1 # Copyright © 2018 AT&T USA
3 # Licensed under the Apache License, Version 2.0 (the "License");
4 # you may not use this file except in compliance with the License.
5 # You may obtain a copy of the License at
7 # http://www.apache.org/licenses/LICENSE-2.0
9 # Unless required by applicable law or agreed to in writing, software
10 # distributed under the License is distributed on an "AS IS" BASIS,
11 # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 # See the License for the specific language governing permissions and
13 # limitations under the License.
14 #################################################################
15 # Global configuration defaults.
16 #################################################################
19 nodePortPrefixExt: 304
20 repository: nexus3.onap.org:10001
21 readinessImage: onap/oom/readiness:3.0.1
22 loggingRepository: docker.elastic.co
23 loggingImage: beats/filebeat:5.5.0
24 soBaseImage: onap/so/base-image:1.0
26 nameOverride: mariadb-galera
27 serviceName: mariadb-galera
29 # mariadbRootPassword: secretpassword
30 # rootPasswordExternalSecret: some secret
31 #This flag allows SO to instantiate its own mariadb-galera cluster,
32 #serviceName and nameOverride should be so-mariadb-galera if this flag is enabled
35 mountPath: /dockerdata-nfs
36 #This configuration specifies Service and port for SDNC OAM interface
37 sdncOamService: sdnc-oam
39 #This configuration will run the migration. The configurations are for backing up the data
40 #from DB and then restoring it to the present versions preferred DB.
43 dbHost: mariadb-galera
46 dbPassword: secretpassword
47 # dbCredsExternalSecret: some secret
54 header: Basic c29Ac28ub25hcC5vcmc6ZGVtbzEyMzQ1Ngo=
55 encrypted: 3EDC974C5CD7FE54C47C7490AF4D3B474CDD7D0FFA35A7ACDE3E209631E45F428976EAC0858874F17390A13149E63C90281DD8D20456
58 auth: 3EDC974C5CD7FE54C47C7490AF4D3B474CDD7D0FFA35A7ACDE3E209631E45F428976EAC0858874F17390A13149E63C90281DD8D20456
59 defaultCloudOwner: onap
62 cadiKeyFile: /app/client/org.onap.so.keyfile
63 cadiTrustStore: /app/client/org.onap.so.trust.jks
64 cadiTruststorePassword: enc:MFpuxKeYK6Eo6QXjDUjtOBbp0FthY7SB4mKSIJm_RWC
66 cadiLongitude: -90.43248
69 aafRootNs: org.onap.so
70 aafLocateUrl: https://aaf-locate.onap:8095
71 aafUrl: https://aaf-locate.onap:8095/locate/org.osaaf.aaf.service:2.1
72 msoKey: 07a7159d3bf51a0e53be7a8f89699be7
75 truststore: /app/client/org.onap.so.trust.jks
76 keystore: /app/client/org.onap.so.jks
77 trustStorePassword: LHN4Iy5DKlcpXXdWZ0pDNmNjRkhJIzpI
78 keyStorePassword: c280b25hcA==
81 share_path: /usr/local/share/ca-certificates/
83 #################################################################
85 #################################################################
88 name: &dbRootPassSecretName '{{ include "common.release" . }}-so-db-root-pass'
90 externalSecret: '{{ ternary .Values.global.mariadbGalera.rootPasswordExternalSecret (default (include "common.mariadb.secret.rootPassSecretName" (dict "dot" . "chartName" .Values.global.mariadbGalera.nameOverride)) .Values.global.mariadbGalera.rootPasswordExternalSecret) .Values.global.mariadbGalera.localCluster }}'
91 password: '{{ .Values.global.mariadbGalera.mariadbRootpassword }}'
92 - uid: db-backup-creds
93 name: &dbBackupCredsSecretName '{{ include "common.release" . }}-so-db-backup-creds'
95 externalSecret: '{{ ternary .Values.global.migration.dbCredsExternalSecret "migrationDisabled" .Values.global.migration.enabled }}'
96 login: '{{ ternary .Values.global.migration.dbUser "migrationDisabled" .Values.global.migration.enabled }}'
97 password: '{{ ternary .Values.global.migration.dbPassword "migrationDisabled" .Values.global.migration.enabled }}'
98 passwordPolicy: required
100 helm.sh/hook: pre-upgrade,pre-install
101 helm.sh/hook-weight: "0"
102 helm.sh/hook-delete-policy: before-hook-creation
104 name: &dbUserCredsSecretName '{{ include "common.release" . }}-so-db-user-creds'
106 externalSecret: '{{ .Values.dbCreds.userCredsExternalSecret }}'
107 login: '{{ .Values.dbCreds.userName }}'
108 password: '{{ .Values.dbCreds.userPassword }}'
109 passwordPolicy: generate
110 - uid: db-admin-creds
111 name: &dbAdminCredsSecretName '{{ include "common.release" . }}-so-db-admin-creds'
113 externalSecret: '{{ .Values.dbCreds.adminCredsExternalSecret }}'
114 login: '{{ .Values.dbCreds.adminName }}'
115 password: '{{ .Values.dbCreds.adminPassword }}'
116 passwordPolicy: generate
117 - uid: "so-onap-certs"
118 name: &so-certs '{{ include "common.release" . }}-so-certs'
119 externalSecret: '{{ tpl (default "" .Values.certSecret) . }}'
122 - resources/config/certificates/onap-ca.crt
123 - resources/config/certificates/msb-ca.crt
125 #################################################################
126 # Application configuration defaults.
