2021-09-13 10:58:34 +00:00
|
|
|
# Include{groups}
|
2021-07-06 13:57:15 +00:00
|
|
|
questions:
|
2021-10-20 17:39:05 +00:00
|
|
|
# Include{global}
|
2022-08-08 21:25:02 +00:00
|
|
|
# Include{controller}
|
|
|
|
# Include{controllerStatefullset}
|
|
|
|
# Include{replicas}
|
|
|
|
# Include{replica1}
|
|
|
|
# Include{strategy}
|
|
|
|
# Include{recreate}
|
2021-09-13 10:58:34 +00:00
|
|
|
# Include{controllerExpert}
|
2022-08-12 08:40:46 +00:00
|
|
|
# Include{controllerExpertExtraArgs}
|
2022-06-07 17:41:19 +00:00
|
|
|
- variable: secretEnv
|
2021-12-11 12:49:05 +00:00
|
|
|
group: "Container Configuration"
|
|
|
|
label: "Image Secrets"
|
|
|
|
schema:
|
2022-01-21 00:35:59 +00:00
|
|
|
additional_attrs: true
|
2021-12-11 12:49:05 +00:00
|
|
|
type: dict
|
|
|
|
attrs:
|
|
|
|
- variable: LDAP_READONLY_USER_USERNAME
|
|
|
|
label: "LDAP_READONLY_USER_USERNAME"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: "readonly"
|
|
|
|
- variable: LDAP_READONLY_USER_PASSWORD
|
|
|
|
label: "LDAP_READONLY_USER_PASSWORD"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
private: true
|
|
|
|
default: "REPLACETHIS"
|
|
|
|
- variable: LDAP_ADMIN_PASSWORD
|
|
|
|
label: "LDAP_ADMIN_PASSWORD"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
private: true
|
|
|
|
default: "REPLACETHIS"
|
|
|
|
- variable: LDAP_CONFIG_PASSWORD
|
|
|
|
label: "LDAP_CONFIG_PASSWORD"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
private: true
|
|
|
|
default: "REPLACETHIS"
|
2021-07-06 13:57:15 +00:00
|
|
|
- variable: env
|
2021-08-31 19:28:47 +00:00
|
|
|
group: "App Configuration"
|
2021-07-06 13:57:15 +00:00
|
|
|
label: "Image Environment"
|
|
|
|
schema:
|
2022-01-21 00:35:59 +00:00
|
|
|
additional_attrs: true
|
2021-07-06 13:57:15 +00:00
|
|
|
type: dict
|
|
|
|
attrs:
|
|
|
|
- variable: LDAP_LOG_LEVEL
|
|
|
|
label: "LDAP_LOG_LEVEL"
|
|
|
|
schema:
|
2021-12-11 12:49:05 +00:00
|
|
|
type: int
|
2021-07-06 13:57:15 +00:00
|
|
|
required: true
|
2021-12-11 12:49:05 +00:00
|
|
|
default: 256
|
2021-07-06 13:57:15 +00:00
|
|
|
- variable: LDAP_ORGANISATION
|
|
|
|
label: "LDAP_ORGANISATION"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: "Example Company or Household"
|
|
|
|
- variable: LDAP_DOMAIN
|
|
|
|
label: "LDAP_DOMAIN"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: "example.org"
|
|
|
|
- variable: LDAP_READONLY_USER
|
|
|
|
label: "LDAP_READONLY_USER"
|
|
|
|
schema:
|
2021-12-11 12:49:05 +00:00
|
|
|
type: boolean
|
|
|
|
default: false
|
2021-07-06 13:57:15 +00:00
|
|
|
- variable: LDAP_RFC2307BIS_SCHEMA
|
|
|
|
label: "LDAP_RFC2307BIS_SCHEMA"
|
|
|
|
schema:
|
2021-12-11 12:49:05 +00:00
|
|
|
type: boolean
|
|
|
|
default: false
|
2021-07-06 13:57:15 +00:00
|
|
|
- variable: LDAP_BACKEND
|
|
|
|
label: "LDAP_BACKEND"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: "mdb"
|
|
|
|
- variable: LDAP_TLS
|
|
|
|
label: "LDAP_TLS"
|
|
|
|
schema:
|
2021-12-11 12:49:05 +00:00
|
|
|
type: boolean
|
|
|
|
default: true
|
2021-07-06 13:57:15 +00:00
|
|
|
- variable: LDAP_TLS_ENFORCE
|
|
|
|
label: "LDAP_TLS_ENFORCE"
|
|
|
|
schema:
|
2021-12-11 12:49:05 +00:00
|
|
|
type: boolean
|
|
|
|
default: false
|
2021-07-06 13:57:15 +00:00
|
|
|
- variable: LDAP_TLS_VERIFY_CLIENT
|
|
|
|
label: "LDAP_TLS_VERIFY_CLIENT"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: "never"
|
|
|
|
- variable: LDAP_TLS_PROTOCOL_MIN
|
|
|
|
label: "LDAP_TLS_PROTOCOL_MIN"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: "3.0"
|
|
|
|
- variable: LDAP_TLS_CIPHER_SUITE
|
|
|
|
label: "LDAP_TLS_CIPHER_SUITE"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: "NORMAL"
|
|
|
|
- variable: LDAP_TLS_REQCERT
|
|
|
|
label: "LDAP_TLS_REQCERT"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: "never"
|
|
|
|
- variable: CONTAINER_LOG_LEVEL
|
|
|
|
label: "CONTAINER_LOG_LEVEL"
|
|
|
|
schema:
|
2021-12-11 12:49:05 +00:00
|
|
|
type: int
|
2021-07-06 13:57:15 +00:00
|
|
|
required: true
|
2021-12-11 12:49:05 +00:00
|
|
|
default: 4
|
2021-07-06 13:57:15 +00:00
|
|
|
- variable: KEEP_EXISTING_CONFIG
|
|
|
|
label: "KEEP_EXISTING_CONFIG"
|
|
|
|
schema:
|
2021-12-11 12:49:05 +00:00
|
|
|
type: boolean
|
|
|
|
default: false
|
2021-07-06 13:57:15 +00:00
|
|
|
- variable: LDAP_REMOVE_CONFIG_AFTER_SETUP
|
|
|
|
label: "LDAP_REMOVE_CONFIG_AFTER_SETUP"
|
|
|
|
schema:
|
2021-12-11 12:49:05 +00:00
|
|
|
type: boolean
|
|
|
|
default: true
|
2021-07-06 13:57:15 +00:00
|
|
|
- variable: LDAP_SSL_HELPER_PREFIX
|
|
|
|
label: "LDAP_SSL_HELPER_PREFIX"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: "ldap"
|
2021-08-31 19:07:44 +00:00
|
|
|
- variable: LDAP_BASE_DN
|
|
|
|
label: "LDAP_BASE_DN"
|
|
|
|
schema:
|
|
|
|
type: string
|
|
|
|
required: true
|
|
|
|
default: ""
|
2021-09-13 10:58:34 +00:00
|
|
|
# Include{containerConfig}
|
2022-08-08 21:25:02 +00:00
|
|
|
# Include{serviceRoot}
|
2021-07-06 13:57:15 +00:00
|
|
|
- variable: main
|
|
|
|
label: "Main Service"
|
|
|
|
description: "The Primary service on which the healthcheck runs, often the webUI"
|
|
|
|
schema:
|
2022-01-21 00:35:59 +00:00
|
|
|
additional_attrs: true
|
2021-07-06 13:57:15 +00:00
|
|
|
type: dict
|
|
|
|
attrs:
|
2022-09-17 11:24:06 +00:00
|
|
|
# Include{serviceSelectorLoadBalancer}
|
2022-09-14 21:27:12 +00:00
|
|
|
# Include{serviceSelectorExtras}
|
2021-07-06 13:57:15 +00:00
|
|
|
- variable: main
|
|
|
|
label: "Main Service Port Configuration"
|
|
|
|
schema:
|
2022-01-21 00:35:59 +00:00
|
|
|
additional_attrs: true
|
2021-07-06 13:57:15 +00:00
|
|
|
type: dict
|
|
|
|
attrs:
|
2021-11-14 14:32:48 +00:00
|
|
|
- variable: port
|
|
|
|
label: "Port"
|
|
|
|
description: "This port exposes the container port on the service"
|
|
|
|
schema:
|
|
|
|
type: int
|
|
|
|
default: 389
|
|
|
|
required: true
|
2022-08-08 21:25:02 +00:00
|
|
|
# Include{advancedPortTCP}
|
2021-11-06 23:32:56 +00:00
|
|
|
- variable: targetPort
|
|
|
|
label: "Target Port"
|
|
|
|
description: "The internal(!) port on the container the Application runs on"
|
|
|
|
schema:
|
|
|
|
type: int
|
|
|
|
default: 389
|
2021-07-06 13:57:15 +00:00
|
|
|
- variable: ldaps
|
|
|
|
label: "ldaps Service"
|
|
|
|
description: "The ldaps service"
|
|
|
|
schema:
|
2022-01-21 00:35:59 +00:00
|
|
|
additional_attrs: true
|
2021-07-06 13:57:15 +00:00
|
|
|
type: dict
|
|
|
|
attrs:
|
2022-09-17 11:24:06 +00:00
|
|
|
# Include{serviceSelectorLoadBalancer}
|
2022-09-14 21:27:12 +00:00
|
|
|
# Include{serviceSelectorExtras}
|
2021-11-08 14:18:49 +00:00
|
|
|
- variable: ldaps
|
|
|
|
label: "ldaps Service Port Configuration"
|
2021-07-06 13:57:15 +00:00
|
|
|
schema:
|
2022-01-21 00:35:59 +00:00
|
|
|
additional_attrs: true
|
2021-07-06 13:57:15 +00:00
|
|
|
type: dict
|
|
|
|
attrs:
|
2021-11-14 14:32:48 +00:00
|
|
|
- variable: port
|
|
|
|
label: "Port"
|
|
|
|
description: "This port exposes the container port on the service"
|
|
|
|
schema:
|
|
|
|
type: int
|
|
|
|
default: 636
|
|
|
|
required: true
|
2022-08-08 21:25:02 +00:00
|
|
|
# Include{advancedPortTCP}
|
2021-11-06 23:32:56 +00:00
|
|
|
- variable: targetPort
|
|
|
|
label: "Target Port"
|
|
|
|
description: "The internal(!) port on the container the Application runs on"
|
|
|
|
schema:
|
|
|
|
type: int
|
|
|
|
default: 636
|
2022-08-08 21:25:02 +00:00
|
|
|
# Include{serviceExpertRoot}
|
2021-09-13 16:49:14 +00:00
|
|
|
default: false
|
2021-10-05 10:50:21 +00:00
|
|
|
# Include{serviceExpert}
|
2021-09-13 10:58:34 +00:00
|
|
|
# Include{serviceList}
|
2022-08-08 21:25:02 +00:00
|
|
|
# Include{vctRoot}
|
2022-01-21 00:35:59 +00:00
|
|
|
additional_attrs: true
|
2021-07-06 13:57:15 +00:00
|
|
|
type: dict
|
|
|
|
attrs:
|
|
|
|
- variable: data
|
|
|
|
label: "App Data Storage"
|
|
|
|
description: "Stores the Application Data."
|
|
|
|
schema:
|
2022-01-21 00:35:59 +00:00
|
|
|
additional_attrs: true
|
2021-07-06 13:57:15 +00:00
|
|
|
type: dict
|
|
|
|
attrs:
|
2021-11-06 20:41:31 +00:00
|
|
|
# Include{persistenceBasic}
|
|
|
|
# Include{persistenceAdvanced}
|
2021-07-06 13:57:15 +00:00
|
|
|
- variable: slapd
|
2021-08-31 21:21:38 +00:00
|
|
|
label: "App slapd Storage"
|
2021-07-06 13:57:15 +00:00
|
|
|
description: "Stores the Application slapd."
|
|
|
|
schema:
|
2022-01-21 00:35:59 +00:00
|
|
|
additional_attrs: true
|
2021-07-06 13:57:15 +00:00
|
|
|
type: dict
|
|
|
|
attrs:
|
2021-11-06 20:41:31 +00:00
|
|
|
# Include{persistenceBasic}
|
|
|
|
# Include{persistenceAdvanced}
|
2021-09-13 10:58:34 +00:00
|
|
|
# Include{persistenceList}
|
2022-03-03 14:04:31 +00:00
|
|
|
# Include{security}
|
2022-08-08 21:25:02 +00:00
|
|
|
# Include{securityContextAdvancedRoot}
|
2021-11-06 20:41:31 +00:00
|
|
|
- variable: privileged
|
|
|
|
label: "Privileged mode"
|
|
|
|
schema:
|
|
|
|
type: boolean
|
|
|
|
default: false
|
|
|
|
- variable: readOnlyRootFilesystem
|
|
|
|
label: "ReadOnly Root Filesystem"
|
|
|
|
schema:
|
|
|
|
type: boolean
|
|
|
|
default: false
|
|
|
|
- variable: allowPrivilegeEscalation
|
|
|
|
label: "Allow Privilege Escalation"
|
|
|
|
schema:
|
|
|
|
type: boolean
|
|
|
|
default: false
|
|
|
|
- variable: runAsNonRoot
|
|
|
|
label: "runAsNonRoot"
|
|
|
|
schema:
|
|
|
|
type: boolean
|
|
|
|
default: false
|
2022-01-13 11:18:20 +00:00
|
|
|
# Include{securityContextAdvanced}
|
2022-08-08 21:25:02 +00:00
|
|
|
# Include{podSecurityContextRoot}
|
2021-09-26 18:05:21 +00:00
|
|
|
- variable: runAsUser
|
|
|
|
label: "runAsUser"
|
|
|
|
description: "The UserID of the user running the application"
|
|
|
|
schema:
|
|
|
|
type: int
|
|
|
|
default: 0
|
|
|
|
- variable: runAsGroup
|
|
|
|
label: "runAsGroup"
|
2022-04-20 07:35:54 +00:00
|
|
|
description: "The groupID this App of the user running the application"
|
2021-09-26 18:05:21 +00:00
|
|
|
schema:
|
|
|
|
type: int
|
|
|
|
default: 0
|
|
|
|
- variable: fsGroup
|
|
|
|
label: "fsGroup"
|
|
|
|
description: "The group that should own ALL storage."
|
|
|
|
schema:
|
|
|
|
type: int
|
|
|
|
default: 568
|
2022-01-13 11:18:20 +00:00
|
|
|
# Include{podSecurityContextAdvanced}
|
2021-09-26 18:44:02 +00:00
|
|
|
# Include{resources}
|
2021-10-04 11:46:38 +00:00
|
|
|
# Include{advanced}
|
2021-09-13 10:58:34 +00:00
|
|
|
# Include{addons}
|
2022-08-12 11:15:27 +00:00
|
|
|
# Include{documentation}
|