-
Notifications
You must be signed in to change notification settings - Fork 3
/
Copy pathvalues-openshift-gitops.yaml
86 lines (81 loc) · 2.35 KB
/
values-openshift-gitops.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
---
# Configure openshift-gitops operator. This will be enabled via init_GitOps.sh script
gitopsinstances:
openshift_gitops:
enabled: true
namespace: openshift-gitops
clusterAdmin: disabled
global_project:
enabled: false
syncwave: 10
server:
route:
enabled: true
generic_config:
disableAdmin: true
resourceTrackingMethod: annotation
kustomizeBuildOptions: "--enable-helm"
appset: {}
repo: {}
controller: {}
sso:
dex:
openShiftOAuth: true
ha: {}
redis: {}
rbac:
defaultRole: 'role:none'
policy: |-
# Access Control
g, system:cluster-admins, role:admin
g, cluster-admin, role:admin
p, role:none, applications, get, */*, deny
p, role:none, certificates, get, *, deny
p, role:none, clusters, get, *, deny
p, role:none, repositories, get, *, deny
p, role:none, projects, get, *, deny
p, role:none, accounts, get, *, deny
p, role:none, gpgkeys, get, *, deny
scopes: '[groups]'
resourceExclusions: |-
# resources to be excluded
- apiGroups:
- tekton.dev
clusters:
- '*'
kinds:
- TaskRun
- PipelineRun
# Enable default health checks.
# This will create some default health checks I usually add.
# * ClusterLogging, * Application (Argo CD), * Lokistack, * Subcription, * Central (ACS), InstallPlan
default_resourceHealthChecks: true
# Deploy openshift-gitops operator. This will be enabled via init_GitOps.sh script
helper-operator:
enabled: false
operators:
openshift-gitops-operator:
enabled: true
syncwave: '0'
namespace:
name: openshift-gitops-operator
create: true
subscription:
channel: latest
approval: Automatic
operatorName: openshift-gitops-operator
source: redhat-operators
sourceNamespace: openshift-marketplace
operatorgroup:
create: true
notownnamespace: true
# Deploy openshift-gitops operator. This will be enabled via init_GitOps.sh script
helper-status-checker:
enabled: false
checks:
- operatorName: openshift-gitops-operator
namespace:
name: openshift-gitops-operator
syncwave: 3
serviceAccount:
name: "status-checker-gitops"