09d0d4e59d
* chart_version_detector: repo가 이미 등록돼 있으면 update를 건너뛰던 버그를 고친다 repo alias가 이미 helm repo list에 있으면 add/update를 통째로 건너뛰어, 로컬에 예전에 캐시된 index.yaml을 그대로 썼다 — latest_version이 조용히 낡은 값으로 나온다(실측: secrets-operator에서 실제 최신 0.11.8 대신 0.11.4가 나왔다). repo 등록 여부와 무관하게 update는 항상 호출하도록 고친다. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * secrets-operator v0.10.33 → 0.11.8 호환성: breaking_change_check 결과 breaking=false(이 차트는 custom-values.yaml이 없어 오버라이드 충돌 자체가 불가능). CVE: infisical/kubernetes-operator 이미지를 trivy+CoverageProbe로 실측한 결과 실효 HIGH 차단이 34→10건으로 줄었다(CRITICAL은 둘 다 0, 둘 다 CoverageProbe: ok로 측정 신뢰 가능). 신규 CRD 3개 (InfisicalAuth·InfisicalConnection·InfisicalStaticSecret) 추가 — 상세는 CUSTOM-README.md. 기존 v0.10.33 디렉토리는 카탈로그 정책대로 동결 보관한다(삭제하지 않음). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * secrets-operator 자체 빌드 이미지 배포 테스트 오버라이드 추가 dev 클러스터에서 hardened-containers 자체 빌드 이미지(v0.11.8-security-hardened)로 실제 업그레이드·CRD 적용·Infisical 시크릿 동기화까지 검증할 때 쓴 오버라이드. 카탈로그 값(이 차트는 애초에 custom-values.yaml 없음)은 건드리지 않는다. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
88 lines
2.2 KiB
YAML
88 lines
2.2 KiB
YAML
# -- The Infisical API host URL. This is the default host used when no hostAPI is set on the CRD or global ConfigMap.
|
|
hostAPI: "https://app.infisical.com/api"
|
|
|
|
logger:
|
|
# -- The output of the logs. Can be "stdout" or "stderr". Defaults to "stderr".
|
|
writer: "stderr"
|
|
|
|
controllerManager:
|
|
serviceAccount:
|
|
create: true
|
|
name: ""
|
|
annotations: {}
|
|
nodeSelector: {}
|
|
tolerations: []
|
|
affinity: {}
|
|
topologySpreadConstraints: []
|
|
# -- Extra volumes to add to the pod
|
|
extraVolumes: []
|
|
# -- Extra init containers to add to the pod
|
|
extraInitContainers: []
|
|
manager:
|
|
args:
|
|
- --metrics-bind-address=:8443
|
|
- --leader-elect
|
|
- --health-probe-bind-address=:8081
|
|
containerSecurityContext:
|
|
allowPrivilegeEscalation: false
|
|
capabilities:
|
|
drop:
|
|
- ALL
|
|
readOnlyRootFilesystem: true
|
|
image:
|
|
repository: infisical/kubernetes-operator
|
|
tag: v0.11.8
|
|
resources:
|
|
limits:
|
|
cpu: 500m
|
|
memory: 128Mi
|
|
requests:
|
|
cpu: 10m
|
|
memory: 64Mi
|
|
# -- Extra environment variables to add to the manager container
|
|
extraEnv: []
|
|
# -- Extra volume mounts to add to the manager container
|
|
extraVolumeMounts: []
|
|
podSecurityContext:
|
|
runAsNonRoot: true
|
|
seccompProfile:
|
|
type: RuntimeDefault
|
|
replicas: 1
|
|
kubernetesClusterDomain: cluster.local
|
|
|
|
# DEPRECATED: Use scopedNamespaces instead. This field will be removed in a future version.
|
|
# If both scopedNamespace and scopedNamespaces are set, scopedNamespaces takes precedence.
|
|
scopedNamespace: ""
|
|
|
|
# List of namespaces to watch. If empty, the operator watches all namespaces (cluster-scoped).
|
|
# When scopedRBAC is true, a Role and RoleBinding will be created in each namespace.
|
|
# Example:
|
|
# scopedNamespaces:
|
|
# - team-a-namespace
|
|
# - team-b-namespace
|
|
scopedNamespaces: []
|
|
|
|
scopedRBAC: false
|
|
installCRDs: true
|
|
imagePullSecrets: []
|
|
|
|
metricsService:
|
|
ports:
|
|
- name: https
|
|
port: 8443
|
|
protocol: TCP
|
|
targetPort: 8443
|
|
type: ClusterIP
|
|
|
|
telemetry:
|
|
serviceMonitor:
|
|
enabled: false
|
|
|
|
selectors: {}
|
|
scheme: https
|
|
port: https
|
|
path: /metrics
|
|
bearerTokenFile: /var/run/secrets/kubernetes.io/serviceaccount/token
|
|
interval: 30s
|
|
scrapeTimeout: 10s
|