Repast content values-tenant.yaml 11

This commit is contained in:
Ruben Hensen
2024-09-10 00:15:26 +02:00
parent b51e15d8e5
commit 4c0aaa55f2
+180 -180
View File
@@ -181,167 +181,167 @@ tenant:
# #
# The name of a custom `Container Runtime <https://kubernetes.io/docs/concepts/containers/runtime-class/>`__ to use for the Operator Console pods. # The name of a custom `Container Runtime <https://kubernetes.io/docs/concepts/containers/runtime-class/>`__ to use for the Operator Console pods.
# runtimeClassName: "" # runtimeClassName: ""
### # ###
# The mount path where Persistent Volumes are mounted inside Tenant container(s). # # The mount path where Persistent Volumes are mounted inside Tenant container(s).
mountPath: /export # mountPath: /export
### # ###
# The Sub path inside Mount path where MinIO stores data. # # The Sub path inside Mount path where MinIO stores data.
# # #
# .. warning:: # # .. warning::
# # #
# Treat the ``mountPath`` and ``subPath`` values as immutable once you deploy the Tenant. # # Treat the ``mountPath`` and ``subPath`` values as immutable once you deploy the Tenant.
# If you change these values post-deployment, then you may have different paths for new and pre-existing data. # # If you change these values post-deployment, then you may have different paths for new and pre-existing data.
# This can vastly increase operational complexity and may result in unpredictable data states. # # This can vastly increase operational complexity and may result in unpredictable data states.
subPath: /data # subPath: /data
### # ###
# Configures a Prometheus-compatible scraping endpoint at the specified port. # # Configures a Prometheus-compatible scraping endpoint at the specified port.
metrics: # metrics:
enabled: false # enabled: false
port: 9000 # port: 9000
protocol: http # protocol: http
### # ###
# Configures external certificate settings for the Tenant. # # Configures external certificate settings for the Tenant.
certificate: # certificate:
### # ###
# Specify an array of Kubernetes TLS secrets, where each entry corresponds to a secret the TLS private key and public certificate pair. # # Specify an array of Kubernetes TLS secrets, where each entry corresponds to a secret the TLS private key and public certificate pair.
# # #
# This is used by MinIO to verify TLS connections from clients using those CAs # # This is used by MinIO to verify TLS connections from clients using those CAs
# If you omit this and have clients using TLS certificates minted by an external CA, those connections may fail with warnings around certificate verification. # # If you omit this and have clients using TLS certificates minted by an external CA, those connections may fail with warnings around certificate verification.
# See `Operator CRD: TenantSpec <https://min.io/docs/minio/kubernetes/upstream/reference/operator-crd.html#tenantspec>`__. # # See `Operator CRD: TenantSpec <https://min.io/docs/minio/kubernetes/upstream/reference/operator-crd.html#tenantspec>`__.
externalCaCertSecret: [ ] # externalCaCertSecret: [ ]
### # ###
# Specify an array of Kubernetes secrets, where each entry corresponds to a secret contains the TLS private key and public certificate pair. # # Specify an array of Kubernetes secrets, where each entry corresponds to a secret contains the TLS private key and public certificate pair.
# # #
# Omit this to use only the MinIO Operator autogenerated certificates. # # Omit this to use only the MinIO Operator autogenerated certificates.
# # #
# If you omit this field *and* set ``requestAutoCert`` to false, the Tenant starts without TLS. # # If you omit this field *and* set ``requestAutoCert`` to false, the Tenant starts without TLS.
# # #
# See `Operator CRD: TenantSpec <https://min.io/docs/minio/kubernetes/upstream/reference/operator-crd.html#tenantspec>`__. # # See `Operator CRD: TenantSpec <https://min.io/docs/minio/kubernetes/upstream/reference/operator-crd.html#tenantspec>`__.
# # #
# .. important:: # # .. important::
# # #
# The MinIO Operator may output TLS connectivity errors if it cannot trust the Certificate Authority (CA) which minted the custom certificates. # # The MinIO Operator may output TLS connectivity errors if it cannot trust the Certificate Authority (CA) which minted the custom certificates.
