Skip to content

Certs operator values#

Values under certs-operator configure the operator that issues the TLS certificates of the Hopsworks services and removes them on uninstall.

Generated from the Hopsworks Helm chart 5.2.0-alpha-1791549041 (Hopsworks 5.2.0).

Deployed when global._hopsworks.full_platform is true.

General#

Defaults as YAML
certs-operator:
  fullnameOverride: null
  gracefulCertTeardown:
    enabled: true
    timeoutSeconds: 120
    ttlSecondsAfterFinished: null
  hopsworkslib: {}
  nameOverride: null
  nodeSelector: {}
  serviceAccount:
    create: false
    name: ''
  tolerations: []
  topologySpreadConstraint: {}
certs-operator #
Type object, default {}. override certs-operator values
certs-operator.fullnameOverride #
Type string, default nil. override app fully qualified name
certs-operator.gracefulCertTeardown #
Type object, default {"enabled":true,"timeoutSeconds":120,"ttlSecondsAfterFinished":null}. ordered, narrow-RBAC teardown of HopsworksCerts on uninstall: a pre-delete hook deletes the certs while the certs-operator is still alive (so it releases its own finalizers), and a post-delete hook force-clears any finalizers left behind on runtimes that drop pre-delete hooks (ArgoCD < 3.3). Independent of the wipe job.
certs-operator.gracefulCertTeardown.enabled #
Type bool, default true. enable the ordered HopsworksCert teardown hooks on uninstall
certs-operator.gracefulCertTeardown.timeoutSeconds #
Type int, default 120. seconds the pre-delete drain waits for the operator to finalize the certs before deferring to the post-delete backstop
certs-operator.gracefulCertTeardown.ttlSecondsAfterFinished #
Type string, default nil. ttlSecondsAfterFinished for the teardown Jobs; null falls through to the global default
certs-operator.hopsworkslib #
Type object, default {}. override hopsworkslib values
certs-operator.nameOverride #
Type string, default nil. override app chart name
certs-operator.nodeSelector #
Type object, default {}. node selector configuration
certs-operator.serviceAccount.create #
Type bool, default false.
certs-operator.serviceAccount.name #
Type string, default "".
certs-operator.tolerations #
Type list, default [].
certs-operator.topologySpreadConstraint #
Type object, default {}. The default topology spread constraint. If not defined the global topology spread constraint would be used instead.

controller#

Defaults as YAML
certs-operator:
  controller:
    manager:
      resources:
        limits:
          cpu: 500m
          memory: 128Mi
        requests:
          cpu: 10m
          memory: 64Mi
      watchNamespaces: null
    serviceAccount:
      annotations: {}
certs-operator.controller.manager.resources.limits.cpu #
Type string, default "500m".
certs-operator.controller.manager.resources.limits.memory #
Type string, default "128Mi".
certs-operator.controller.manager.resources.requests.cpu #
Type string, default "10m".
certs-operator.controller.manager.resources.requests.memory #
Type string, default "64Mi".
certs-operator.controller.manager.watchNamespaces #
Type string, default nil. Comma separated list of Namespaces to restrict certs-operator to watch for. If not set it will watch all Namespaces.
certs-operator.controller.serviceAccount.annotations #
Type object, default {}. service account annotations

dependencies#

Defaults as YAML
certs-operator:
  dependencies:
    ca:
      apiKeySecretKey: key
      apiKeySecretName: hopsworks-api-key-auth
      authMethod: api_key
      consulServiceName: glassfish
      consulServiceTag: ca
      httpScheme: https
      httpTimeout: 60s
      password: adminpw
      port: 8182
      user: agent@hops.io
certs-operator.dependencies.ca.apiKeySecretKey #
Type string, default "key".
certs-operator.dependencies.ca.apiKeySecretName #
Type string, default "hopsworks-api-key-auth".
certs-operator.dependencies.ca.authMethod #
Type string, default "api_key".
certs-operator.dependencies.ca.consulServiceName #
Type string, default "glassfish".
certs-operator.dependencies.ca.consulServiceTag #
Type string, default "ca".
certs-operator.dependencies.ca.httpScheme #
Type string, default "https".
certs-operator.dependencies.ca.httpTimeout #
Type string, default "60s".
certs-operator.dependencies.ca.password #
Type string, default "adminpw".
certs-operator.dependencies.ca.port #
Type int, default 8182.
certs-operator.dependencies.ca.user #
Type string, default "agent@hops.io".