Big Bang values.yaml
📜
domain📜
Type: string
"bigbang.dev"
Description: Domain used for BigBang created exposed services, can be overridden by individual packages.
offline📜
Type: bool
false
Description: (experimental) Toggle sourcing from external repos. All this does right now is toggle GitRepositories, it is not fully functional
helmRepositories📜
Type: list
[]
Default value (formatted)
[]
Description: List of Helm repositories/credentials to pull helm charts from. OCI Type: Must specify username/password or existingSecret if repository requires auth. Using “private-registry” for existingSecret will reuse credentials from registryCredentials above. Default Type: Must specify existingSecret with auth - see https://fluxcd.io/flux/components/source/helmrepositories/#secret-reference for details on secret data required.
registryCredentials📜
Type: object
{"email":"","password":"","registry":"registry1.dso.mil","username":""}
Default value (formatted)
{
"email": "",
"password": "",
"registry": "registry1.dso.mil",
"username": ""
}
Description: Single set of registry credentials used to pull all images deployed by BigBang.
openshift📜
Type: bool
false
Description: Multiple sets of registry credentials used to pull all images deployed by BigBang. Credentials will only be created when a valid combination exists, registry, username, and password (email is optional) Or a list of registires: - registry: registry1.dso.mil username: “” password: “” email: “” - registry: registry.dso.mil username: “” password: “” email: “” Openshift Container Platform Feature Toggle
git📜
Type: object
{"credentials":{"caFile":"","knownHosts":"","password":"","privateKey":"","publicKey":"","username":""},"existingSecret":""}
Default value (formatted)
{
"credentials": {
"caFile": "",
"knownHosts": "",
"password": "",
"privateKey": "",
"publicKey": "",
"username": ""
},
"existingSecret": ""
}
Description: Git credential settings for accessing private repositories Order of precedence is: 1. existingSecret 2. http credentials (username/password/caFile) 3. ssh credentials (privateKey/publicKey/knownHosts)
git.existingSecret📜
Type: string
""
Description: Existing secret to use for git credentials, must be in the appropriate format: https://toolkit.fluxcd.io/components/source/gitrepositories/#https-authentication
git.credentials📜
Type: object
{"caFile":"","knownHosts":"","password":"","privateKey":"","publicKey":"","username":""}
Default value (formatted)
{
"caFile": "",
"knownHosts": "",
"password": "",
"privateKey": "",
"publicKey": "",
"username": ""
}
Description: Chart created secrets with user defined values
git.credentials.username📜
Type: string
""
Description: HTTP git credentials, both username and password must be provided
git.credentials.caFile📜
Type: string
""
Description: HTTPS certificate authority file. Required for any repo with a self signed certificate
git.credentials.privateKey📜
Type: string
""
Description: SSH git credentials, privateKey, publicKey, and knownHosts must be provided
sso📜
Type: object
{"certificateAuthority":{"cert":"","secretName":"tls-ca-sso"},"name":"SSO","oidc":{"authorization":"{{ .Values.sso.url }}/protocol/openid-connect/auth","claims":{"email":"email","groups":"groups","name":"name","username":"preferred_username"},"endSession":"{{ .Values.sso.url }}/protocol/openid-connect/logout","jwks":"","jwksUri":"{{ .Values.sso.url }}/protocol/openid-connect/certs","token":"{{ .Values.sso.url }}/protocol/openid-connect/token","userinfo":"{{ .Values.sso.url }}/protocol/openid-connect/userinfo"},"saml":{"entityDescriptor":"{{ .Values.sso.url }}/protocol/saml/descriptor","metadata":"","service":"{{ .Values.sso.url }}/protocol/saml"},"url":"https://login.dso.mil/auth/realms/baby-yoda"}
Default value (formatted)
{
"certificateAuthority": {
"cert": "",
"secretName": "tls-ca-sso"
},
"name": "SSO",
"oidc": {
"authorization": "{{ .Values.sso.url }}/protocol/openid-connect/auth",
"claims": {
"email": "email",
"groups": "groups",
"name": "name",
"username": "preferred_username"
},
"endSession": "{{ .Values.sso.url }}/protocol/openid-connect/logout",
"jwks": "",
"jwksUri": "{{ .Values.sso.url }}/protocol/openid-connect/certs",
"token": "{{ .Values.sso.url }}/protocol/openid-connect/token",
"userinfo": "{{ .Values.sso.url }}/protocol/openid-connect/userinfo"
},
"saml": {
"entityDescriptor": "{{ .Values.sso.url }}/protocol/saml/descriptor",
"metadata": "",
"service": "{{ .Values.sso.url }}/protocol/saml"
},
"url": "https://login.dso.mil/auth/realms/baby-yoda"
}
Description: Global SSO values used for BigBang deployments when sso is enabled
sso.name📜
Type: string
"SSO"
Description: Name of the identity provider. This is used by some packages as the SSO login label.