# # #
# You can pass the CA to the Operator to allow it to trust that cert. # # You can pass the CA to the Operator to allow it to trust that cert.
# See `Self-Signed, Internal, and Private Certificates <https://min.io/docs/minio/kubernetes/upstream/operations/network-encryption.html#self-signed-internal-and-private-certificates>`__ for more information. # # See `Self-Signed, Internal, and Private Certificates <https://min.io/docs/minio/kubernetes/upstream/operations/network-encryption.html#self-signed-internal-and-private-certificates>`__ for more information.
# This step may also be necessary for globally trusted CAs where you must provide intermediate certificates to the Operator to help build the full chain of trust. # # This step may also be necessary for globally trusted CAs where you must provide intermediate certificates to the Operator to help build the full chain of trust.
externalCertSecret: [ ] # externalCertSecret: [ ]
### # ###
# Enable automatic Kubernetes based `certificate generation and signing <https://kubernetes.io/docs/tasks/tls/managing-tls-in-a-cluster>`__ # # Enable automatic Kubernetes based `certificate generation and signing <https://kubernetes.io/docs/tasks/tls/managing-tls-in-a-cluster>`__
requestAutoCert: true # requestAutoCert: true
### # ###
# The minimum number of days to expiry before an alert for an expiring certificate is fired. # # The minimum number of days to expiry before an alert for an expiring certificate is fired.
# In the below example, if a given certificate will expire in 7 days then expiration events will only be triggered 1 day before expiry # # In the below example, if a given certificate will expire in 7 days then expiration events will only be triggered 1 day before expiry
# certExpiryAlertThreshold: 1 # # certExpiryAlertThreshold: 1
### # ###
# This field is used only when ``requestAutoCert: true``. # # This field is used only when ``requestAutoCert: true``.
# Use this field to set CommonName for the auto-generated certificate. # # Use this field to set CommonName for the auto-generated certificate.
# MinIO defaults to using the internal Kubernetes DNS name for the pod # # MinIO defaults to using the internal Kubernetes DNS name for the pod
# The default DNS name format is typically ``*.minio.default.svc.cluster.local``. # # The default DNS name format is typically ``*.minio.default.svc.cluster.local``.
# # #
# See `Operator CRD: CertificateConfig <https://min.io/docs/minio/kubernetes/upstream/reference/operator-crd.html#certificateconfig>`__ # # See `Operator CRD: CertificateConfig <https://min.io/docs/minio/kubernetes/upstream/reference/operator-crd.html#certificateconfig>`__
certConfig: { } # certConfig: { }
### # ###
# MinIO features to enable or disable in the MinIO Tenant # # MinIO features to enable or disable in the MinIO Tenant
# See `Operator CRD: Features <https://min.io/docs/minio/kubernetes/upstream/reference/operator-crd.html#features>`__. # # See `Operator CRD: Features <https://min.io/docs/minio/kubernetes/upstream/reference/operator-crd.html#features>`__.
features: # features:
bucketDNS: false # bucketDNS: false
domains: { } # domains: { }
enableSFTP: false # enableSFTP: false
### # ###
# Array of objects describing one or more buckets to create during tenant provisioning. # # Array of objects describing one or more buckets to create during tenant provisioning.
# Example: # # Example:
# # #
# .. code-block:: yaml # # .. code-block:: yaml
# # #
# - name: my-minio-bucket # # - name: my-minio-bucket
# objectLock: false # optional # # objectLock: false # optional
# region: us-east-1 # optional # # region: us-east-1 # optional
buckets: [ ] # buckets: [ ]
### # ###
# Array of Kubernetes secrets from which the Operator generates MinIO users during tenant provisioning. # # Array of Kubernetes secrets from which the Operator generates MinIO users during tenant provisioning.
