Secrets
This table was generated from secrets.yaml.
Cells marked with "—" mean "not specified in schema".
alerts
¶
Configure secrets for alerting.
Key | Type | Default | Description |
---|---|---|---|
alerts. |
object | — | Configure secrets for alerting with OpsGenie. |
alerts. |
— | — | — |
alerts. |
object | — | Configure secrets for alerting with Slack. |
alerts. |
string | — | — |
dex
¶
Configure secrets for Dex.
Key | Type | Default | Description |
---|---|---|---|
dex. |
array of object | — | See note |
dex. |
array of object | — | See note |
dex. |
array of object | — | Configure additional static logins for Dex. Additional static logins for Dex. |
dex. |
string | — | — |
dex. |
string | — | — |
Notes for dex.additionalStaticClients[]
Configure additional static clients in Dex.
Clients in this case is application that wants to allow users to authenticate via Dex.
Note
See the upstream documentation for reference.
Configure an additional static client in Dex.
Notes for dex.connectors[]
Configure upstream Identity Providers.
Note
See the upstream documentation for reference.
Configure an upstream Identity Provider.
externalDns
¶
Configure secrets for External DNS.
Key | Type | Default | Description |
---|---|---|---|
externalDns. |
object | — | Configure AWS Route 53 secrets for External DNS. |
externalDns. |
string | — | — |
externalDns. |
string | — | — |
fluentd
¶
Secret configuration options for Fluentd.
Key | Type | Default | Description |
---|---|---|---|
fluentd. |
object | — | Configuration options for using object storage specific to Fluentd. |
fluentd. |
object | — | Secrets for using S3 as object storage in Welkin. |
fluentd. |
string | — | Access key to authenticate with. |
fluentd. |
string | — | Secret key to authenticate with. |
grafana
¶
Configure secrets for Grafana.
Key | Type | Default | Description |
---|---|---|---|
grafana. |
string | — | — |
grafana. |
object | — | Configure secrets for Admin Grafana. |
grafana. |
array | — | — |
grafana. |
string | — | — |
grafana. |
string | — | — |
grafana. |
object | — | Configure secrets for Dev Grafana. |
grafana. |
array | — | — |
harbor
¶
Secret configuration options for Harbor.
Key | Type | Default | Description |
---|---|---|---|
harbor. |
string | — | — |
harbor. |
string | — | — |
harbor. |
object | — | External database password config. |
harbor. |
string | — | — |
harbor. |
object | — | Internal database password config. |
harbor. |
string | — | — |
harbor. |
string | — | — |
harbor. |
object | — | Configuration options for using object storage specific to harbor. |
harbor. |
object | — | Secrets for using S3 as object storage in Welkin. |
harbor. |
string | — | Access key to authenticate with. |
harbor. |
string | — | Secret key to authenticate with. |
harbor. |
string | — | — |
harbor. |
string | — | — |
harbor. |
string | — | — |
issuers
¶
Configure secrets for issuers.
Notes for issuers.secrets
Configure secrets for issuers.
This must match the configuration set on the issuers.
Keys become the name of the secret, and the value the data of the secret.
kubeapiMetricsPassword
¶
None
Key | Type | Default | Description |
---|---|---|---|
kured
¶
Notification secrets for Kured (Kubernetes Reboot Daemon).
Key | Type | Default | Description |
---|---|---|---|
kured. |
object | — | Notification secrets to send notifications from Kured to Slack. |
kured. |
string | — | — |
objectStorage
¶
Configuration options for using object storage in Welkin.
Key | Type | Default | Description |
---|---|---|---|
objectStorage. |
object | — | Secrets for using Azure as object storage in Welkin. |
objectStorage. |
string | — | Storage account key to authenticate with. |
objectStorage. |
string | — | Storage account name to authenticate with. |
objectStorage. |
object | — | Secrets for restoring object storage from a secondary site to the primary site with Rclone. |
objectStorage. |
object | — | Secrets for encrypt data when syncing. |
objectStorage. |
string | — | Crypt password, generate with pwgen 32 1 . |
objectStorage. |
string | — | Obscured crypt password, generate with rclone obscure <password> . |
objectStorage. |
string | — | Crypt salt, generate with pwgen 32 1 . |
objectStorage. |
string | — | Obscured crypt salt, generate with rclone obscure <salt> . |
objectStorage. |
object | — | Allows for complete or partial overrides of the destinations of the restore, the main object storage configuration. |
objectStorage. |
object | — | Secrets for using Azure as object storage in Welkin. |
objectStorage. |
string | — | Storage account key to authenticate with. |
objectStorage. |
string | — | Storage account name to authenticate with. |
objectStorage. |
object | — | Secrets for using S3 as object storage in Welkin. |
objectStorage. |
string | — | Access key to authenticate with. |
objectStorage. |
string | — | Secret key to authenticate with. |
objectStorage. |
object | — | See note |
objectStorage. |
string | — | Application Credential ID to authenticate with. |
objectStorage. |
string | — | Application Credential Name to authenticate with, requires username to be set. |
objectStorage. |
string | — | Application Credential Secret to authenticate with, requires username to be set. |
objectStorage. |
string | — | — |
objectStorage. |
string | — | — |
objectStorage. |
object | — | Allows for complete or partial overrides of the sources of the restore, the sync object storage configuration. |
objectStorage. |
object | — | Secrets for using Azure as object storage in Welkin. |
