8 repository: chainguard-private/curl
10 version: sha256:096d8d5a69a38d0cf89c6826a3f31f30cb598cd770a58e12651963d83ced810c
11 imagePullPolicy: IfNotPresent
12initContainerResources: {}
26 repository: chainguard-private/redis
27 pullPolicy: IfNotPresent
28 # -- 6.2.17-alpine3.21
29 version: sha256:372045e490a45af5f3b0e37f281a018a333191070bb3e8973b82401f001d8183
32 initialDelaySeconds: 5
42 - test "$(redis-cli -h 127.0.0.1 ping)" = "PONG"
63 repository: chainguard-private/cloud-sql-proxy
64 # -- crane digest gcr.io/cloud-sql-connectors/cloud-sql-proxy:2.19.0-alpine
65 version: sha256:3810907a3b87c6ea1c8adc1213619f37beed38c9e9acad9de20d4cc33482668e
71 allowPrivilegeEscalation: false
72 readOnlyRootFilesystem: true
89 repository: chainguard-private/mariadb
90 pullPolicy: IfNotPresent
91 version: sha256:d07c8e19b0d70dde7d345d369ae1c8c671c665ac3fdb1cd148f42e93a12f3710
99 repository: chainguard-private/rekor-server
100 pullPolicy: IfNotPresent
101 # crane digest ghcr.io/sigstore/rekor/rekor-server:v1.5.1
102 version: latest@sha256:8f9c4c9a0b5fce79b98967e4ce36bf29e0ed46fc519f5c3e6942ede01420fed0
103 # -- KMS type for signing key (possible values: "" / "none", "aws")
105 # -- AWS region if using AWS KMS for signing key
106 awsKmsRegion: us-east-1
107 # -- kubernetes secret name containing IAM credentials for use with AWS KMS
108 awsKmsCredentialsSecretName: aws-kms-credentials
128 staticGlobalIP: lb-ext-ip
129 frontendConfigSpec: # https://cloud.google.com/kubernetes-engine/docs/how-to/ingress-configuration#configuring_ingress_features_through_frontendconfig_parameters
130 sslPolicy: rekor-ssl-policy
133 backendConfigSpec: # https://cloud.google.com/kubernetes-engine/docs/how-to/ingress-configuration#configuring_ingress_features_through_backendconfig_parameters
135 name: rekor-security-policy
151 initialDelaySeconds: 10
161 filename: sharding-config.yaml
164 initialDelaySeconds: 30
182 bucket: file:///var/run/attestations
188 mountPath: /var/lib/mysql
194 prometheus.io/scrape: "true"
195 prometheus.io/path: /metrics
196 prometheus.io/port: "2112"
215 repository: chainguard-private/sigstore-scaffolding-trillian-createtree
216 pullPolicy: IfNotPresent
218 version: sha256:833764227b2582b49f3fe771f2353e80600fc242c599ef98fef58e745dfc9221
219 ttlSecondsAfterFinished: 3600
232# Configure backfillredis to repair indices that were not inserted into Redis.
238 repository: chainguard-private/rekor-backfill-index
239 pullPolicy: IfNotPresent
241 version: sha256:111b729951e83d29b54b6861737878818afbba8d565f56990afdd4fb5343433c
242 ttlSecondsAfterFinished: 3600
246 rekorAddress: rekor.rekor-system.svc
253# Configure Trillian dependency
257 name: trillian-system
259 forceNamespace: trillian-system
260 fullnameOverride: trillian
263 name: trillian-logserver
264 fullnameOverride: trillian-logserver
268 name: trillian-logsigner
269 fullnameOverride: trillian-logsigner
271 fullnameOverride: trillian-mysql
272# Force namespace of namespaced resources