#version: lakekeeper, 0.8.1 catalog: resources: {} ingress: enabled: true annotations: cert-manager.io/cluster-issuer: root-ca-issuer cert-manager.io/duration: 8760h cert-manager.io/renew-before: 720h konghq.com/https-redirect-status-code: '301' konghq.com/protocols: https host: "lakekeeper2.gke.paasup.io" ingressClassName: "kong" tls: enabled: true secretName: "lakekeeper2-tls-secret" extraEnv: - name: SSL_CERT_FILE value: "/tmp/ca.crt" extraVolumeMounts: - name: keycloak-tls mountPath: "/tmp/ca.crt" subPath: ca.crt readOnly: true extraVolumes: - name: keycloak-tls secret: secretName: keycloak-tls postgresql: storage: className: requestedSize: 5Gi resources: {} auth: oauth2: providerUri: "https://keycloak.gke.paasup.io/realms/paasup" audience: "lakekeeper" ui: clientID: "service-lakekeeper2" scopes: "lakekeeper" authz: backend: "openfga" openfga: apiKey: "SkvHuWNibZZH" internalOpenFGA: true openfga: resources: {} playground: enabled: true authn: method: "preshared" preshared: keys: ["SkvHuWNibZZH"] postgresql: primary: resources: {} persistence: storageClass: "" size: 8Gi