2023-01-17 23:06:10 +00:00
|
|
|
# Include{groups}
|
|
|
|
questions:
|
|
|
|
# Include{global}
|
|
|
|
- variable: clusterIssuer
|
|
|
|
group: App Configuration
|
|
|
|
label: Cluster Certificate Issuer
|
|
|
|
schema:
|
|
|
|
additional_attrs: true
|
|
|
|
type: dict
|
|
|
|
attrs:
|
|
|
|
- variable: ACME
|
2023-01-18 00:02:12 +00:00
|
|
|
label: 'ACME Issuer'
|
2023-01-17 23:06:10 +00:00
|
|
|
schema:
|
|
|
|
type: list
|
|
|
|
default: []
|
|
|
|
items:
|
|
|
|
- variable: ACMEEntry
|
|
|
|
label: 'ACME Issuer Entry'
|
|
|
|
schema:
|
|
|
|
additional_attrs: true
|
|
|
|
type: dict
|
|
|
|
attrs:
|
|
|
|
- variable: name
|
|
|
|
label: Name
|
|
|
|
description: "Name to give the issuer"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
2023-03-11 21:52:29 +00:00
|
|
|
valid_chars: '^[a-z]+(-?[a-z]){0,63}-?[a-z]+$'
|
2023-01-17 23:06:10 +00:00
|
|
|
default: ""
|
2023-01-18 00:02:12 +00:00
|
|
|
- variable: type
|
|
|
|
label: Type or DNS-Provider
|
|
|
|
description: DNS Provider
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
default: cloudflare
|
|
|
|
enum:
|
|
|
|
- value: cloudflare
|
|
|
|
description: Cloudflare
|
|
|
|
- value: route53
|
|
|
|
description: Route53
|
|
|
|
- value: akamai
|
|
|
|
description: Akamai
|
|
|
|
- value: digitalocean
|
|
|
|
description: Digitalocean
|
|
|
|
- value: rfc2136
|
|
|
|
description: rfc2136 (Advanced)
|
|
|
|
- value: HTTP01
|
|
|
|
description: HTTP01 (Experimental)
|
2023-10-04 21:27:10 +00:00
|
|
|
- value: acmedns
|
|
|
|
description: ACME DNS (Advanced)
|
2023-01-17 23:06:10 +00:00
|
|
|
- variable: server
|
|
|
|
label: Server
|
|
|
|
description: "Server for ACME, for example: letsencrypt"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
default: 'Letsencrypt-Production'
|
|
|
|
enum:
|
|
|
|
- value: 'https://acme-v02.api.letsencrypt.org/directory'
|
|
|
|
description: Letsencrypt-Production
|
|
|
|
- value: 'https://acme-staging-v02.api.letsencrypt.org/directory'
|
|
|
|
description: Letsencrypt-Staging
|
|
|
|
- value: 'https://api.buypass.no/acme-v02/directory'
|
|
|
|
description: BuyPass-Production
|
|
|
|
- value: 'https://api.test4.buypass.no/acme-v02/directory'
|
|
|
|
description: BuyPass-Staging
|
|
|
|
- value: custom
|
|
|
|
description: Custom
|
|
|
|
- variable: customServer
|
|
|
|
label: Custom ACME Server (Advanced)
|
|
|
|
description: "This can be used to enter your own custom ACME server"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
show_if: [["server", "=", "custom"]]
|
|
|
|
default: 'https://acme-staging-v02.api.letsencrypt.org/directory'
|
2023-11-23 14:06:45 +00:00
|
|
|
- variable: caBundle
|
|
|
|
label: Trusted CABundle for private ACME server
|
|
|
|
description: "Trusted CABundle for private ACME server, encoded in base64"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
show_if: [["server", "=", "custom"]]
|
2023-01-17 23:06:10 +00:00
|
|
|
- variable: email
|
|
|
|
label: Email
|
|
|
|
description: "Email adress to use for certificate issuing must match your DNS provider email when required"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: "something@example.com"
|
|
|
|
- variable: cfapikey
|
|
|
|
label: CloudFlare API key
|
|
|
|
description: "CloudFlare API Key"
|
|
|
|
schema:
|
|
|
|
show_if: [["type", "=", "cloudflare"]]
|
|
|
|
type: string
|
|
|
|
default: ""
|
|
|
|
- variable: cfapitoken
|
|
|
|
label: CloudFlare API Token
|
|
|
|
description: "CloudFlare API Token"
|
|
|
|
schema:
|
|
|
|
show_if: [["type", "=", "cloudflare"]]
|
|
|
|
type: string
|
|
|
|
default: ""
|
|
|
|
- variable: region
|
|
|
|
label: Route53 Region
|
|
|
|
description: "Route 53 Region"
|
|
|
|
schema:
|
|
|
|
show_if: [["type", "=", "route53"]]
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: "us-west-1"
|
|
|
|
- variable: accessKeyID
|
|
|
|
label: Route53 accessKeyID
|
|
|
|
description: "Route53 accessKeyID"
|
|
|
|
schema:
|
|
|
|
show_if: [["type", "=", "route53"]]
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: ""
|
|
|
|
- variable: route53SecretAccessKey
|
|
|
|
label: Route53 Secret Access Key
|
|
|
|
description: "Route53 Secret Access Key"
|
|
|
|
schema:
|
|
|
|
show_if: [["type", "=", "route53"]]
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: ""
|
|
|
|
- variable: role
|
|
|
|
label: Route53 Role (optional)
|
|
|
|
description: "Route53 Role"
|
|
|
|
schema:
|
|
|
|
show_if: [["type", "=", "route53"]]
|
|
|
|
type: string
|
|
|
|
default: ""
|
|
|
|
- variable: serviceConsumerDomain
|
|
|
|
label: Akamai Service Consumer Domain
|
|
|
|
description: "Akamai Service Consumer Domain"
|
|
|
|
schema:
|
|
|
|
show_if: [["type", "=", "akamai"]]
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: ""
|
|
|
|
- variable: akclientToken
|
|
|
|
label: Akamai Client Token
|
|
|
|
description: "Client Token"
|
|
|
|
schema:
|
|
|
|
show_if: [["type", "=", "akamai"]]
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: ""
|
|
|
|
- variable: akclientSecret
|
|
|
|
label: Akamai Client Secret
|
|
|
|
description: "Akamai Client Secret"
|
|
|
|
schema:
|
|
|
|
show_if: [["type", "=", "akamai"]]
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: ""
|
|
|
|
- variable: akaccessToken
|
|
|
|
label: Akamai Access Token
|
|
|
|
description: "Akamai Access Token"
|
|
|
|
schema:
|
|
|
|
show_if: [["type", "=", "akamai"]]
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: ""
|
|
|
|
- variable: doaccessToken
|
|
|
|
label: Digitalocean Access Token
|
|
|
|
description: "Digitalocean Access Token"
|
|
|
|
schema:
|
|
|
|
show_if: [["type", "=", "digitalocean"]]
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: ""
|
|
|
|
- variable: nameserver
|
|
|
|
label: rfc2136 Namesever
|
|
|
|
description: "rfc2136 Namesever"
|
|
|
|
schema:
|
2023-03-09 21:28:47 +00:00
|
|
|
show_if: [["type", "=", "rfc2136"]]
|
2023-01-17 23:06:10 +00:00
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: ""
|
|
|
|
- variable: tsigKeyName
|
|
|
|
label: rfc2136 tsig Key Name
|
|
|
|
description: "rfc2136 tsig Key Name"
|
|
|
|
schema:
|
2023-03-09 21:28:47 +00:00
|
|
|
show_if: [["type", "=", "rfc2136"]]
|
2023-01-17 23:06:10 +00:00
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: ""
|
|
|
|
- variable: tsigAlgorithm
|
|
|
|
label: rfc2136 tsig Algorithm
|
|
|
|
description: "rfc2136 tsig Algorithm"
|
|
|
|
schema:
|
2023-03-09 21:28:47 +00:00
|
|
|
show_if: [["type", "=", "rfc2136"]]
|
2023-01-17 23:06:10 +00:00
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: ""
|
|
|
|
- variable: rfctsigSecret
|
|
|
|
label: rfc2136 sig Secret
|
|
|
|
description: "rfc2136 sig Secret"
|
|
|
|
schema:
|
2023-03-09 21:28:47 +00:00
|
|
|
show_if: [["type", "=", "rfc2136"]]
|
2023-01-17 23:06:10 +00:00
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: ""
|
2023-10-04 21:27:10 +00:00
|
|
|
- variable: acmednsHost
|
|
|
|
label: ACME DNS host
|
|
|
|
description: "ACME DNS API server address"
|
|
|
|
schema:
|
|
|
|
show_if: [["type", "=", "acmedns"]]
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: "https://auth.acme-dns.io"
|
|
|
|
- variable: acmednsConfig
|
|
|
|
label: ACME DNS config
|
|
|
|
description: "ACME DNS per-domain auth configuration"
|
|
|
|
schema:
|
|
|
|
show_if: [["type", "=", "acmedns"]]
|
|
|
|
type: list
|
|
|
|
default: []
|
|
|
|
items:
|
|
|
|
- variable: acmednsEntry
|
|
|
|
label: 'ACME DNS entry'
|
|
|
|
schema:
|
|
|
|
type: dict
|
|
|
|
attrs:
|
|
|
|
- variable: domain
|
|
|
|
label: Domain
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
- variable: username
|
|
|
|
label: Username
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
- variable: password
|
|
|
|
label: Password
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
- variable: fulldomain
|
|
|
|
label: Full domain
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
- variable: subdomain
|
|
|
|
label: Subdomain
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
- variable: allowFrom
|
|
|
|
label: Allow from
|
|
|
|
schema:
|
|
|
|
type: list
|
|
|
|
default: []
|
|
|
|
items:
|
|
|
|
- variable: cidr
|
|
|
|
label: CIDR
|
|
|
|
schema:
|
|
|
|
type: ipaddr
|
|
|
|
cidr: true
|
|
|
|
required: true
|
2023-01-17 23:06:10 +00:00
|
|
|
- variable: CA
|
2023-03-11 21:52:29 +00:00
|
|
|
label: Certificate Authority Issuer
|
2023-01-17 23:06:10 +00:00
|
|
|
schema:
|
|
|
|
type: list
|
|
|
|
default: []
|
|
|
|
items:
|
|
|
|
- variable: CAEntry
|
|
|
|
label: 'CA Issuer Entry'
|
|
|
|
schema:
|
|
|
|
additional_attrs: true
|
|
|
|
type: dict
|
|
|
|
attrs:
|
|
|
|
- variable: name
|
|
|
|
label: Name
|
|
|
|
description: "Name to give the issuer"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
2023-03-11 21:52:29 +00:00
|
|
|
valid_chars: '^[a-z]+(-?[a-z]){0,63}-?[a-z]+$'
|
2023-01-17 23:06:10 +00:00
|
|
|
default: ""
|
|
|
|
- variable: selfSigned
|
|
|
|
label: selfSigned
|
|
|
|
description: "Create Self Signed CA cert"
|
|
|
|
schema:
|
|
|
|
type: boolean
|
|
|
|
default: true
|
|
|
|
- variable: selfSignedCommonName
|
|
|
|
label: selfSigned CommonName
|
|
|
|
description: "Common name for selfSigned Certiticate Authority"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
2023-05-28 18:35:27 +00:00
|
|
|
show_if: [["selfSigned", "=", true]]
|
2023-01-17 23:06:10 +00:00
|
|
|
default: "my-selfsigned-ca"
|
|
|
|
- variable: crt
|
|
|
|
label: "Custom CA cert (experimental)"
|
|
|
|
description: "certificate for Certiticate Authority"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
2023-06-07 07:50:44 +00:00
|
|
|
max_length: 10240
|
2023-05-28 18:35:27 +00:00
|
|
|
show_if: [["selfSigned", "=", false]]
|
2023-01-17 23:06:10 +00:00
|
|
|
default: ""
|
|
|
|
- variable: key
|
|
|
|
label: "Custom CA key (experimental)"
|
|
|
|
description: "key Certiticate Authority"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
2023-06-07 07:50:44 +00:00
|
|
|
max_length: 10240
|
2023-05-28 18:35:27 +00:00
|
|
|
show_if: [["selfSigned", "=", false]]
|
2023-01-17 23:06:10 +00:00
|
|
|
default: ""
|
2023-03-04 12:42:14 +00:00
|
|
|
|
2023-01-18 11:59:26 +00:00
|
|
|
- variable: selfSigned
|
|
|
|
label: 'SelfSigned Issuer'
|
|
|
|
schema:
|
|
|
|
additional_attrs: true
|
|
|
|
type: dict
|
|
|
|
attrs:
|
|
|
|
- variable: enabled
|
|
|
|
label: enabled
|
|
|
|
description: "Enable self-signed issuer"
|
|
|
|
schema:
|
|
|
|
type: boolean
|
|
|
|
default: true
|
|
|
|
- variable: name
|
|
|
|
label: Name
|
|
|
|
description: "Name to give the issuer"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
2023-03-11 21:52:29 +00:00
|
|
|
valid_chars: '^[a-z]+(-?[a-z]){0,63}-?[a-z]+$'
|
|
|
|
default: "selfsigned"
|
2023-01-17 23:06:10 +00:00
|
|
|
|
2023-10-28 19:17:04 +00:00
|
|
|
- variable: clusterCertificates
|
|
|
|
group: App Configuration
|
2023-11-05 22:08:08 +00:00
|
|
|
label: Cluster Wide Certificates (Advanced)
|
2023-10-28 19:17:04 +00:00
|
|
|
description: "Creates certificates for use within the entire cluster. Can be used to create wildcard certificates."
|
|
|
|
schema:
|
|
|
|
additional_attrs: true
|
|
|
|
type: dict
|
|
|
|
attrs:
|
|
|
|
- variable: certificates
|
|
|
|
label: Cluster Certificates
|
|
|
|
schema:
|
|
|
|
type: list
|
|
|
|
default: []
|
|
|
|
items:
|
2023-10-30 22:51:31 +00:00
|
|
|
- variable: CertEntry
|
|
|
|
label: 'Certificate Entry'
|
2023-10-28 19:17:04 +00:00
|
|
|
schema:
|
2023-10-30 22:51:31 +00:00
|
|
|
additional_attrs: true
|
|
|
|
type: dict
|
|
|
|
attrs:
|
|
|
|
- variable: enabled
|
|
|
|
label: Enabled
|
|
|
|
schema:
|
|
|
|
type: boolean
|
|
|
|
default: true
|
|
|
|
- variable: name
|
|
|
|
label: Certificate Name
|
2023-10-28 19:17:04 +00:00
|
|
|
schema:
|
|
|
|
type: string
|
2023-10-30 22:51:31 +00:00
|
|
|
required: true
|
2023-10-28 19:17:04 +00:00
|
|
|
default: ""
|
2023-10-30 22:51:31 +00:00
|
|
|
- variable: certificateIssuer
|
|
|
|
label: Cert-Manager clusterIssuer
|
|
|
|
description: "One of the Cert-Manager clusterIssuers defined above"
|
|
|
|
schema:
|
|
|
|
type: string
|
2023-10-28 19:17:04 +00:00
|
|
|
required: true
|
2023-10-30 22:51:31 +00:00
|
|
|
valid_chars: '^[a-z]+(-?[a-z]){0,63}-?[a-z]+$'
|
|
|
|
default: "selfsigned"
|
|
|
|
- variable: hosts
|
|
|
|
label: Certificate Hosts
|
|
|
|
description: "NOTE: Creation of wildcard certificates with an ACME issuer requires a DNSO1 solver to be set up."
|
|
|
|
schema:
|
|
|
|
type: list
|
|
|
|
default: []
|
|
|
|
items:
|
|
|
|
- variable: host
|
|
|
|
label: Host
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
default: ""
|
|
|
|
required: true
|
2023-10-28 19:17:04 +00:00
|
|
|
|
2023-03-06 16:20:23 +00:00
|
|
|
- variable: customMetrics
|
|
|
|
group: Metrics
|
|
|
|
label: Prometheus Metrics
|
|
|
|
schema:
|
|
|
|
additional_attrs: true
|
|
|
|
type: dict
|
|
|
|
attrs:
|
|
|
|
- variable: enabled
|
|
|
|
label: Enabled
|
|
|
|
description: Enable Prometheus Metrics
|
|
|
|
schema:
|
|
|
|
type: boolean
|
|
|
|
default: true
|