diff --git a/cassandra/values.yaml b/cassandra/values.yaml index 32850a3..047212f 100644 --- a/cassandra/values.yaml +++ b/cassandra/values.yaml @@ -12,18 +12,18 @@ ## @param global.defaultStorageClass Global default StorageClass for Persistent Volume(s) ## global: - imageRegistry: "" + imageRegistry: "registry.co-work.ru" ## E.g. ## imagePullSecrets: ## - myRegistryKeySecretName ## - imagePullSecrets: [] + imagePullSecrets: [docker-registry-secret] defaultStorageClass: "" ## Security parameters ## security: ## @param global.security.allowInsecureImages Allows skipping image verification - allowInsecureImages: false + allowInsecureImages: true ## Compatibility adaptations for Kubernetes platforms ## compatibility: diff --git a/elasticsearch/values.yaml b/elasticsearch/values.yaml index 4a08db4..add5232 100644 --- a/elasticsearch/values.yaml +++ b/elasticsearch/values.yaml @@ -30,9 +30,9 @@ esMajorVersion: "" # such as elasticsearch.yml and log4j2.properties esConfig: elasticsearch.yml: | - xpack.security.enabled: false - xpack.security.http.ssl.enabled: false - xpack.security.transport.ssl.enabled: false + xpack.security.enabled: false + xpack.security.http.ssl.enabled: false + xpack.security.transport.ssl.enabled: false log4j2.properties: | status = error appender.console.type = Console @@ -106,7 +106,7 @@ hostAliases: [] # - "foo.local" # - "bar.local" -image: "docker.io/library/elasticsearch" +image: "registry.co-work.ru/library/elasticsearch" imageTag: "8.5.1" imagePullPolicy: "IfNotPresent" @@ -184,9 +184,9 @@ extraVolumeMounts: # mountPath: /usr/share/elasticsearch/config/http-certs # readOnly: true -extraContainers: +extraContainers: - name: elasticsearch-template-loader - image: docker.io/library/elasticsearch:8.5.1 + image: registry.co-work.ru/library/elasticsearch:8.5.1 command: - /bin/bash - -c @@ -329,7 +329,9 @@ clusterHealthCheckParams: "wait_for_status=green&timeout=1s" ## schedulerName: "" -imagePullSecrets: [] +imagePullSecrets: + - name: docker-registry-secret + nodeSelector: tenant: client2 tolerations: diff --git a/kafka/values.yaml b/kafka/values.yaml index a9ecde8..7cd5350 100644 --- a/kafka/values.yaml +++ b/kafka/values.yaml @@ -13,19 +13,19 @@ ## @param global.storageClass DEPRECATED: use global.defaultStorageClass instead ## global: - imageRegistry: "" + imageRegistry: "registry.co-work.ru" ## E.g. ## imagePullSecrets: ## - myRegistryKeySecretName ## - imagePullSecrets: [] + imagePullSecrets: [docker-registry-secret] defaultStorageClass: "" storageClass: "client2" ## Security parameters ## security: ## @param global.security.allowInsecureImages Allows skipping image verification - allowInsecureImages: false + allowInsecureImages: true ## Compatibility adaptations for Kubernetes platforms ## compatibility: diff --git a/nfs-subdir-external-provisioner/values.yaml b/nfs-subdir-external-provisioner/values.yaml index 76d116e..636c7ff 100644 --- a/nfs-subdir-external-provisioner/values.yaml +++ b/nfs-subdir-external-provisioner/values.yaml @@ -2,10 +2,10 @@ replicaCount: 1 strategyType: Recreate image: - repository: registry.k8s.io/sig-storage/nfs-subdir-external-provisioner + repository: registry.co-work.ru/sig-storage/nfs-subdir-external-provisioner tag: v4.0.2 pullPolicy: IfNotPresent -imagePullSecrets: [] +imagePullSecrets: name: docker-registry-secret] nfs: server: 192.168.2.14 diff --git a/postgresql-ha/values.yaml b/postgresql-ha/values.yaml index 5576c4a..bcdc7ba 100644 --- a/postgresql-ha/values.yaml +++ b/postgresql-ha/values.yaml @@ -23,13 +23,16 @@ ## @param global.pgpool.existingSecret Pgpool existing secret ## global: - imageRegistry: "" + imageRegistry: "registry.co-work.ru" ## E.g. ## imagePullSecrets: ## - myRegistryKeySecretName ## - imagePullSecrets: [] + imagePullSecrets: [docker-registry-secret] storageClass: "client2" + security: + allowInsecureImages: true + postgresql: username: "" password: "" @@ -658,7 +661,7 @@ postgresql: CREATE DATABASE search_db; CREATE DATABASE device; CREATE DATABASE license; - + ## @param postgresql.initdbScriptsCM ConfigMap with scripts to be run at first boot ## NOTE: This will override initdbScripts ## @@ -1349,11 +1352,11 @@ pgpool: drop: ["ALL"] seccompProfile: type: "RuntimeDefault" - + extraVolumes: - name: pgpool-run emptyDir: {} - + extraVolumeMounts: - name: pgpool-run mountPath: /var/run/pgpool @@ -1393,7 +1396,7 @@ pgpool: periodSeconds: 10 timeoutSeconds: 10 successThreshold: 1 - failureThreshold: 6 + failureThreshold: 6 ## Pgpool container's readiness probe ## ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle/#container-probes ## @param pgpool.readinessProbe.enabled Enable readinessProbe @@ -2246,7 +2249,7 @@ backup: - key: "node-role.kubernetes.io/control-plane" operator: "Exists" effect: "NoSchedule" - + storage: ## @param backup.cronjob.storage.existingClaim Provide an existing `PersistentVolumeClaim` (only when `architecture=standalone`) ## If defined, PVC must be created manually before volume will be bound diff --git a/redis/values.yaml b/redis/values.yaml index 3d25bbc..ccbec39 100644 --- a/redis/values.yaml +++ b/redis/values.yaml @@ -14,19 +14,19 @@ ## @param global.redis.password Global Redis® password (overrides `auth.password`) ## global: - imageRegistry: "" + imageRegistry: "registry.co-work.ru" ## E.g. ## imagePullSecrets: ## - myRegistryKeySecretName ## - imagePullSecrets: [] + imagePullSecrets: [docker-registry-secret] defaultStorageClass: "" storageClass: "client2" ## Security parameters ## security: ## @param global.security.allowInsecureImages Allows skipping image verification - allowInsecureImages: false + allowInsecureImages: true redis: password: "" ## Compatibility adaptations for Kubernetes platforms @@ -1584,7 +1584,7 @@ sentinel: ## @param sentinel.extraPodSpec Optionally specify extra PodSpec for the Redis® Sentinel pod(s) ## extraPodSpec: {} - + externalAccess: ## @param sentinel.externalAccess.enabled Enable external access to the Redis ## @@ -1600,10 +1600,10 @@ sentinel: ## @param sentinel.externalAccess.service.redisPort Port for the services used to expose redis-server ## redisPort: 6379 - + ## @param sentinel.externalAccess.service.sentinelPort Port for the services used to expose redis-sentinel - ## - sentinelPort: 26379 + ## + sentinelPort: 26379 ## @param sentinel.externalAccess.service.loadBalancerIP Array of load balancer IPs for each Redis® node. Length must be the same as sentinel.replicaCount ## loadBalancerIP: [] diff --git a/vault-secrets-operator/values.yaml b/vault-secrets-operator/values.yaml index 9232cd6..2d7727c 100644 --- a/vault-secrets-operator/values.yaml +++ b/vault-secrets-operator/values.yaml @@ -121,7 +121,7 @@ controller: # Image sets the repo and tag of the kube-rbac-proxy image to use for the controller. image: pullPolicy: IfNotPresent - repository: quay.io/brancz/kube-rbac-proxy + repository: registry.co-work.ru/brancz/kube-rbac-proxy tag: v0.18.1 # Configures the default resources for the kube rbac proxy container. @@ -147,7 +147,7 @@ controller: # ``` # Refer to https://kubernetes.io/docs/concepts/containers/images/#using-a-private-registry. # @type: array - imagePullSecrets: [] + imagePullSecrets: [docker-registry-secret] # Extra labels to attach to the deployment. This should be formatted as a YAML object (map) extraLabels: {} @@ -160,7 +160,7 @@ controller: # Image sets the repo and tag of the vault-secrets-operator image to use for the controller. image: pullPolicy: IfNotPresent - repository: hashicorp/vault-secrets-operator + repository: registry.co-work.ru/hashicorp/vault-secrets-operator tag: 0.10.0 # logging @@ -877,9 +877,9 @@ hooks: # to complete. # @type: string executionTimeout: 30s - + ## Used by unit tests, and will not be rendered except when using `helm template`, this can be safely ignored. tests: # @type: boolean enabled: true -fullnameOverride: "vault-secrets-operator" \ No newline at end of file +fullnameOverride: "vault-secrets-operator" diff --git a/vault/values.yaml b/vault/values.yaml index c58e30c..6093096 100644 --- a/vault/values.yaml +++ b/vault/values.yaml @@ -13,7 +13,7 @@ global: # Image pull secret to use for registry authentication. # Alternatively, the value may be specified as an array of strings. - imagePullSecrets: [] + imagePullSecrets: [docker-registry-secret] # imagePullSecrets: # - name: image-pull-secret @@ -67,7 +67,7 @@ injector: # image sets the repo and tag of the vault-k8s image to use for the injector. image: - repository: "hashicorp/vault-k8s" + repository: "registry.co-work.ru/hashicorp/vault-k8s" tag: "1.6.2" pullPolicy: IfNotPresent @@ -75,7 +75,7 @@ injector: # containers. This should be set to the official Vault image. Vault 1.3.1+ is # required. agentImage: - repository: "hashicorp/vault" + repository: "registry.co-work.ru/hashicorp/vault" tag: "1.19.0" # The default values for the injected Vault Agent containers. @@ -378,7 +378,7 @@ server: secretKey: "license" image: - repository: "hashicorp/vault" + repository: "registry.co-work.ru/hashicorp/vault" tag: "1.19.0" # Overrides the default Image Pull Policy pullPolicy: IfNotPresent @@ -1089,7 +1089,7 @@ csi: enabled: false image: - repository: "hashicorp/vault-csi-provider" + repository: "registry.co-work.ru/hashicorp/vault-csi-provider" tag: "1.5.0" pullPolicy: IfNotPresent @@ -1182,7 +1182,7 @@ csi: extraArgs: [] image: - repository: "hashicorp/vault" + repository: "registry.co-work.ru/hashicorp/vault" tag: "1.19.0" pullPolicy: IfNotPresent