# # #
# Each secret should specify the ``CONSOLE_ACCESS_KEY`` and ``CONSOLE_SECRET_KEY`` as the access key and secret key for that user. # # Each secret should specify the ``CONSOLE_ACCESS_KEY`` and ``CONSOLE_SECRET_KEY`` as the access key and secret key for that user.
users: [ ] # users: [ ]
### # ###
# The `PodManagement <https://kubernetes.io/docs/tutorials/stateful-application/basic-stateful-set/#pod-management-policy>`__ policy for MinIO Tenant Pods. # # The `PodManagement <https://kubernetes.io/docs/tutorials/stateful-application/basic-stateful-set/#pod-management-policy>`__ policy for MinIO Tenant Pods.
# Can be "OrderedReady" or "Parallel" # # Can be "OrderedReady" or "Parallel"
podManagementPolicy: Parallel # podManagementPolicy: Parallel
# The `Liveness Probe <https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes>`__ for monitoring Tenant pod liveness. # # The `Liveness Probe <https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes>`__ for monitoring Tenant pod liveness.
# Tenant pods will be restarted if the probe fails. # # Tenant pods will be restarted if the probe fails.
liveness: { } # liveness: { }
### # ###
# `Readiness Probe <https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/>`__ for monitoring Tenant container readiness. # # `Readiness Probe <https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/>`__ for monitoring Tenant container readiness.
# Tenant pods will be removed from service endpoints if the probe fails. # # Tenant pods will be removed from service endpoints if the probe fails.
readiness: { } # readiness: { }
### # ###
# `Startup Probe <https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/>`__ for monitoring container startup. # # `Startup Probe <https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/>`__ for monitoring container startup.
# Tenant pods will be restarted if the probe fails. # # Tenant pods will be restarted if the probe fails.
# Refer # # Refer
startup: { } # startup: { }
### # ###
# The `Lifecycle hooks <https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/>`__ for container. # # The `Lifecycle hooks <https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/>`__ for container.
lifecycle: { } # lifecycle: { }
### # ###
# Directs the Operator to deploy the MinIO S3 API and Console services as LoadBalancer objects. # # Directs the Operator to deploy the MinIO S3 API and Console services as LoadBalancer objects.
# # #
# If the Kubernetes cluster has a configured LoadBalancer, it can attempt to route traffic to those services automatically. # # If the Kubernetes cluster has a configured LoadBalancer, it can attempt to route traffic to those services automatically.
# # #
# - Specify ``minio: true`` to expose the MinIO S3 API. # # - Specify ``minio: true`` to expose the MinIO S3 API.
# - Specify ``console: true`` to expose the Console. # # - Specify ``console: true`` to expose the Console.
# # #
# Both fields default to ``false``. # # Both fields default to ``false``.
exposeServices: { } # exposeServices: { }
### # ###
# The `Kubernetes Service Account <https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/>`__ associated with the Tenant. # # The `Kubernetes Service Account <https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/>`__ associated with the Tenant.
serviceAccountName: "" # serviceAccountName: ""
### # ###
# Directs the Operator to add the Tenant's metric scrape configuration to an existing Kubernetes Prometheus deployment managed by the Prometheus Operator. # # Directs the Operator to add the Tenant's metric scrape configuration to an existing Kubernetes Prometheus deployment managed by the Prometheus Operator.
prometheusOperator: false # prometheusOperator: false
### # ###
# Configure pod logging configuration for the MinIO Tenant. # # Configure pod logging configuration for the MinIO Tenant.