objectStorage. |
string | — | Storage account key to authenticate with. |
objectStorage. |
string | — | Storage account name to authenticate with. |
objectStorage. |
object | — | Secrets for using S3 as object storage in Welkin. |
objectStorage. |
string | — | Access key to authenticate with. |
objectStorage. |
string | — | Secret key to authenticate with. |
objectStorage. |
object | — | See note |
objectStorage. |
string | — | Application Credential ID to authenticate with. |
objectStorage. |
string | — | Application Credential Name to authenticate with, requires username to be set. |
objectStorage. |
string | — | Application Credential Secret to authenticate with, requires username to be set. |
objectStorage. |
string | — | — |
objectStorage. |
string | — | — |
objectStorage. |
object | — | Secrets for using S3 as object storage in Welkin. |
objectStorage. |
string | — | Access key to authenticate with. |
objectStorage. |
string | — | Secret key to authenticate with. |
objectStorage. |
object | — | See note |
objectStorage. |
string | — | Application Credential ID to authenticate with. |
objectStorage. |
string | — | Application Credential Name to authenticate with, requires username to be set. |
objectStorage. |
string | — | Application Credential Secret to authenticate with, requires username to be set. |
objectStorage. |
string | — | — |
objectStorage. |
string | — | — |
objectStorage. |
object | — | Secrets for syncing object storage from the primary site to a secondary site with Rclone. |
objectStorage. |
object | — | Secrets for using Azure as object storage in Welkin. |
objectStorage. |
string | — | Storage account key to authenticate with. |
objectStorage. |
string | — | Storage account name to authenticate with. |
objectStorage. |
object | — | Secrets for encrypt data when syncing. |
objectStorage. |
string | — | Crypt password, generate with pwgen 32 1 . |
objectStorage. |
string | — | Obscured crypt password, generate with rclone obscure <password> . |
objectStorage. |
string | — | Crypt salt, generate with pwgen 32 1 . |
objectStorage. |
string | — | Obscured crypt salt, generate with rclone obscure <salt> . |
objectStorage. |
object | — | Secrets for using S3 as object storage in Welkin. |
objectStorage. |
string | — | Access key to authenticate with. |
objectStorage. |
string | — | Secret key to authenticate with. |
objectStorage. |
object | — | See note |
objectStorage. |
string | — | Application Credential ID to authenticate with. |
objectStorage. |
string | — | Application Credential Name to authenticate with, requires username to be set. |
objectStorage. |
string | — | Application Credential Secret to authenticate with, requires username to be set. |
objectStorage. |
string | — | — |
objectStorage. |
string | — | — |
Notes for objectStorage.restore.destinations.swift
Secrets for using Swift as object storage in Welkin.
Important
Currently Harbor only supports username
and password
authentication.
Notes for objectStorage.restore.sources.swift
Secrets for using Swift as object storage in Welkin.
Important
Currently Harbor only supports username
and password
authentication.
Notes for objectStorage.swift
Secrets for using Swift as object storage in Welkin.
Important
Currently Harbor only supports username
and password
authentication.
Notes for objectStorage.sync.swift
Secrets for using Swift as object storage in Welkin.
Important
Currently Harbor only supports username
and password
authentication.
opensearch
¶
Secrets for OpenSearch.
Key | Type | Default | Description |
---|---|---|---|
opensearch. |
string | — | — |
opensearch. |
string | — | — |
opensearch. |
string | — | — |
opensearch. |
string | — | — |
opensearch. |
string | — | — |
opensearch. |
string | — | — |
opensearch. |
string | — | — |
opensearch. |
string | — | — |
opensearch. |
string | — | — |
opensearch. |
array of object | — | See note |
opensearch. |
string | — | — |
opensearch. |
string | — | — |
opensearch. |
object | — | Configuration options for using object storage specific to opensearch. |
opensearch. |
object | — | Secrets for using S3 as object storage in Welkin. |
opensearch. |
string | — | Access key to authenticate with. |
opensearch. |
string | — | Secret key to authenticate with. |
opensearch. |
string | — | — |
Notes for opensearch.extraUsers[]
Configures extra users for OpenSearch Security.
Configures extra user for OpenSearch Security.
Note
See the upstream documentation for reference.
thanos
¶
Secrets for Thanos.
Key | Type | Default | Description |
---|---|---|---|
thanos. |
object | — | Configuration options for using object storage specific to thanos. |
thanos. |
object | — | Secrets for using S3 as object storage in Welkin. |
thanos. |
string | — | Access key to authenticate with. |
thanos. |
string | — | Secret key to authenticate with. |
thanos. |
object | — | Secrets for Thanos Receiver. |
thanos. |
object | — | Configure authentication to Thanos Receiver, |
thanos. |
string | — | Configure the password for authenticating to Thanos Receiver. |
user
¶
Admin password for user Grafana and user Alertmanager.
velero
¶
Secret configuration options for Velero.
Key | Type | Default | Description |
---|---|---|---|
velero. |
object | — | Configuration options for using object storage specific to Velero. |
velero. |
object | — | Secrets for using S3 as object storage in Welkin. |
velero. |
string | — | Access key to authenticate with. |
velero. |
string | — | Secret key to authenticate with. |