DirectorySecurity AdvisoriesPricing
Sign in
Directory
external-secrets logoHELM

external-secrets

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart versions
Default values
Chart metadata
Images

Tag:
Compare:

1
global:
2
nodeSelector: {}
3
tolerations: []
4
topologySpreadConstraints: []
5
# - maxSkew: 1
6
# topologyKey: topology.kubernetes.io/zone
7
# whenUnsatisfiable: ScheduleAnyway
8
# matchLabelKeys:
9
# - pod-template-hash
10
# - maxSkew: 1
11
# topologyKey: kubernetes.io/hostname
12
# whenUnsatisfiable: DoNotSchedule
13
# matchLabelKeys:
14
# - pod-template-hash
15
affinity: {}
16
# -- Global hostAliases to be applied to all deployments
17
hostAliases: []
18
# -- Global pod labels to be applied to all deployments
19
podLabels: {}
20
# -- Global pod annotations to be applied to all deployments
21
podAnnotations: {}
22
# -- Global imagePullSecrets to be applied to all deployments
23
imagePullSecrets: []
24
# -- Global image repository to be applied to all deployments
25
repository: ""
26
compatibility:
27
openshift:
28
# -- Manages the securityContext properties to make them compatible with OpenShift.
29
# Possible values:
30
# auto - Apply configurations if it is detected that OpenShift is the target platform.
31
# force - Always apply configurations.
32
# disabled - No modification applied.
33
adaptSecurityContext: auto
34
replicaCount: 1
35
bitwarden-sdk-server:
36
enabled: false
37
namespaceOverride: ""
38
# -- Specifies the amount of historic ReplicaSets k8s should keep (see https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#clean-up-policy)
39
revisionHistoryLimit: 10
40
image:
41
repository: cgr.dev/chainguard-private/external-secrets-fips
42
pullPolicy: IfNotPresent
43
# -- The image tag to use. The default is the chart appVersion.
44
tag: 2.11.0-r1@sha256:f59cf8e863c5177345b463b38bb33a72a0efce4c54b967563ea5b09e423028ee
45
# -- The flavour of tag you want to use
46
# There are different image flavours available, like distroless and ubi.
47
# Please see GitHub release notes for image tags for these flavors.
48
# By default, the distroless image is used.
49
flavour: ""
50
# -- If set, install and upgrade CRDs through helm chart.
51
installCRDs: true
52
crds:
53
# -- If true, create CRDs for Cluster External Secret. If set to false you must also set processClusterExternalSecret: false.
54
createClusterExternalSecret: true
55
# -- If true, create CRDs for Cluster Secret Store. If set to false you must also set processClusterStore: false.
56
createClusterSecretStore: true
57
# -- If true, create CRDs for Secret Store. If set to false you must also set processSecretStore: false.
58
createSecretStore: true
59
# -- If true, create CRDs for Cluster Generator. If set to false you must also set processClusterGenerator: false.
60
createClusterGenerator: true
61
# -- If true, create CRDs for Cluster Push Secret. If set to false you must also set processClusterPushSecret: false.
62
createClusterPushSecret: true
63
# -- If true, create CRDs for Push Secret. If set to false you must also set processPushSecret: false.
64
createPushSecret: true
65
annotations: {}
66
conversion:
67
# -- Conversion is disabled by default as we stopped supporting v1alpha1.
68
enabled: false
69
# -- If true, enable v1beta1 API version serving for ExternalSecret, ClusterExternalSecret, SecretStore, and ClusterSecretStore CRDs.
70
# v1beta1 is deprecated. Only enable this for backward compatibility if you have existing v1beta1 resources.
71
# Warning: This flag will be removed on 2026.05.01.
72
unsafeServeV1Beta1: false
73
imagePullSecrets: []
74
nameOverride: ""
75
fullnameOverride: ""
76
namespaceOverride: ""
77
# -- Additional labels added to all helm chart resources.
78
commonLabels: {}
79
# -- If true, external-secrets will perform leader election between instances to ensure no more
80
# than one instance of external-secrets operates at a time.
81
leaderElect: false
82
# -- ID of the lease object used for leader election.
83
# Leave empty to use the default ('external-secrets-controller').
84
# Set to a unique value when running multiple independent ESO deployments in the same namespace.
85
# @default -- "external-secrets-controller"
86
leaderElectionID: ""
87
# -- Duration that non-leader candidates will wait to force acquire leadership.
88
# Increase this along with renewDeadline to tolerate a busy or briefly unavailable API server
89
# (for example during control plane maintenance) without churning leadership.
90
# Leave empty to use the controller default ('15s').
91
# @default -- "15s"
92
leaderElectionLeaseDuration: ""
93
# -- Duration that the acting leader will retry refreshing leadership before giving up.
94
# Must be less than leaderElectionLeaseDuration.
95
# Leave empty to use the controller default ('10s').
96
# @default -- "10s"
97
leaderElectionRenewDeadline: ""
98
# -- Duration the leader election client waits between tries of actions.
99
# Leave empty to use the controller default ('2s').
100
# @default -- "2s"
101
leaderElectionRetryPeriod: ""
102
# -- If set external secrets will filter matching
103
# Secret Stores with the appropriate controller values.
104
controllerClass: ""
105
# -- If true external secrets will use recommended kubernetes
106
# annotations as prometheus metric labels.
107
extendedMetricLabels: false
108
# -- If set external secrets are only reconciled in the
109
# provided namespace
110
scopedNamespace: ""
111
# -- If true, create scoped RBAC roles and implicitly disable cluster-scoped
112
# controllers. Scoped to scopedNamespace if set, otherwise to .Release.Namespace.
113
scopedRBAC: false
114
# -- If true the OpenShift finalizer permissions will be added to RBAC
115
openshiftFinalizers: true
116
# -- If true the system:auth-delegator ClusterRole will be added to RBAC
117
systemAuthDelegator: false
118
# -- if true, the operator will process cluster external secret. Else, it will ignore them.
119
# When enabled, this adds update/patch permissions on namespaces to handle finalizers for proper
120
# cleanup during namespace deletion, preventing race conditions with ExternalSecrets.
121
processClusterExternalSecret: true
122
# -- if true, the operator will process cluster push secret. Else, it will ignore them.
123
processClusterPushSecret: true
124
# -- if true, the operator will process cluster store. Else, it will ignore them.
125
processClusterStore: true
126
# -- if true, the operator will process secret store. Else, it will ignore them.
127
processSecretStore: true
128
# -- Default time duration between reconciling (Cluster)SecretStores.
129
storeRequeueInterval: ""
130
# -- if true, the operator will process cluster generator. Else, it will ignore them.
131
processClusterGenerator: true
132
# -- if true, the operator will process push secret. Else, it will ignore them.
133
processPushSecret: true
134
# -- Enable support for generic targets (ConfigMaps, Custom Resources).
135
# Warning: Using generic target. Make sure access policies and encryption are properly configured.
136
# When enabled, this grants the controller permissions to create/update/delete
137
# ConfigMaps and optionally other resource types specified in generic.resources.
138
genericTargets:
139
# -- Enable generic target support
140
enabled: false
141
# -- List of additional resource types to grant permissions for.
142
# Each entry should specify apiGroup, resources, and verbs.
143
# Example:
144
# resources:
145
# - apiGroup: "argoproj.io"
146
# resources: ["applications"]
147
# verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
148
resources: []
149
# -- Specifies whether an external secret operator deployment be created.
150
createOperator: true
151
# -- if true, HTTP2 will be enabled for the services created by all controllers, curently metrics and webhook.
152
enableHTTP2: false
153
# -- TLS security profile settings applied to all controller, webhook, and certController deployments.
154
# These can be overridden per-component via webhook.tls and certController.tls.
155
tls:
156
# -- Minimum TLS version supported (e.g. "1.2" or "1.3"). If empty, the Go CLI default applies.
157
# +docs:property
158
minVersion: ""
159
# -- Comma-separated list of TLS cipher suites (TLS_CIPHER_SUITE names).
160
# Does not apply to TLS 1.3. If empty, Go defaults apply.
161
# +docs:property
162
ciphers: ""
163
# -- Ordered list of TLS key exchange curves (e.g. X25519, CurveP256, or decimal CurveID).
164
# If empty, Go defaults apply.
165
# +docs:property
166
curvePreferences: []
167
# -- Vault token cache configuration
168
vault:
169
# -- Enable Vault token cache. External secrets will reuse the Vault token without creating a new one on each request.
170
enableTokenCache: false
171
# -- Maximum size of Vault token cache. Only used if enableTokenCache is true.
172
tokenCacheSize: 262144
173
# -- Specifies the number of concurrent ExternalSecret Reconciles external-secret executes at
174
# a time.
175
concurrent: 1
176
# -- Specifies Log Params to the External Secrets Operator
177
log:
178
level: info
179
timeEncoding: epoch
180
service:
181
# -- Set the ip family policy to configure dual-stack see [Configure dual-stack](https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services)
182
ipFamilyPolicy: ""
183
# -- Sets the families that should be supported and the order in which they should be applied to ClusterIP as well. Can be IPv4 and/or IPv6.
184
ipFamilies: []
185
serviceAccount:
186
# -- Specifies whether a service account should be created.
187
create: true
188
# -- Automounts the service account token in all containers of the pod
189
automount: true
190
# -- Annotations to add to the service account.
191
annotations: {}
192
# -- Extra Labels to add to the service account.
193
extraLabels: {}
194
# -- The name of the service account to use.
195
# If not set and create is true, a name is generated using the fullname template.
196
name: ""
197
rbac:
198
# -- Specifies whether role and rolebinding resources should be created.
199
create: true
200
# -- Specifies whether the serviceaccounts/token create permission is included in the controller RBAC.
201
# When set to false, users must create per-ServiceAccount Role/RoleBinding with resourceNames constraint
202
# to grant ESO token creation for specific ServiceAccounts referenced in SecretStore specs.
203
serviceAccountTokenCreate: true
204
servicebindings:
205
# -- Specifies whether a clusterrole to give servicebindings read access should be created.
206
create: true
207
# -- Specifies whether permissions are aggregated to the view ClusterRole
208
aggregateToView: true
209
# -- Specifies whether permissions are aggregated to the edit ClusterRole
210
aggregateToEdit: true
211
# -- Specifies whether permissions are aggregated to the admin ClusterRole
212
aggregateToAdmin: true
213
## -- Extra environment variables to add to container.
214
extraEnv: []
215
## -- Map of extra arguments to pass to container.
216
extraArgs: {}
217
## -- Extra volumes to pass to pod.
218
extraVolumes: []
219
## -- Extra Kubernetes objects to deploy with the helm chart
220
extraObjects: []
221
## -- Extra volumes to mount to the container.
222
extraVolumeMounts: []
223
## -- Extra init containers to add to the pod.
224
extraInitContainers: []
225
## -- Extra containers to add to the pod.
226
extraContainers: []
227
# -- Annotations to add to Deployment
228
deploymentAnnotations: {}
229
# -- Set deployment strategy
230
strategy: {}
231
# -- Annotations to add to Pod
232
podAnnotations: {}
233
podLabels: {}
234
podSecurityContext:
235
enabled: true
236
# fsGroup: 2000
237
securityContext:
238
allowPrivilegeEscalation: false
239
capabilities:
240
drop:
241
- ALL
242
enabled: true
243
readOnlyRootFilesystem: true
244
runAsNonRoot: true
245
runAsUser: 1000
246
seccompProfile:
247
type: RuntimeDefault
248
resources: {}
249
# requests:
250
# cpu: 10m
251
# memory: 32Mi
252
253
serviceMonitor:
254
# -- Specifies whether to create a ServiceMonitor resource for collecting Prometheus metrics
255
enabled: false
256
# -- How should we react to missing CRD "`monitoring.coreos.com/v1/ServiceMonitor`"
257
#
258
# Possible values:
259
# - `skipIfMissing`: Only render ServiceMonitor resources if CRD is present, skip if missing.
260
# - `failIfMissing`: Fail Helm install if CRD is not present.
261
# - `alwaysRender` : Always render ServiceMonitor resources, do not check for CRD.
262
263
# @schema
264
# enum:
265
# - skipIfMissing
266
# - failIfMissing
267
# - alwaysRender
268
# @schema
269
renderMode: skipIfMissing # @schema enum: [skipIfMissing, failIfMissing, alwaysRender]
270
# -- namespace where you want to install ServiceMonitors
271
namespace: ""
272
# -- Additional labels
273
additionalLabels: {}
274
# -- Interval to scrape metrics
275
interval: 30s
276
# -- Timeout if metrics can't be retrieved in given time interval
277
scrapeTimeout: 25s
278
# -- Let prometheus add an exported_ prefix to conflicting labels
279
honorLabels: false
280
# -- Metric relabel configs to apply to samples before ingestion. [Metric Relabeling](https://prometheus.io/docs/prometheus/latest/configuration/configuration/#metric_relabel_configs)
281
metricRelabelings: []
282
# - action: replace
283
# regex: (.*)
284
# replacement: $1
285
# sourceLabels:
286
# - exported_namespace
287
# targetLabel: namespace
288
289
# -- Relabel configs to apply to samples before ingestion. [Relabeling](https://prometheus.io/docs/prometheus/latest/configuration/configuration/#relabel_config)
290
relabelings: []
291
# - sourceLabels: [__meta_kubernetes_pod_node_name]
292
# separator: ;
293
# regex: ^(.*)$
294
# targetLabel: nodename
295
# replacement: $1
296
# action: replace
297
metrics:
298
listen:
299
port: 8080
300
auth:
301
# -- Enable Kubernetes RBAC-based authentication for metrics endpoint. Requires metrics.listen.secure to be true. Default value is false.
302
enabled: false
303
secure:
304
enabled: false
305
# -- if those are not set or invalid, self-signed certs will be generated
306
# -- TLS cert directory path
307
certDir: /etc/tls
308
# -- TLS cert file path
309
certFile: /etc/tls/tls.crt
310
# -- TLS key file path
311
keyFile: /etc/tls/tls.key
312
service:
313
# -- Enable if you use another monitoring tool than Prometheus to scrape the metrics
314
enabled: false
315
# -- Metrics service port to scrape
316
port: 8080
317
# -- Additional service annotations
318
annotations: {}
319
grafanaDashboard:
320
# -- If true creates a Grafana dashboard.
321
enabled: false
322
# -- Namespace where the dashboard ConfigMap should be created.
323
# Resolution order: grafanaDashboard.namespace, then namespaceOverride, then the release namespace.
324
namespace: ""
325
# -- Label that ConfigMaps should have to be loaded as dashboards.
326
sidecarLabel: "grafana_dashboard"
327
# -- Label value that ConfigMaps should have to be loaded as dashboards.
328
sidecarLabelValue: "1"
329
# -- Annotations that ConfigMaps can have to get configured in Grafana,
330
# See: sidecar.dashboards.folderAnnotation for specifying the dashboard folder.
331
# https://github.com/grafana/helm-charts/tree/main/charts/grafana
332
annotations: {}
333
# -- Extra labels to add to the Grafana dashboard ConfigMap.
334
extraLabels: {}
335
livenessProbe:
336
# -- Enabled determines if the liveness probe should be used or not. By default it's disabled.
337
enabled: false
338
# -- The body of the liveness probe settings.
339
spec:
340
# -- Bind address for the health server used by both liveness and readiness probes (--live-addr flag).
341
address: ""
342
# -- Port for the health server used by both liveness and readiness probes (--live-addr flag).
343
port: 8082
344
# -- Specify the maximum amount of time to wait for a probe to respond before considering it fails.
345
timeoutSeconds: 5
346
# -- Number of consecutive probe failures that should occur before considering the probe as failed.
347
failureThreshold: 5
348
# -- Period in seconds for K8s to start performing probes.
349
periodSeconds: 10
350
# -- Number of successful probes to mark probe successful.
351
successThreshold: 1
352
# -- Delay in seconds for the container to start before performing the initial probe.
353
initialDelaySeconds: 10
354
# -- Handler for liveness probe.
355
httpGet:
356
# -- Set this value to 'live' (for named port) or an an integer for liveness probes.
357
# @schema type: [string, integer]
358
port: live
359
# -- Path for liveness probe.
360
path: /healthz
361
readinessProbe:
362
# -- Determines whether the readiness probe is enabled. Disabled by default. Enabling this will auto-start the health server (--live-addr) even if livenessProbe is disabled. Health server address/port are configured via livenessProbe.spec.address and livenessProbe.spec.port.
363
enabled: false
364
# -- The body of the readiness probe settings (standard Kubernetes probe spec).
365
spec:
366
# -- Specify the maximum amount of time to wait for a probe to respond before considering it fails.
367
timeoutSeconds: 5
368
# -- Number of consecutive probe failures that should occur before considering the probe as failed.
369
failureThreshold: 3
370
# -- Period in seconds for K8s to start performing probes.
371
periodSeconds: 10
372
# -- Number of successful probes to mark probe successful.
373
successThreshold: 1
374
# -- Delay in seconds for the container to start before performing the initial probe.
375
initialDelaySeconds: 10
376
# -- Handler for readiness probe.
377
httpGet:
378
# -- Set this value to 'live' (for named port) or an integer for readiness probes.
379
# @schema type: [string, integer]
380
port: live
381
# -- Path for readiness probe.
382
path: /readyz
383
nodeSelector: {}
384
tolerations: []
385
topologySpreadConstraints: []
386
affinity: {}
387
# -- Pod priority class name.
388
priorityClassName: ""
389
# -- Pod scheduler name.
390
schedulerName: ""
391
# -- Pod runtime class name.
392
runtimeClassName: ""
393
# -- Pod disruption budget - for more details see https://kubernetes.io/docs/concepts/workloads/pods/disruptions/
394
podDisruptionBudget:
395
enabled: false
396
minAvailable: 1 # @schema type:[integer, string]
397
nameOverride: ""
398
# maxUnavailable: "50%"
399
# -- Run the controller on the host network
400
hostNetwork: false
401
# -- (bool) Specifies if controller pod should use hostUsers or not. If hostNetwork is true, hostUsers should be too. Only available in Kubernetes ≥ 1.33.
402
# @schema type: [boolean, null]
403
hostUsers:
404
# -- Setup a networkPolicy for external-secrets
405
networkPolicy:
406
# -- Specifies whether the networkPolicy should be created.
407
enabled: false
408
# -- The ingress traffic
409
# Should match the health and (optionally) metrics port
410
ingress:
411
- ports:
412
- protocol: TCP
413
# @schema type: [string, integer]
414
port: 8080 # metrics port
415
- protocol: TCP
416
# @schema type: [string, integer]
417
port: 8082 # health port
418
# -- The egress traffic
419
# The minimum egress ports required to function are:
420
# DNS (53/udp, 53/tcp)
421
# API server (80/tcp, 443/tcp, or 6443/tcp)
422
# You will need to customize this value to meet your needs
423
egress: []
424
webhook:
425
# -- Annotations to place on validating webhook configuration.
426
annotations: {}
427
# -- Specifies whether a webhook deployment be created. If set to false, crds.conversion.enabled should also be set to false otherwise the kubeapi will be hammered because the conversion is looking for a webhook endpoint.
428
create: true
429
# -- Specifies the time to check if the cert is valid
430
certCheckInterval: "5m"
431
# -- Specifies the lookaheadInterval for certificate validity
432
lookaheadInterval: ""
433
replicaCount: 1
434
# -- Specifies Log Params to the Webhook
435
log:
436
level: info
437
timeEncoding: epoch
438
# -- Specifies the amount of historic ReplicaSets k8s should keep (see https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#clean-up-policy)
439
revisionHistoryLimit: 10
440
certDir: /tmp/certs
441
# -- Webhook-specific TLS security profile overrides.
442
# When set, these override the global tls.* values for the webhook deployment.
443
tls:
444
# -- Minimum TLS version supported (e.g. "1.2" or "1.3"). If empty, the global tls.minVersion is used.
445
# +docs:property
446
minVersion: ""
447
# -- Comma-separated list of TLS cipher suites. If empty, the global tls.ciphers is used.
448
# +docs:property
449
ciphers: ""
450
# -- Ordered list of TLS key exchange curves. If empty, the global tls.curvePreferences is used.
451
# +docs:property
452
curvePreferences: []
453
# -- Specifies whether validating webhooks should be created with failurePolicy: Fail or Ignore
454
failurePolicy: Fail
455
# -- Specifies if webhook pod should use hostNetwork or not.
456
hostNetwork: false
457
# -- (bool) Specifies if webhook pod should use hostUsers or not. If hostNetwork is true, hostUsers should be too. Only available in Kubernetes ≥ 1.33.
458
# @schema type: [boolean, null]
459
hostUsers:
460
# -- Setup a networkPolicy for external-secrets webhook
461
networkPolicy:
462
# -- Specifies whether the networkPolicy should be created.
463
enabled: false
464
# -- The ingress traffic
465
# Should match the webhook, health, and (optionally) metrics port
466
ingress:
467
- ports:
468
- protocol: TCP
469
# @schema type: [string, integer]
470
port: 8080 # metrics port
471
- protocol: TCP
472
# @schema type: [string, integer]
473
port: 8081 # health port
474
- protocol: TCP
475
# @schema type: [string, integer]
476
port: 10250 # webhook port
477
# -- The egress traffic
478
# The minimum egress ports required to function are:
479
# DNS (53/udp, 53/tcp)
480
# API server (80/tcp, 443/tcp, or 6443/tcp)
481
# You will need to customize this value to meet your needs
482
egress: []
483
image:
484
repository: cgr.dev/chainguard-private/external-secrets-fips
485
pullPolicy: IfNotPresent
486
# -- The image tag to use. The default is the chart appVersion.
487
tag: 2.11.0-r1@sha256:f59cf8e863c5177345b463b38bb33a72a0efce4c54b967563ea5b09e423028ee
488
# -- The flavour of tag you want to use
489
flavour: ""
490
imagePullSecrets: []
491
# -- The port the webhook will listen to
492
port: 10250
493
serviceAccount:
494
# -- Specifies whether a service account should be created.
495
create: true
496
# -- Automounts the service account token in all containers of the pod
497
automount: true
498
# -- Annotations to add to the service account.
499
annotations: {}
500
# -- Extra Labels to add to the service account.
501
extraLabels: {}
502
# -- The name of the service account to use.
503
# If not set and create is true, a name is generated using the fullname template.
504
name: ""
505
nodeSelector: {}
506
# -- Specifies `hostAliases` to webhook deployment
507
hostAliases: []
508
certManager:
509
# -- Enabling cert-manager support will disable the built in secret and
510
# switch to using cert-manager (installed separately) to automatically issue
511
# and renew the webhook certificate. This chart does not install
512
# cert-manager for you, See https://cert-manager.io/docs/
513
enabled: false
514
# -- Automatically add the cert-manager.io/inject-ca-from annotation to the
515
# webhooks and CRDs. As long as you have the cert-manager CA Injector
516
# enabled, this will automatically setup your webhook's CA to the one used
517
# by cert-manager. See https://cert-manager.io/docs/concepts/ca-injector
518
addInjectorAnnotations: true
519
cert:
520
# -- Create a certificate resource within this chart. See
521
# https://cert-manager.io/docs/usage/certificate/
522
create: true
523
# -- For the Certificate created by this chart, setup the issuer. See
524
# https://cert-manager.io/docs/reference/api-docs/#cert-manager.io/v1.IssuerSpec
525
issuerRef:
526
group: cert-manager.io
527
kind: "Issuer"
528
name: "my-issuer"
529
# -- Set the requested duration (i.e. lifetime) of the Certificate. See
530
# https://cert-manager.io/docs/reference/api-docs/#cert-manager.io/v1.CertificateSpec
531
# One year by default.
532
duration: "8760h0m0s"
533
# -- Set the revisionHistoryLimit on the Certificate. See
534
# https://cert-manager.io/docs/reference/api-docs/#cert-manager.io/v1.CertificateSpec
535
# Defaults to 0 (ignored).
536
revisionHistoryLimit: 0
537
# -- How long before the currently issued certificate’s expiry
538
# cert-manager should renew the certificate. See
539
# https://cert-manager.io/docs/reference/api-docs/#cert-manager.io/v1.CertificateSpec
540
# Note that renewBefore should be greater than .webhook.lookaheadInterval
541
# since the webhook will check this far in advance that the certificate is
542
# valid.
543
renewBefore: ""
544
# -- Specific settings on the privateKey and its generation
545
privateKey: {}
546
# rotationPolicy: Always
547
# algorithm: RSA
548
# size: 2048
549
# -- Specific settings on the signatureAlgorithm used on the cert.
550
# signatureAlgorithm is only valid for cert-manager v1.18.0+
551
signatureAlgorithm: ""
552
# -- Add extra annotations to the Certificate resource.
553
annotations: {}
554
tolerations: []
555
topologySpreadConstraints: []
556
affinity: {}
557
# -- Set deployment strategy
558
strategy: {}
559
# -- Pod priority class name.
560
priorityClassName: ""
561
# -- Pod scheduler name.
562
schedulerName: ""
563
# -- Pod runtime class name.
564
runtimeClassName: ""
565
# -- Pod disruption budget - for more details see https://kubernetes.io/docs/concepts/workloads/pods/disruptions/
566
podDisruptionBudget:
567
enabled: false
568
minAvailable: 1 # @schema type:[integer, string]
569
nameOverride: ""
570
# maxUnavailable: "50%"
571
metrics:
572
listen:
573
port: 8080
574
auth:
575
# -- Enable Kubernetes RBAC-based authentication for webhook's metrics endpoint. Requires webhook.metrics.listen.secure to be true. Default value is false.
576
enabled: false
577
secure:
578
enabled: false
579
# -- if those are not set or invalid, self-signed certs will be generated
580
# -- TLS cert directory path
581
certDir: /etc/tls
582
# -- TLS cert file path
583
certFile: /etc/tls/tls.crt
584
# -- TLS key file path
585
keyFile: /etc/tls/tls.key
586
service:
587
# -- Enable if you use another monitoring tool than Prometheus to scrape the metrics
588
enabled: false
589
# -- Metrics service port to scrape
590
port: 8080
591
# -- Additional service annotations
592
annotations: {}
593
livenessProbe:
594
enabled: false
595
# -- Set this value to 'live' (for named port) or an integer for liveness probes.
596
# @schema type: [string, integer]
597
port: 8081
598
timeoutSeconds: 5
599
failureThreshold: 5
600
periodSeconds: 10
601
successThreshold: 1
602
initialDelaySeconds: 10
603
readinessProbe:
604
enabled: true
605
address: ""
606
# -- Set this value to 'ready' (for named port) or an integer for readiness probes.
607
# @schema type: [string, integer]
608
port: 8081
609
timeoutSeconds: 5
610
failureThreshold: 3
611
periodSeconds: 5
612
successThreshold: 1
613
initialDelaySeconds: 20
614
startupProbe:
615
# -- Enabled determines if the startup probe should be used or not. By default it's disabled.
616
enabled: false
617
# -- Number of seconds after the container has started before the startup probe is initiated.
618
initialDelaySeconds: 10
619
# -- How often (in seconds) to perform the startup probe.
620
periodSeconds: 10
621
# -- Number of consecutive failures before the container is restarted. The startup window is initialDelaySeconds + failureThreshold * periodSeconds.
622
failureThreshold: 30
623
## -- Extra environment variables to add to container.
624
extraEnv: []
625
## -- Map of extra arguments to pass to container.
626
extraArgs: {}
627
## -- Extra init containers to add to the pod.
628
extraInitContainers: []
629
## -- Extra volumes to pass to pod.
630
extraVolumes: []
631
## -- Extra volumes to mount to the container.
632
extraVolumeMounts: []
633
# -- Annotations to add to Secret
634
secretAnnotations: {}
635
# -- Annotations to add to Deployment
636
deploymentAnnotations: {}
637
# -- Annotations to add to Pod
638
podAnnotations: {}
639
podLabels: {}
640
podSecurityContext:
641
enabled: true
642
# fsGroup: 2000
643
securityContext:
644
allowPrivilegeEscalation: false
645
capabilities:
646
drop:
647
- ALL
648
enabled: true
649
readOnlyRootFilesystem: true
650
runAsNonRoot: true
651
runAsUser: 1000
652
seccompProfile:
653
type: RuntimeDefault
654
resources: {}
655
# requests:
656
# cpu: 10m
657
# memory: 32Mi
658
659
# -- Manage the service through which the webhook is reached.
660
service:
661
# -- Whether the service object should be enabled or not (it is expected to exist).
662
enabled: true
663
# -- Custom annotations for the webhook service.
664
annotations: {}
665
# -- Custom labels for the webhook service.
666
labels: {}
667
# -- The service type of the webhook service.
668
type: ClusterIP
669
# -- If the webhook service type is LoadBalancer, you can assign a specific load balancer IP here.
670
# Check the documentation of your load balancer provider to see if/how this should be used.
671
loadBalancerIP: ""
672
certController:
673
# -- Specifies whether a certificate controller deployment be created.
674
create: true
675
requeueInterval: "5m"
676
replicaCount: 1
677
# -- Restrict the cert controller's informer cache to CustomResourceDefinitions and
678
# ValidatingWebhookConfigurations carrying the `external-secrets.io/component` label.
679
# Disable this only if the CRDs it manages were installed without that label.
680
enablePartialCache: true
681
# -- Specifies Log Params to the Certificate Controller
682
log:
683
level: info
684
timeEncoding: epoch
685
# -- Specifies the amount of historic ReplicaSets k8s should keep (see https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#clean-up-policy)
686
revisionHistoryLimit: 10
687
# -- CertController-specific TLS security profile overrides.
688
# When set, these override the global tls.* values for the cert-controller deployment.
689
tls:
690
# -- Minimum TLS version supported (e.g. "1.2" or "1.3"). If empty, the global tls.minVersion is used.
691
# +docs:property
692
minVersion: ""
693
# -- Comma-separated list of TLS cipher suites. If empty, the global tls.ciphers is used.
694
# +docs:property
695
ciphers: ""
696
# -- Ordered list of TLS key exchange curves. If empty, the global tls.curvePreferences is used.
697
# +docs:property
698
curvePreferences: []
699
image:
700
repository: cgr.dev/chainguard-private/external-secrets-fips
701
pullPolicy: IfNotPresent
702
tag: 2.11.0-r1@sha256:f59cf8e863c5177345b463b38bb33a72a0efce4c54b967563ea5b09e423028ee
703
flavour: ""
704
imagePullSecrets: []
705
rbac:
706
# -- Specifies whether role and rolebinding resources should be created.
707
create: true
708
serviceAccount:
709
# -- Specifies whether a service account should be created.
710
create: true
711
# -- Automounts the service account token in all containers of the pod
712
automount: true
713
# -- Annotations to add to the service account.
714
annotations: {}
715
# -- Extra Labels to add to the service account.
716
extraLabels: {}
717
# -- The name of the service account to use.
718
# If not set and create is true, a name is generated using the fullname template.
719
name: ""
720
nodeSelector: {}
721
# -- Specifies `hostAliases` to cert-controller deployment
722
hostAliases: []
723
tolerations: []
724
topologySpreadConstraints: []
725
affinity: {}
726
# -- Set deployment strategy
727
strategy: {}
728
# -- Run the certController on the host network
729
hostNetwork: false
730
# -- (bool) Specifies if certController pod should use hostUsers or not. If hostNetwork is true, hostUsers should be too. Only available in Kubernetes ≥ 1.33.
731
# @schema type: [boolean, null]
732
hostUsers:
733
# -- Setup a networkPolicy for external-secrets certController
734
networkPolicy:
735
# -- Specifies whether the networkPolicy should be created.
736
enabled: false
737
# -- The ingress traffic
738
# Should match the health and (optionally) metrics port
739
ingress:
740
- ports:
741
- protocol: TCP
742
# @schema type: [string, integer]
743
port: 8080 # metrics port
744
- protocol: TCP
745
# @schema type: [string, integer]
746
port: 8081 # health port
747
# -- The egress traffic
748
# The minimum egress ports required to function are:
749
# DNS (53/udp, 53/tcp)
750
# API server (80/tcp, 443/tcp, or 6443/tcp)
751
# You will need to customize this value to meet your needs
752
egress: []
753
# -- Pod priority class name.
754
priorityClassName: ""
755
# -- Pod scheduler name.
756
schedulerName: ""
757
# -- Pod runtime class name.
758
runtimeClassName: ""
759
# -- Pod disruption budget - for more details see https://kubernetes.io/docs/concepts/workloads/pods/disruptions/
760
podDisruptionBudget:
761
enabled: false
762
minAvailable: 1 # @schema type:[integer, string]
763
nameOverride: ""
764
# maxUnavailable: "50%"
765
metrics:
766
listen:
767
port: 8080
768
auth:
769
# -- Enable Kubernetes RBAC-based authentication for certController's metrics endpoint. Requires certController.metrics.listen.secure to be true. Default value is false.
770
enabled: false
771
secure:
772
enabled: false
773
# -- if those are not set or invalid, self-signed certs will be generated
774
# -- TLS cert directory path
775
certDir: /etc/tls
776
# -- TLS cert file path
777
certFile: /etc/tls/tls.crt
778
# -- TLS key file path
779
keyFile: /etc/tls/tls.key
780
service:
781
# -- Enable if you use another monitoring tool than Prometheus to scrape the metrics
782
enabled: false
783
# -- Metrics service port to scrape
784
port: 8080
785
# -- Additional service annotations
786
annotations: {}
787
livenessProbe:
788
enabled: false
789
# -- Set this value to 'live' (for named port) or an integer for liveness probes.
790
# @schema type: [string, integer]
791
port: 8081
792
timeoutSeconds: 5
793
failureThreshold: 5
794
periodSeconds: 10
795
successThreshold: 1
796
initialDelaySeconds: 10
797
readinessProbe:
798
enabled: true
799
address: ""
800
# -- Set this value to 'ready' (for named port) or an integer for readiness probes.
801
# @schema type: [string, integer]
802
port: 8081
803
timeoutSeconds: 5
804
failureThreshold: 3
805
periodSeconds: 5
806
successThreshold: 1
807
initialDelaySeconds: 20
808
startupProbe:
809
# -- Enabled determines if the startup probe should be used or not. By default it's disabled.
810
enabled: false
811
# -- Number of seconds after the container has started before the startup probe is initiated.
812
initialDelaySeconds: 10
813
# -- How often (in seconds) to perform the startup probe.
814
periodSeconds: 10
815
# -- Number of consecutive failures before the container is restarted. The startup window is initialDelaySeconds + failureThreshold * periodSeconds.
816
failureThreshold: 30
817
## -- Extra environment variables to add to container.
818
extraEnv: []
819
## -- Map of extra arguments to pass to container.
820
extraArgs: {}
821
## -- Extra init containers to add to the pod.
822
extraInitContainers: []
823
## -- Extra volumes to pass to pod.
824
extraVolumes: []
825
## -- Extra volumes to mount to the container.
826
extraVolumeMounts: []
827
# -- Annotations to add to Deployment
828
deploymentAnnotations: {}
829
# -- Annotations to add to Pod
830
podAnnotations: {}
831
podLabels: {}
832
podSecurityContext:
833
enabled: true
834
# fsGroup: 2000
835
securityContext:
836
allowPrivilegeEscalation: false
837
capabilities:
838
drop:
839
- ALL
840
enabled: true
841
readOnlyRootFilesystem: true
842
runAsNonRoot: true
843
runAsUser: 1000
844
seccompProfile:
845
type: RuntimeDefault
846
resources: {}
847
# requests:
848
# cpu: 10m
849
# memory: 32Mi
850
# -- Specifies `dnsPolicy` to deployment
851
dnsPolicy: ClusterFirst
852
# -- Specifies `dnsOptions` to deployment
853
dnsConfig: {}
854
# -- Specifies `hostAliases` to deployment
855
hostAliases: []
856
# -- Any extra pod spec on the deployment
857
podSpecExtra: {}
858

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.