Certs operator values#
Values under certs-operator configure the operator that issues the TLS certificates of the Hopsworks services and removes them on uninstall.
Generated from the Hopsworks Helm chart 5.2.0-alpha-1791549041 (Hopsworks 5.2.0).
Deployed when global._hopsworks.full_platform is true.
General#
Defaults as YAML
certs-operator#- Type
object, default{}. override certs-operator values certs-operator.fullnameOverride#- Type
string, defaultnil. override app fully qualified name certs-operator.gracefulCertTeardown#- Type
object, default{"enabled":true,"timeoutSeconds":120,"ttlSecondsAfterFinished":null}. ordered, narrow-RBAC teardown of HopsworksCerts on uninstall: a pre-delete hook deletes the certs while the certs-operator is still alive (so it releases its own finalizers), and a post-delete hook force-clears any finalizers left behind on runtimes that drop pre-delete hooks (ArgoCD < 3.3). Independent of thewipejob. certs-operator.gracefulCertTeardown.enabled#- Type
bool, defaulttrue. enable the ordered HopsworksCert teardown hooks on uninstall certs-operator.gracefulCertTeardown.timeoutSeconds#- Type
int, default120. seconds the pre-delete drain waits for the operator to finalize the certs before deferring to the post-delete backstop certs-operator.gracefulCertTeardown.ttlSecondsAfterFinished#- Type
string, defaultnil. ttlSecondsAfterFinished for the teardown Jobs; null falls through to the global default certs-operator.hopsworkslib#- Type
object, default{}. override hopsworkslib values certs-operator.nameOverride#- Type
string, defaultnil. override app chart name certs-operator.nodeSelector#- Type
object, default{}. node selector configuration certs-operator.serviceAccount.create#- Type
bool, defaultfalse. certs-operator.serviceAccount.name#- Type
string, default"". certs-operator.tolerations#- Type
list, default[]. certs-operator.topologySpreadConstraint#- Type
object, default{}. The default topology spread constraint. If not defined the global topology spread constraint would be used instead.
controller#
Defaults as YAML
certs-operator.controller.manager.resources.limits.cpu#- Type
string, default"500m". certs-operator.controller.manager.resources.limits.memory#- Type
string, default"128Mi". certs-operator.controller.manager.resources.requests.cpu#- Type
string, default"10m". certs-operator.controller.manager.resources.requests.memory#- Type
string, default"64Mi". certs-operator.controller.manager.watchNamespaces#- Type
string, defaultnil. Comma separated list of Namespaces to restrict certs-operator to watch for. If not set it will watch all Namespaces. certs-operator.controller.serviceAccount.annotations#- Type
object, default{}. service account annotations
dependencies#
Defaults as YAML
certs-operator.dependencies.ca.apiKeySecretKey#- Type
string, default"key". certs-operator.dependencies.ca.apiKeySecretName#- Type
string, default"hopsworks-api-key-auth". certs-operator.dependencies.ca.authMethod#- Type
string, default"api_key". certs-operator.dependencies.ca.consulServiceName#- Type
string, default"glassfish". certs-operator.dependencies.ca.consulServiceTag#- Type
string, default"ca". certs-operator.dependencies.ca.httpScheme#- Type
string, default"https". certs-operator.dependencies.ca.httpTimeout#- Type
string, default"60s". certs-operator.dependencies.ca.password#- Type
string, default"adminpw". certs-operator.dependencies.ca.port#- Type
int, default8182. certs-operator.dependencies.ca.user#- Type
string, default"agent@hops.io".