# Copyright © 2019 Amdocs, Bell Canada
# Copyright (c) 2020 Nordix Foundation, Modifications
# Modifications Copyright © 2020-2021 Nokia
+# Modifications Copyright © 2023 Nordix Foundation
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
nodePortPrefix: 302
nodePortPrefixExt: 304
-
- # Install test components
- # test components are out of the scope of ONAP but allow to have a entire
- # environment to test the different features of ONAP
- # Current tests environments provided:
- # - netbox (needed for CDS IPAM)
- # - AWX (needed for XXX)
- # - EJBCA Server (needed for CMPv2 tests)
- # Today, "contrib" chart that hosting these components must also be enabled
- # in order to make it work. So `contrib.enabled` must have the same value than
- # addTestingComponents
- addTestingComponents: &testing false
-
# ONAP Repository
# Four different repositories are used
# You can change individually these repositories to ones that will serve the
repository: nexus3.onap.org:10001
dockerHubRepository: &dockerHubRepository docker.io
elasticRepository: &elasticRepository docker.elastic.co
+ quayRepository: quay.io
googleK8sRepository: k8s.gcr.io
githubContainerRegistry: ghcr.io
- #/!\ DEPRECATED /!\
- # Legacy repositories which will be removed at the end of migration.
- # Please don't use
- loggingRepository: *elasticRepository
- busyboxRepository: *dockerHubRepository
-
# Default credentials
# they're optional. If the target repository doesn't need them, comment them
repositoryCred:
storageclassProvisioner: kubernetes.io/no-provisioner
volumeReclaimPolicy: Retain
+ # Global flag to enable the creation of default roles instead of using
+ # common roles-wrapper
+ createDefaultRoles: false
+
# override default resource limit flavor for all charts
flavor: unlimited
# enable all component's Ingress interfaces
enable_all: false
+ # Provider: ingress, istio, gw-api
+ provider: istio
+ # Ingress class (only for provider "ingress"): e.g. nginx, traefik
+ ingressClass:
+ # Ingress Selector (only for provider "istio") to match with the
+ # ingress pod label "istio=ingress"
+ ingressSelector: ingress
+ # optional: common used Gateway (for Istio, GW-API) and listener names
+ commonGateway:
+ name: ""
+ httpListener: ""
+ httpsListener: ""
+
# default Ingress base URL and preAddr- and postAddr settings
# Ingress URLs result:
# <preaddr><component.ingress.service.baseaddr><postaddr>.<baseurl>
# tls:
# secret: 'my-ingress-cert'
- # optional: Namespace of the Istio IngressGateway
+ # optional: Namespace of the Istio IngressGateway or Gateway-API
# only valid for Istio Gateway (ServiceMesh enabled)
namespace: istio-ingress
# Global Service Mesh configuration
- # POC Mode, don't use it in production
serviceMesh:
enabled: false
tls: true
# be aware that linkerd is not well tested
engine: "istio" # valid value: istio or linkerd
+ # Global Istio Authorization Policy configuration
+ authorizationPolicies:
+ enabled: false
+
# metrics part
# If enabled, exporters (for prometheus) will be deployed
# if custom resources set to yes, CRD from prometheus operartor will be
# POC Mode, only for use in development environment
# Keep it enabled in production
aafEnabled: false
- aafAgentImage: onap/aaf/aaf_agent:2.1.20
# Disabling MSB
# POC Mode, only for use in development environment
# Set to false if you want to disable TLS for NodePorts. Be aware that this
# will loosen your security.
# if set this element will force or not tls even if serviceMesh.tls is set.
- # tlsEnabled: false
+ tlsEnabled: false
# Logging
# Currently, centralized logging is not in best shape so it's disabled by
# storageClass: "-"
# Example of specific for the components which requires RWX:
-# aaf:
-# persistence:
-# storageClassOverride: "My_RWX_Storage_Class"
-# contrib:
-# netbox:
-# netbox-app:
-# persistence:
-# storageClassOverride: "My_RWX_Storage_Class"
# cds:
# cds-blueprints-processor:
# persistence:
# to customize the ONAP deployment.
#################################################################
-aaf:
- enabled: false
- aaf-sms:
- cps:
- # you must always set the same values as value set in cps.enabled
- enabled: false
aai:
enabled: false
cassandra:
enabled: false
cds:
enabled: false
-clamp:
- enabled: false
cli:
enabled: false
-consul:
- enabled: false
-# Today, "contrib" chart that hosting these components must also be enabled
-# in order to make it work. So `contrib.enabled` must have the same value than
-# addTestingComponents
-contrib:
- enabled: *testing
cps:
enabled: false
dcaegen2-services:
enabled: false
dmaap-dr-node:
enabled: false
-# Today, "logging" chart that perform the central part of logging must also be
-# enabled in order to make it work. So `logging.enabled` must have the same
-# value as centralizedLoggingEnabled
-log:
- enabled: *centralizedLogging
-sniro-emulator:
- enabled: false
oof:
enabled: false
mariadb-galera:
openStackVNFTenantId: "1234"
policy:
enabled: false
-pomba:
- enabled: false
-portal:
- enabled: false
robot:
enabled: false
config:
enabled: false
a1policymanagement:
enabled: false
-cert-wrapper:
- enabled: true
repository-wrapper:
enabled: true
roles-wrapper: