附录 B. 带有红帽服务值文件模板的 Red Hat Trusted Profile Analyzer
红帽的受信任的配置文件分析器(RHTPA)与其他服务值文件模板一起供 RHTPA Helm Chart 使用。
模板
appDomain: $APP_DOMAIN_URL ingress: className: openshift-default additionalAnnotations: "haproxy.router.openshift.io/timeout": "5m" storage: type: s3 region: S3_ENDPOINT_URL bucket: trustify-UNIQUE_ID accessKey: valueFrom: secretKeyRef: name: storage-credentials key: user secretKey: valueFrom: secretKeyRef: name: storage-credentials key: password database: sslMode: require host: valueFrom: secretKeyRef: name: postgresql-credentials key: db.host port: valueFrom: secretKeyRef: name: postgresql-credentials key: db.port name: valueFrom: secretKeyRef: name: postgresql-credentials key: db.name username: valueFrom: secretKeyRef: name: postgresql-credentials key: db.user password: valueFrom: secretKeyRef: name: postgresql-credentials key: db.password createDatabase: name: valueFrom: secretKeyRef: name: postgresql-admin-credentials key: db.name username: valueFrom: secretKeyRef: name: postgresql-admin-credentials key: db.user password: valueFrom: secretKeyRef: name: postgresql-admin-credentials key: db.password migrateDatabase: username: valueFrom: secretKeyRef: name: postgresql-admin-credentials key: db.user password: valueFrom: secretKeyRef: name: postgresql-admin-credentials key: db.password modules: createDatabase: enabled: true migrateDatabase: enabled: true oidc: issuerUrl: OIDC_ISSUER_URL clients: frontend: clientId: FRONTEND_CLIENT_ID cli: clientId: CLI_CLIENT_ID clientSecret: valueFrom: secretKeyRef: name: oidc-cli key: client-secret
appDomain: $APP_DOMAIN_URL
ingress:
className: openshift-default
additionalAnnotations:
"haproxy.router.openshift.io/timeout": "5m"
storage:
type: s3
region: S3_ENDPOINT_URL
bucket: trustify-UNIQUE_ID
accessKey:
valueFrom:
secretKeyRef:
name: storage-credentials
key: user
secretKey:
valueFrom:
secretKeyRef:
name: storage-credentials
key: password
database:
sslMode: require
host:
valueFrom:
secretKeyRef:
name: postgresql-credentials
key: db.host
port:
valueFrom:
secretKeyRef:
name: postgresql-credentials
key: db.port
name:
valueFrom:
secretKeyRef:
name: postgresql-credentials
key: db.name
username:
valueFrom:
secretKeyRef:
name: postgresql-credentials
key: db.user
password:
valueFrom:
secretKeyRef:
name: postgresql-credentials
key: db.password
createDatabase:
name:
valueFrom:
secretKeyRef:
name: postgresql-admin-credentials
key: db.name
username:
valueFrom:
secretKeyRef:
name: postgresql-admin-credentials
key: db.user
password:
valueFrom:
secretKeyRef:
name: postgresql-admin-credentials
key: db.password
migrateDatabase:
username:
valueFrom:
secretKeyRef:
name: postgresql-admin-credentials
key: db.user
password:
valueFrom:
secretKeyRef:
name: postgresql-admin-credentials
key: db.password
modules:
createDatabase:
enabled: true
migrateDatabase:
enabled: true
oidc:
issuerUrl: OIDC_ISSUER_URL
clients:
frontend:
clientId: FRONTEND_CLIENT_ID
cli:
clientId: CLI_CLIENT_ID
clientSecret:
valueFrom:
secretKeyRef:
name: oidc-cli
key: client-secret