Code Review
/
oom.git
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
review
|
tree
raw
|
inline
| side by side
[SO] Create Authorization Policies for SO
[oom.git]
/
kubernetes
/
so
/
components
/
so-sdc-controller
/
values.yaml
diff --git
a/kubernetes/so/components/so-sdc-controller/values.yaml
b/kubernetes/so/components/so-sdc-controller/values.yaml
index
e613950
..
8b17efc
100755
(executable)
--- a/
kubernetes/so/components/so-sdc-controller/values.yaml
+++ b/
kubernetes/so/components/so-sdc-controller/values.yaml
@@
-19,15
+19,10
@@
global:
nodePortPrefixExt: 304
persistence:
mountPath: /dockerdata-nfs
nodePortPrefixExt: 304
persistence:
mountPath: /dockerdata-nfs
- security:
- aaf:
- enabled: false
- aaf:
- auth:
- header: Basic c29Ac28ub25hcC5vcmc6ZGVtbzEyMzQ1Ngo=
mariadbGalera:
serviceName: mariadb-galera
servicePort: '3306'
mariadbGalera:
serviceName: mariadb-galera
servicePort: '3306'
+ soSdcListenerKafkaUser: so-sdc-list-user
readinessCheck:
wait_for:
readinessCheck:
wait_for:
@@
-58,7
+53,7
@@
secrets:
#################################################################
# Application configuration defaults.
#################################################################
#################################################################
# Application configuration defaults.
#################################################################
-image: onap/so/sdc-controller:1.
9.2
+image: onap/so/sdc-controller:1.
12.0
pullPolicy: Always
db:
pullPolicy: Always
db:
@@
-87,26
+82,22
@@
minReadySeconds: 10
containerPort: &containerPort 8085
logPath: ./logs/sdc/
app: sdc-controller
containerPort: &containerPort 8085
logPath: ./logs/sdc/
app: sdc-controller
+
service:
service:
- type: ClusterIP
- internalPort: *containerPort
- externalPort: *containerPort
- portName: so-sdc-port
+ type: ClusterIP
+ ports:
+ - name: http
+ port: *containerPort
+
updateStrategy:
updateStrategy:
-
type: RollingUpdate
-
maxUnavailable: 1
-
maxSurge: 1
+ type: RollingUpdate
+ maxUnavailable: 1
+ maxSurge: 1
#################################################################
# soHelpers part
#################################################################
soHelpers:
#################################################################
# soHelpers part
#################################################################
soHelpers:
- nameOverride: so-sdc-cert-init
- certInitializer:
- nameOverride: so-sdc-cert-init
- credsPath: /opt/app/osaaf/local
- cadi:
- apiEnforcement: org.onap.so.sdcControllerPerm
containerPort: *containerPort
# Resource Limit flavor -By Default using small
containerPort: *containerPort
# Resource Limit flavor -By Default using small
@@
-128,21
+119,41
@@
resources:
memory: 2Gi
cpu: 1000m
unlimited: {}
memory: 2Gi
cpu: 1000m
unlimited: {}
+
livenessProbe:
livenessProbe:
- path: /manage/health
- port: 8085
- scheme: HTTP
- initialDelaySeconds: 600
- periodSeconds: 60
- timeoutSeconds: 10
- successThreshold: 1
- failureThreshold: 3
+ path: /manage/health
+ port: 8085
+ scheme: HTTP
+ initialDelaySeconds: 600
+ periodSeconds: 60
+ timeoutSeconds: 10
+ successThreshold: 1
+ failureThreshold: 3
+
ingress:
enabled: false
ingress:
enabled: false
+
+serviceMesh:
+ authorizationPolicy:
+ authorizedPrincipals:
+ - serviceAccount: robot-read
+ - serviceAccount: so-read
+
nodeSelector: {}
tolerations: []
affinity: {}
nodeSelector: {}
tolerations: []
affinity: {}
+# Strimzi KafkaUser config
+kafkaUser:
+ acls:
+ - name: SO
+ type: group
+ operations: [Read]
+ - name: SDC-DISTR
+ type: topic
+ patternType: prefix
+ operations: [Read, Write]
+
#Pods Service Account
serviceAccount:
nameOverride: so-sdc-controller
#Pods Service Account
serviceAccount:
nameOverride: so-sdc-controller