1 # ============LICENSE_START=======================================================
2 # Copyright (C) 2019 Nordix Foundation.
3 # Modifications Copyright (C) 2019-2021 AT&T Intellectual Property.
4 # Modifications Copyright (C) 2020-2022 Bell Canada. All rights reserved.
5 # Modifications Copyright © 2022 Nordix Foundation
6 # ================================================================================
7 # Licensed under the Apache License, Version 2.0 (the "License");
8 # you may not use this file except in compliance with the License.
9 # You may obtain a copy of the License at
11 # http://www.apache.org/licenses/LICENSE-2.0
13 # Unless required by applicable law or agreed to in writing, software
14 # distributed under the License is distributed on an "AS IS" BASIS,
15 # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16 # See the License for the specific language governing permissions and
17 # limitations under the License.
19 # SPDX-License-Identifier: Apache-2.0
20 # ============LICENSE_END=========================================================
22 #################################################################
23 # Global configuration defaults.
24 #################################################################
26 nodePortPrefixExt: 304
31 #################################################################
33 #################################################################
37 externalSecret: '{{ tpl (default "" .Values.db.credsExternalSecret) . }}'
38 login: '{{ .Values.db.user }}'
39 password: '{{ .Values.db.password }}'
40 passwordPolicy: required
41 - uid: restserver-secret
43 externalSecret: '{{ tpl (default "" .Values.restServer.papUserExternalSecret) . }}'
44 login: '{{ .Values.restServer.user }}'
45 password: '{{ .Values.restServer.password }}'
46 passwordPolicy: required
49 externalSecret: '{{ tpl (default "" .Values.restServer.apiUserExternalSecret) . }}'
50 login: '{{ .Values.healthCheckRestClient.api.user }}'
51 password: '{{ .Values.healthCheckRestClient.api.password }}'
52 passwordPolicy: required
53 - uid: distribution-secret
55 externalSecret: '{{ tpl (default "" .Values.healthCheckRestClient.distribution.credsExternalSecret) . }}'
56 login: '{{ .Values.healthCheckRestClient.distribution.user }}'
57 password: '{{ .Values.healthCheckRestClient.distribution.password }}'
58 passwordPolicy: required
59 - uid: policy-kafka-user
60 externalSecret: '{{ tpl (default "" .Values.config.jaasConfExternalSecret) . }}'
63 - name: sasl.jaas.config
64 value: '{{ .Values.config.someConfig }}'
67 #################################################################
68 # Application configuration defaults.
69 #################################################################
71 image: onap/policy-pap:3.1.3
74 # flag to enable debugging - application support required
77 # application configuration
84 pgName: policy-pg-primary
92 healthCheckRestClient:
100 # default number of instances
107 # probe configuration parameters
109 initialDelaySeconds: 60
111 # necessary to disable liveness probe when setting breakpoints
112 # in debugger so K8s doesn't restart unresponsive container
117 initialDelaySeconds: 10
120 api: /policy/pap/v1/healthcheck
140 authorizedPrincipals:
141 - serviceAccount: strimzi-kafka-read
142 - serviceAccount: portal-app-read
162 #Pods Service Account
164 nameOverride: policy-pap
170 # Override the labels based on the Prometheus config parameter: serviceMonitorSelector.
171 # The default operator for prometheus enforces the below label.
180 externalSecretNameSuffix: policy-pap-user-creds
181 externalSecretUserKey: login
182 externalSecretPasswordKey: password
184 # application configuration
186 # Event consumption (kafka) properties
189 policyHeartbeat: policy-heartbeat
190 policyNotification: policy-notification
191 policyPdpPap: policy-pdp-pap
196 policyPdpPapTopic: policy-pdp-pap
198 # If targeting a custom kafka cluster, ie useStrimziKakfa: false
199 # uncomment below config and target your kafka bootstrap servers,
200 # along with any other security config.
203 # spring.kafka.bootstrap-servers: <kafka-bootstrap>:9092
204 # spring.kafka.security.protocol: PLAINTEXT
205 # spring.kafka.consumer.group-id: policy-group
207 # Any new property can be added in the env by setting in overrides in the format mentioned below
208 # All the added properties must be in "key: value" format instead of yaml.
210 authenticationType: scram-sha-512
214 operations: [Create, Describe, Read, Write]
215 - name: policy-pdp-pap
218 operations: [Create, Describe, Read, Write]
219 - name: policy-heartbeat
222 operations: [Create, Describe, Read, Write]
223 - name: policy-notification
226 operations: [Create, Describe, Read, Write]