ingress-controller"
deployment.image.tag string "2.1.0"
deployment.imagePullSecrets list []
deployment.nodeSelector object {}
deployment.podAnnotations object {}
deployment.podSecurityContext object {"fsGroup":2000} Set security context for the pod fsGroup: 2000 ensures containers can share Unix socket files via a common group.
deployment.replicas int 1
deployment.resources object {} Set pod resource requests & limits
deployment.tolerations list []
deployment.topologySpreadConstraints list [] Topology Spread Constraints for pod assignment spread across your cluster among failure-domains ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/#spread-constraints-for-pods
fullnameOverride string ""
gatewayProxy.createDefault bool false Controls whether to create a default GatewayProxy custom resource.
gatewayProxy.provider object {"controlPlane":{"auth":{"adminKey":{"value":"edd1c9f034335f136f87ad84b625c8f1","valueFrom":{}},"type":"AdminKey"},"endpoints":[],"service":{"name":"","port":9180}},"pluginMetadata":{},"plugins":[],"type":"ControlPlane"} Configuration for the GatewayProxy provider connection
gatewayProxy.provider.controlPlane object {"auth":{"adminKey":{"value":"edd1c9f034335f136f87ad84b625c8f1","valueFrom":{}},"type":"AdminKey"},"endpoints":[],"service":{"name":"","port":9180}} ControlPlane provider specific configuration Either endpoints or service must be specified, but not both.
gatewayProxy.provider.controlPlane.auth object {"adminKey":{"value":"edd1c9f034335f136f87ad84b625c8f1","valueFrom":{}},"type":"AdminKey"} Authentication configuration for control plane connection
gatewayProxy.provider.controlPlane.auth.adminKey object {"value":"edd1c9f034335f136f87ad84b625c8f1","valueFrom":{}} AdminKey authentication configuration. Either value or valueFrom must be specified, but not both.
gatewayProxy.provider.controlPlane.auth.adminKey.value string "edd1c9f034335f136f87ad84b625c8f1" The admin key value for authentication.
gatewayProxy.provider.controlPlane.auth.adminKey.valueFrom object {} Reference to admin key stored in a Kubernetes Secret
gatewayProxy.provider.controlPlane.auth.type string AdminKey Authentication type. Only AdminKey is currently supported.
gatewayProxy.provider.controlPlane.endpoints list [] List of APISIX control plane Admin API endpoints. example: ["http://apisix-admin.default.svc.cluster.local:9180"]
gatewayProxy.provider.controlPlane.service object {"name":"","port":9180} Alternatively, reference a Kubernetes Service for the APISIX Admin API.
gatewayProxy.provider.pluginMetadata object {} Global plugin metadata shared by all instances of the same plugin.
gatewayProxy.provider.plugins list [] List of global plugins to be enabled on the GatewayProxy.
gatewayProxy.provider.type string "ControlPlane" Specifies the provider type for the GatewayProxy.
labelsOverride object {} Override default labels assigned to Apache APISIX ingress controller resource
nameOverride string "" Default values for apisix-ingress-controller. This is a YAML-formatted file. Declare variables to be passed into your templates.
podDisruptionBudget object {"enabled":false,"maxUnavailable":1,"minAvailable":"90%"} See https://kubernetes.io/docs/tasks/run-application/configure-pdb/ for more details
podDisruptionBudget.enabled bool false Enable or disable podDisruptionBudget
podDisruptionBudget.maxUnavailable int 1 Set the maxUnavailable of podDisruptionBudget
podDisruptionBudget.minAvailable string "90%" Set the minAvailable of podDisruptionBudget. You can specify only one of maxUnavailable and minAvailable in a single PodDisruptionBudget. See Specifying a Disruption Budget for your Application for more details
serviceMonitor.annotations object {} @param serviceMonitor.annotations ServiceMonitor annotations
serviceMonitor.enabled bool false Enable or disable ServiceMonitor
serviceMonitor.interval string "15s" @param serviceMonitor.interval Interval at which metrics should be scraped
serviceMonitor.labels object {} @param serviceMonitor.labels ServiceMonitor extra labels
serviceMonitor.metricRelabelings object {} @param serviceMonitor.metricRelabelings MetricRelabelConfigs to apply to samples before ingestion. ref: https://prometheus.io/docs/prometheus/latest/configuration/configuration/#metric_relabel_configs
serviceMonitor.namespace string "monitoring" @param serviceMonitor.namespace Namespace in which to create the ServiceMonitor
webhook.certificate.provided bool false Set to true if you want to provide your own certificate
webhook.enabled bool true Enable or disable admission webhook
webhook.failurePolicy string "Ignore" Failure policy for the webhook (Fail or Ignore)
webhook.port int 9443 The port for the webhook server to listen on
webhook.timeoutSeconds int 10 Timeout in seconds for the webhook