sso.url📜
Type: string
"https://login.dso.mil/auth/realms/baby-yoda"
Description: Base URL for the identity provider. For OIDC, this is the issuer. For SAML this is the entityID.
sso.certificateAuthority📜
Type: object
{"cert":"","secretName":"tls-ca-sso"}
Default value (formatted)
{
"cert": "",
"secretName": "tls-ca-sso"
}
Description: Certificate authority for the identity provider’s certificates
sso.certificateAuthority.cert📜
Type: string
""
Description: The certificate authority public certificate in .pem format. Populating this will create a secret in each namespace that enables SSO.
sso.certificateAuthority.secretName📜
Type: string
"tls-ca-sso"
Description: The secret name to use for the certificate authority. Can be manually populated if cert is blank.
sso.saml.entityDescriptor📜
Type: string
"{{ .Values.sso.url }}/protocol/saml/descriptor"
Description: SAML entityDescriptor (metadata) path
sso.saml.service📜
Type: string
"{{ .Values.sso.url }}/protocol/saml"
Description: SAML SSO Service path
sso.saml.metadata📜
Type: string
""
Description: Literal SAML XML metadata retrieved from {{ .Values.sso.saml.entityDescriptor }}
. Required for SSO in Nexus, Twistlock, or Sonarqube.
sso.oidc📜
Type: object
{"authorization":"{{ .Values.sso.url }}/protocol/openid-connect/auth","claims":{"email":"email","groups":"groups","name":"name","username":"preferred_username"},"endSession":"{{ .Values.sso.url }}/protocol/openid-connect/logout","jwks":"","jwksUri":"{{ .Values.sso.url }}/protocol/openid-connect/certs","token":"{{ .Values.sso.url }}/protocol/openid-connect/token","userinfo":"{{ .Values.sso.url }}/protocol/openid-connect/userinfo"}
Default value (formatted)
{
"authorization": "{{ .Values.sso.url }}/protocol/openid-connect/auth",
"claims": {
"email": "email",
"groups": "groups",
"name": "name",
"username": "preferred_username"
},
"endSession": "{{ .Values.sso.url }}/protocol/openid-connect/logout",
"jwks": "",
"jwksUri": "{{ .Values.sso.url }}/protocol/openid-connect/certs",
"token": "{{ .Values.sso.url }}/protocol/openid-connect/token",
"userinfo": "{{ .Values.sso.url }}/protocol/openid-connect/userinfo"
}
Description: OIDC endpoints can be retrieved from {{ .Values.sso.url }}/.well-known/openid-configuration
sso.oidc.authorization📜
Type: string
"{{ .Values.sso.url }}/protocol/openid-connect/auth"
Description: OIDC authorization path
sso.oidc.endSession📜
Type: string
"{{ .Values.sso.url }}/protocol/openid-connect/logout"
Description: OIDC logout / end session path
sso.oidc.jwksUri📜
Type: string
"{{ .Values.sso.url }}/protocol/openid-connect/certs"
Description: OIDC JSON Web Key Set (JWKS) path
sso.oidc.token📜
Type: string
"{{ .Values.sso.url }}/protocol/openid-connect/token"
Description: OIDC token path
sso.oidc.userinfo📜
Type: string
"{{ .Values.sso.url }}/protocol/openid-connect/userinfo"
Description: OIDC user information path
sso.oidc.jwks📜
Type: string
""
Description: Literal OIDC JWKS data retrieved from JWKS Uri. Only needed if jwsksUri
is not defined.
