diff --git a/charts/kaneo/README.md b/charts/kaneo/README.md index 12afc962f9..8b3da2317d 100644 --- a/charts/kaneo/README.md +++ b/charts/kaneo/README.md @@ -61,6 +61,8 @@ helm uninstall my-kaneo | `nameOverride` | String to partially override the fullname template (will maintain the release name) | `""` | | `fullnameOverride` | String to fully override the fullname template | `""` | | `replicaCount` | Number of replicas (ignored if autoscaling is enabled) | `1` | +| `enableServiceLinks` | Controls Pod's enableServiceLinks field | `false` | +| `topologySpreadConstraints` | Controls Pod's topologySpreadConstraints field | `[]` | ### Autoscaling parameters | Name | Description | Value | | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------ | ----------- | @@ -116,6 +118,7 @@ When CPU autoscaling is enabled, set `kaneo.resources.requests.cpu`; Kubernetes | `kaneo.env.database.external.existingSecret.name` | Name of the secret containing the database connection URI | `""` | | `kaneo.env.database.external.existingSecret.passwordKey` | Key in the secret whose value is a full PostgreSQL connection URI | `postgres_uri` | | `kaneo.extraEnv` | Additional Kubernetes EnvVar entries appended to the Kaneo container | `[]` | +| `kaneo.extraEnvFrom` | Additional Kubernetes EnvFromSource entries appended to the Kaneo container | `[]` | | `kaneo.resources` | Resource requests and limits for the Kaneo container (optional, disabled by default) | `{}` | | `podSecurityContext` | Security context applied at the Pod level | `{}` | | `securityContext` | Security context applied at the container level | `{}` | diff --git a/charts/kaneo/templates/deployment.yaml b/charts/kaneo/templates/deployment.yaml index ab427b7b31..7f7c71bad0 100644 --- a/charts/kaneo/templates/deployment.yaml +++ b/charts/kaneo/templates/deployment.yaml @@ -30,9 +30,14 @@ spec: {{- include "kaneo.selectorLabels" . | nindent 8 }} app.kubernetes.io/component: kaneo spec: + {{- with .Values.imagePullSecrets }} + imagePullSecrets: + {{- toYaml . | nindent 8 }} + {{- end }} serviceAccountName: {{ include "kaneo.serviceAccountName" . }} securityContext: {{- toYaml .Values.podSecurityContext | nindent 8 }} + enableServiceLinks: {{ default false .Values.enableServiceLinks }} containers: - name: kaneo securityContext: @@ -90,6 +95,10 @@ spec: {{- with .Values.kaneo.extraEnv }} {{- toYaml . | nindent 12 }} {{- end }} + {{- with .Values.kaneo.extraEnvFrom }} + envFrom: + {{- toYaml . | nindent 12 }} + {{- end }} livenessProbe: {{- toYaml .Values.kaneo.livenessProbe | nindent 12 }} readinessProbe: @@ -109,3 +118,7 @@ spec: tolerations: {{- toYaml . | nindent 8 }} {{- end }} + {{- with .Values.topologySpreadConstraints }} + topologySpreadConstraints: + {{- toYaml . | nindent 8 }} + {{- end }} diff --git a/charts/kaneo/values.yaml b/charts/kaneo/values.yaml index 7be9dab5e1..cb0e2a0f79 100644 --- a/charts/kaneo/values.yaml +++ b/charts/kaneo/values.yaml @@ -15,6 +15,9 @@ podSecurityContext: {} nodeSelector: {} tolerations: [] affinity: {} +topologySpreadConstraints: [] +imagePullSecrets: [] +enableServiceLinks: false # Service account configuration serviceAccount: create: true @@ -132,6 +135,10 @@ kaneo: # secretKeyRef: # name: oauth-secret # key: client-id + extraEnvFrom: [] + # extraEnvFrom: + # - secretRef: + # name: oauth-secret livenessProbe: httpGet: path: /api/health