127 #################################################################
129 dbSecrets: &dbSecrets
130 userCredsExternalSecret: *dbUserCredsSecretName
131 adminCredsExternalSecret: *dbAdminCredsSecretName
133 # unused in this, just to pass to subcharts
138 repository: nexus3.onap.org:10001
139 image: onap/so/api-handler-infra:1.6.4
144 logPath: ./logs/apih/
145 app: api-handler-infra
151 portName: so-apih-port
156 # Resource Limit flavor -By Default using small
158 # Segregation for Different environment (Small and Large)
160 certificatesPath: /certificates
180 initialDelaySeconds: 600
189 # application configuration
191 logstashServiceName: log-ls
194 #Used only if localCluster is enabled. Instantiates SO's own cassandra cluster
195 #helm deploy demo local/onap --namespace onap --verbose --set so.enabled=true \
196 # --set so.global.mariadbGalera.localCluster=true \
197 # --set so.global.mariadbGalera.nameOverride=so-mariadb-galera \
198 # --set so.global.mariadbGalera.serviceName=so-mariadb-galera
201 mariadbRootPasswordExternalSecret: *dbRootPassSecretName
202 nameOverride: so-mariadb-galera
205 name: so-mariadb-galera
207 mountSubPath: so/mariadb-galera/data
222 auth: Basic YnBlbDpwYXNzd29yZDEk
225 aafId: so@so.onap.org
226 aafPassword: enc:EME-arXn2lx8PO0f2kEtyK7VVGtAGWavXorFoxRmPO9
227 apiEnforcement: org.onap.so.apihPerm
228 noAuthn: /manage/health
229 camundaAuth: AE2E9BE6EF9249085AF98689C4EE087736A5500629A72F35068FFB88813A023581DD6E765071F1C04075B36EA4213A
232 auth: 878785F4F31BC9CFA5AB52A172008212D8845ED2DE08AD5E56AF114720A4E49768B8F95CDA2EB971765D28EDCDAA24
234 auth: 6E081E10B1CA43A843E303733A74D9B23B601A6E22A21C7EF2C7F15A42F81A1A4E85E65268C2661F71321052C7F3E55B96A8E1E951F8BF6F
238 auth: 51EA5414022D7BE536E7516C4D1A6361416921849B72C0D6FC1C7F262FD9F2BBC2AD124190A332D9845A188AD80955567A4F975C84C221EEA8243BFD92FFE6896CDD1EA16ADD34E1E3D47D4A
240 auth: basic bXNvX2FkbWlufHBhc3N3b3JkMSQ=
243 certSecret: *so-certs
247 auth: Basic Y2NzZGthcHBzOmNjc2RrYXBwcw==
249 auth: 221187EFA3AD4E33600DE0488F287099934CE65C3D0697BCECC00BB58E784E07CD74A24581DC31DBC086FF63DF116378776E9BE3D1325885
251 key: 07a7159d3bf51a0e53be7a8f89699be7
254 auth: Basic YnBlbDpwYXNzd29yZDEk
256 auth: A3745B5DBE165EFCF101D85A6FC81C211AB8BF604F8861B6C413D5DC90F8F30E0139DE44B8A342F4EF70AF
257 password: wLg4sjrAFUS8rfVfdvTXeQ==
259 auth: A3745B5DBE165EFCF101D85A6FC81C211AB8BF604F8861B6C413D5DC90F8F30E0139DE44B8A342F4EF70AF
262 aafId: so@so.onap.org
263 aaafPassword: enc:EME-arXn2lx8PO0f2kEtyK7VVGtAGWavXorFoxRmPO9
264 apiEnforcement: org.onap.so.bpmnPerm
265 noAuthn: /manage/health
267 password: 1D78CFC35382B6938A989066A7A7EAEF4FE933D2919BABA99EB4763737F39876C333EE5F
270 endpoint: http://replaceme:28090/optimizationInstance/V1/create
276 auth: Basic dm5mbTpwYXNzd29yZDEk
278 so-catalog-db-adapter:
279 certSecret: *so-certs
285 aafId: so@so.onap.org
286 aafPassword: enc:EME-arXn2lx8PO0f2kEtyK7VVGtAGWavXorFoxRmPO9
287 apiEnforcement: org.onap.so.catalogDbAdapterPerm
288 noAuthn: /manage/health
291 auth: Basic YnBlbDpwYXNzd29yZDEk
294 certSecret: *so-certs
298 so-openstack-adapter:
299 certSecret: *so-certs
304 encrypted: 7F182B0C05D58A23A1C4966B9CDC9E0B8BC5CD53BC8C7B4083D869F8D53E9BDC3EFD55C94B1D3F
306 auth: 2A11B07DB6214A839394AA1EC5844695F5114FC407FF5422625FB00175A3DCB8A1FF745F22867EFA72D5369D599BBD88DA8BED4233CF5586
311 bpelauth: D1A67FA93B6A6419132D0F83CC771AF774FD3C60853C50C22C8C6FC5088CC79E9E81EDE9EA39F22B2F66A0068E
313 basic_auth: bXNvOkphY2tkYXdzIGxvdmUgbXkgYmlnIHNwaGlueCBvZiBxdWFydHouCg==
315 msoKey: 07a7159d3bf51a0e53be7a8f89699be7
316 auth: BEA8637716A7EB617DF472BA6552D22F68C1CB17B0D094D77DDA562F4ADAAC4457CAB848E1A4
320 aafId: so@so.onap.org
321 aafPassword: enc:EME-arXn2lx8PO0f2kEtyK7VVGtAGWavXorFoxRmPO9
322 apiEnforcement: org.onap.so.openStackAdapterPerm
323 noAuthn: /manage/health
325 auth: Basic YnBlbDpwYXNzd29yZDEk
327 so-request-db-adapter:
328 certSecret: *so-certs
334 aafId: so@so.onap.org
335 aafPassword: enc:EME-arXn2lx8PO0f2kEtyK7VVGtAGWavXorFoxRmPO9
336 apiEnforcement: org.onap.so.requestDbAdapterPerm
337 noAuthn: /manage/health
340 auth: Basic YnBlbDpwYXNzd29yZDEk
343 certSecret: *so-certs
347 auth: 2A11B07DB6214A839394AA1EC5844695F5114FC407FF5422625FB00175A3DCB8A1FF745F22867EFA72D5369D599BBD88DA8BED4233CF5586
349 msoKey: 07a7159d3bf51a0e53be7a8f89699be7
352 aafId: so@so.onap.org
353 aafPassword: enc:EME-arXn2lx8PO0f2kEtyK7VVGtAGWavXorFoxRmPO9
354 apiEnforcement: org.onap.so.sdcControllerPerm
355 noAuthn: /manage/health
358 key: 566B754875657232314F5548556D3665
360 auth: Basic YnBlbDpwYXNzd29yZDEk
363 password: 76966BDD3C7414A03F7037264FF2E6C8EEC6C28F2B67F2840A1ED857C0260FEE731D73F47F828E5527125D29FD25D3E0DE39EE44C058906BF1657DE77BF897EECA93BDC07FA64F
366 certSecret: *so-certs
374 bpelauth: 4C18603C5AE7E3A42A6CED95CDF9C0BA9B2109B3725747662E5D34E5FDF63DA9ADEBB08185098F14699195FDE9475100
375 sdncauth: ED07A7EE5F099FA53369C3DF2240AD68A00154676EEDBC6F8C16BAA83B1912941B8941ABD48683D2C1072DA7040659692DE936A59BBF42A038CF71DE67B4A375190071EC76EA657801B033C135
377 encryptionKey: 07a7159d3bf51a0e53be7a8f89699be7
381 aafId: so@so.onap.org
382 aafPassword: enc:EME-arXn2lx8PO0f2kEtyK7VVGtAGWavXorFoxRmPO9
383 apiEnforcement: org.onap.so.sdncAdapterPerm
384 noAuthn: /manage/health
387 auth: Basic YnBlbDpwYXNzd29yZDEk
389 aafEncrypted: 3EDC974C5CD7FE54C47C7490AF4D3B474CDD7D0FFA35A7ACDE3E209631E45F428976EAC0858874F17390A13149E63C90281DD8D20456
392 certSecret: *so-certs
395 certSecret: *so-certs
401 aafId: so@so.onap.org
402 aafPassword: enc:EME-arXn2lx8PO0f2kEtyK7VVGtAGWavXorFoxRmPO9
403 apiEnforcement: org.onap.so.vfcAdapterPerm
404 noAuthn: /manage/health
407 auth: Basic YnBlbDpwYXNzd29yZDEk
410 certSecret: *so-certs
415 username: so@so.onap.org
416 password: 8DB1C939BFC6A35C3832D0E52E452D0E05AE2537AF142CECD125FF827C05A972FDD0F4700547DA
418 auth: 2A11B07DB6214A839394AA1EC5844695F5114FC407FF5422625FB00175A3DCB8A1FF745F22867EFA72D5369D599BBD88DA8BED4233CF5586
420 key: 07a7159d3bf51a0e53be7a8f89699be7
423 aafId: so@so.onap.org
424 aafPassword: enc:EME-arXn2lx8PO0f2kEtyK7VVGtAGWavXorFoxRmPO9
425 apiEnforcement: org.onap.so.nssmfAdapterPerm
426 noAuthn: /manage/health
429 auth: Basic YnBlbDpwYXNzd29yZDEk
432 certSecret: *so-certs
435 username: so@so.onap.org
436 password: 8DB1C939BFC6A35C3832D0E52E452D0E05AE2537AF142CECD125FF827C05A972FDD0F4700547DA
438 auth: 2A11B07DB6214A839394AA1EC5844695F5114FC407FF5422625FB00175A3DCB8A1FF745F22867EFA72D5369D599BBD88DA8BED4233CF5586
441 password: 76966BDD3C7414A03F7037264FF2E6C8EEC6C28F2B67F2840A1ED857C0260FEE731D73F47F828E5527125D29FD25D3E0DE39EE44C058906BF1657DE77BF897EECA93BDC07FA64F
442 key: 566B754875657232314F5548556D3665
444 key: 07a7159d3bf51a0e53be7a8f89699be7
447 aafId: so@so.onap.org
448 aafPassword: enc:EME-arXn2lx8PO0f2kEtyK7VVGtAGWavXorFoxRmPO9
449 apiEnforcement: org.onap.so.vnfmAdapterPerm
450 noAuthn: /manage/health
453 certSecret: *so-certs
455 auth: 2A11B07DB6214A839394AA1EC5844695F5114FC407FF5422625FB00175A3DCB8A1FF745F22867EFA72D5369D599BBD88DA8BED4233CF5586
457 key: 07a7159d3bf51a0e53be7a8f89699be7
461 auth: Basic dm5mbTpwYXNzd29yZDEk
465 rootPasswordExternalSecretLocalDb: *dbRootPassSecretName
466 rootPasswordExternalSecret: '{{ ternary .Values.db.rootPasswordExternalSecretLocalDb (include "common.mariadb.secret.rootPassSecretName" (dict "dot" . "chartName" .Values.global.mariadbGalera.nameOverride)) .Values.global.mariadbGalera.localCluster }}'
467 backupCredsExternalSecret: *dbBackupCredsSecretName
468 userCredsExternalSecret: *dbUserCredsSecretName
469 adminCredsExternalSecret: *dbAdminCredsSecretName
470 so-appc-orchestrator:
471 certSecret: *so-certs
476 auth: BEA8637716A7EB617DF472BA6552D22F68C1CB17B0D094D77DDA562F4ADAAC4457CAB848E1A4
479 aafId: so@so.onap.org
480 aafPassword: enc:EME-arXn2lx8PO0f2kEtyK7VVGtAGWavXorFoxRmPO9
481 apiEnforcement: org.onap.so.openStackAdapterPerm
482 noAuthn: /manage/health
495 key: VIlbtVl6YLhNUrtU
496 secret: 64AG2hF4pYeG2pq7CT6XwUOT
500 aaf: Basic c29Ac28ub25hcC5vcmc6ZGVtbzEyMzQ1Ngo=
501 aafEncrypted: 3EDC974C5CD7FE54C47C7490AF4D3B474CDD7D0FFA35A7ACDE3E209631E45F428976EAC0858874F17390A13149E63C90281DD8D20456