# # #
# - Specify ``json`` for JSON-formatted logs. # # - Specify ``json`` for JSON-formatted logs.
# - Specify ``anonymous`` for anonymized logs. # # - Specify ``anonymous`` for anonymized logs.
# - Specify ``quiet`` to supress logging. # # - Specify ``quiet`` to supress logging.
# # #
# An example of JSON-formatted logs is as follows: # # An example of JSON-formatted logs is as follows:
# # #
# .. code-block:: shell # # .. code-block:: shell
# # #
# $ k logs myminio-pool-0-0 -n default # # $ k logs myminio-pool-0-0 -n default
# {"level":"INFO","errKind":"","time":"2022-04-07T21:49:33.740058549Z","message":"All MinIO sub-systems initialized successfully"} # # {"level":"INFO","errKind":"","time":"2022-04-07T21:49:33.740058549Z","message":"All MinIO sub-systems initialized successfully"}
logging: { } # logging: { }
### # ###
# serviceMetadata allows passing additional labels and annotations to MinIO and Console specific # # serviceMetadata allows passing additional labels and annotations to MinIO and Console specific
# services created by the operator. # # services created by the operator.
serviceMetadata: { } # serviceMetadata: { }
### # ###
# Add environment variables to be set in MinIO container (https://github.com/minio/minio/tree/master/docs/config) # # Add environment variables to be set in MinIO container (https://github.com/minio/minio/tree/master/docs/config)
env: [ ] # env: [ ]
### # ###
# PriorityClassName indicates the Pod priority and hence importance of a Pod relative to other Pods. # # PriorityClassName indicates the Pod priority and hence importance of a Pod relative to other Pods.
# This is applied to MinIO pods only. # # This is applied to MinIO pods only.
# Refer Kubernetes documentation for details https://kubernetes.io/docs/concepts/configuration/pod-priority-preemption/#priorityclass/ # # Refer Kubernetes documentation for details https://kubernetes.io/docs/concepts/configuration/pod-priority-preemption/#priorityclass/
priorityClassName: "" # priorityClassName: ""
### # ###
# An array of `Volumes <https://kubernetes.io/docs/concepts/storage/volumes/>`__ which the Operator can mount to Tenant pods. # # An array of `Volumes <https://kubernetes.io/docs/concepts/storage/volumes/>`__ which the Operator can mount to Tenant pods.
# # #
# The volumes must exist *and* be accessible to the Tenant pods. # # The volumes must exist *and* be accessible to the Tenant pods.
additionalVolumes: [ ] # additionalVolumes: [ ]
### # ###
# An array of volume mount points associated to each Tenant container. # # An array of volume mount points associated to each Tenant container.
# # #
# Specify each item in the array as follows: # # Specify each item in the array as follows:
# # #
# .. code-block:: yaml # # .. code-block:: yaml
# # #
# volumeMounts: # # volumeMounts:
# - name: volumename # # - name: volumename
# mountPath: /path/to/mount # # mountPath: /path/to/mount
# # #
# The ``name`` field must correspond to an entry in the ``additionalVolumes`` array. # # The ``name`` field must correspond to an entry in the ``additionalVolumes`` array.
additionalVolumeMounts: [ ] # additionalVolumeMounts: [ ]
# Define configuration for KES (stateless and distributed key-management system) # Define configuration for KES (stateless and distributed key-management system)
# Refer https://github.com/minio/kes # Refer https://github.com/minio/kes
#kes: #kes:
@@ -444,25 +444,25 @@ tenant:
# Configures `Ingress <https://kubernetes.io/docs/concepts/services-networking/ingress/>`__ for the Tenant S3 API and Console. # Configures `Ingress <https://kubernetes.io/docs/concepts/services-networking/ingress/>`__ for the Tenant S3 API and Console.
# #
# Set the keys to conform to the Ingress controller and configuration of your choice. # Set the keys to conform to the Ingress controller and configuration of your choice.
# ingress: ingress:
# api: api:
# enabled: false enabled: false
# ingressClassName: "" ingressClassName: ""
# labels: { } labels: { }
# annotations: { } annotations: { }
# tls: [ ] tls: [ ]
# host: minio.local host: minio.local
# path: / path: /
# pathType: Prefix pathType: Prefix
# console: console:
# enabled: false enabled: false
# ingressClassName: "" ingressClassName: ""
# labels: { } labels: { }
# annotations: { } annotations: { }
# tls: [ ] tls: [ ]
# host: minio-console.local host: minio-console.local
# path: / path: /
# pathType: Prefix pathType: Prefix
# Use an extraResources template section to include additional Kubernetes resources # Use an extraResources template section to include additional Kubernetes resources
# with the Helm deployment. # with the Helm deployment.
#extraResources: #extraResources: