12 allowPrivilegeEscalation: false
29 initialDelaySeconds: 10
38 initialDelaySeconds: 10
39 # Set this to true to enable the standard go pprof endpoints on port 6060 (https://pkg.go.dev/net/http/pprof)
40 # Should only be used for debugging purposes
41 pprofEndpointsEnabled: false
43 repository: cgr.dev/chainguard-private/opensearch-k8s-operator-fips
44 ## tag default uses appVersion from Chart.yaml, to override specify tag tag: "v1.1"
45 tag: 3.0.0-r1@sha256:dc3afa280e952d7c77ddbdc0f368df460f84a5dc56e64eac8ba65d5850d14512
47 ## Optional array of imagePullSecrets containing private registry credentials
51 dnsBase: cluster.local
52 # Log level of the operator. Possible values: debug, info, warn, error
54 # If a watchNamespace is specified, the manager's cache will be restricted to
55 # watch objects in the desired namespace. Defaults is to watch all namespaces.
56 # To watch multiple namespaces, separate them by commas, or define it as a list.
58 # watchNamespace: ns1,ns2
59 # watchNamespace: [ns1, ns2]
61 # -- Global default max concurrent reconciles for all controllers.
62 maxConcurrentReconciles: 1
63 # -- Per-controller overrides (controller name -> max concurrent reconciles). Example: `{opensearchcluster: 4}`.
64 maxConcurrentReconcilesPerController: {}
65 metricsBindAddress: 127.0.0.1:8080
66# Install the Custom Resource Definitions with Helm
69 # -- Enable support for the deprecated `opensearch.opster.io/v1` API group. When false, deprecated CRDs, webhooks, RBAC rules, and manager watches are skipped.
72 # Specifies whether a service account should be created
74 # The name of the service account to use.
75 # If not set and create is true, a name is generated using the fullname template
77# kubeRbacProxy has been replaced with controller-runtime's built-in
78# WithAuthenticationAndAuthorization for metrics endpoint protection.
79# This provides equivalent security functionality without external dependencies.
84## If this is set to true, RoleBindings will be used instead of ClusterRoleBindings, in order to restrict permissions
85## to the namespace where the operator and OpenSearch cluster are deployed. In that case, specify the namespace in the
86## manager.watchNamespace field.
88## When useRoleBindings is true:
89## - Manager and proxy roles will be created as namespace-scoped Roles instead of ClusterRoles
90## - The metrics ClusterRole will NOT be created, as nonResourceURLs (like /metrics) cannot be used in namespace-scoped Roles
91## - The operator's /metrics endpoint is exposed via kube-apiserver and requires authentication (TokenReviews) and
92## authorization (SubjectAccessReviews). If you need to access metrics with monitoring tools, you must create the
93## appropriate ClusterRole and ClusterRoleBinding manually
95## If false (default), ClusterRoleBindings will be used and the metrics ClusterRole will be created
97# Webhook configuration
99 # Enable validation webhooks
101 # Port exposed by the webhook server container
103 # Failure policy for webhooks. Options: Fail, Ignore
105 # Secret name for webhook TLS certificates (used when certManager.enabled is false)
106 # Defaults to: <release-name>-opensearch-operator-webhook-server-cert
107 # If certManager is disabled, you must manually create this secret with:
108 # - tls.crt: The TLS certificate
109 # - tls.key: The TLS private key
110 # - ca.crt: The CA certificate (optional, for client verification)
111 # The certificate should be valid for:
112 # - <release-name>-opensearch-operator-webhook-service.<namespace>.svc
113 # - <release-name>-opensearch-operator-webhook-service.<namespace>.svc.cluster.local
115 # Cert-manager configuration for webhook certificates
117 # Enable cert-manager for automatic certificate management
118 # If set to false, you must manually create the TLS secret (see webhook.secretName above)