sso.oidc.claims📜
Type: object
{"email":"email","groups":"groups","name":"name","username":"preferred_username"}
Default value (formatted)
{
"email": "email",
"groups": "groups",
"name": "name",
"username": "preferred_username"
}
Description: Identity provider claim names that store metadata about the authenticated user.
sso.oidc.claims.email📜
Type: string
"email"
Description: IdP’s claim name used for the user’s email address.
sso.oidc.claims.name📜
Type: string
"name"
Description: IdP’s claim name used for the user’s full name
sso.oidc.claims.username📜
Type: string
"preferred_username"
Description: IdP’s claim name used for the username
sso.oidc.claims.groups📜
Type: string
"groups"
Description: IdP’s claim name used for the user’s groups or roles
flux📜
Type: object
{"install":{"remediation":{"retries":-1}},"interval":"2m","rollback":{"cleanupOnFail":true,"timeout":"10m"},"test":{"enable":false},"timeout":"10m","upgrade":{"cleanupOnFail":true,"remediation":{"remediateLastFailure":true,"retries":3}}}
Default value (formatted)
{
"install": {
"remediation": {
"retries": -1
}
},
"interval": "2m",
"rollback": {
"cleanupOnFail": true,
"timeout": "10m"
},
"test": {
"enable": false
},
"timeout": "10m",
"upgrade": {
"cleanupOnFail": true,
"remediation": {
"remediateLastFailure": true,
"retries": 3
}
}
}
Description: (Advanced) Flux reconciliation parameters. The default values provided will be sufficient for the majority of workloads.
networkPolicies📜
Type: object
{"controlPlaneCidr":"0.0.0.0/0","enabled":true,"nodeCidr":"","vpcCidr":"0.0.0.0/0"}
Default value (formatted)
{
"controlPlaneCidr": "0.0.0.0/0",
"enabled": true,
"nodeCidr": "",
"vpcCidr": "0.0.0.0/0"
}
Description: Global NetworkPolicies settings
networkPolicies.enabled📜
Type: bool
true
Description: Toggle all package NetworkPolicies, can disable specific packages with package.values.networkPolicies.enabled
networkPolicies.controlPlaneCidr📜
Type: string
"0.0.0.0/0"
Description: Control Plane CIDR, defaults to 0.0.0.0/0, use kubectl get endpoints -n default kubernetes
to get the CIDR range needed for your cluster Must be an IP CIDR range (x.x.x.x/x - ideally with /32 for the specific IP of a single endpoint, broader range for multiple masters/endpoints) Used by package NetworkPolicies to allow Kube API access
networkPolicies.nodeCidr📜
Type: string
""
Description: Node CIDR, defaults to allowing “10.0.0.0/8” “172.16.0.0/12” “192.168.0.0/16” “100.64.0.0/10” networks. use kubectl get nodes -owide
and review the INTERNAL-IP
column to derive CIDR range. Must be an IP CIDR range (x.x.x.x/x - ideally a /16 or /24 to include multiple IPs)
networkPolicies.vpcCidr📜
Type: string
"0.0.0.0/0"
Description: VPC CIDR, defaults to 0.0.0.0/0 In a production environment, it is recommended to setup a Private Endpoint for your AWS services like KMS or S3. Please review https://docs.aws.amazon.com/kms/latest/developerguide/kms-vpc-endpoint.html to setup routing to AWS services that never leave the AWS network. Once created update networkPolicies.vpcCidr
to match the CIDR of your VPC so Vault will be able to reach your VPCs DNS and new KMS endpoint.
imagePullPolicy📜
Type: string
"IfNotPresent"
Description: Global ImagePullPolicy value for all packages Permitted values are: None, Always, IfNotPresent
istio.enabled📜
Type: bool
true
Description: Toggle deployment of Istio.
istio.mtls.mode📜
Type: string
"STRICT"
Description: STRICT = Allow only mutual TLS traffic, PERMISSIVE = Allow both plain text and mutual TLS traffic
istio.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
istio.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/istio-controlplane.git"
istio.git.path📜
Type: string
"./chart"
istio.git.tag📜
Type: string
"1.19.6-bb.2"
istio.helmRepo.repoName📜
Type: string
"registry1"
istio.helmRepo.chartName📜
Type: string
"istio"
istio.helmRepo.tag📜
Type: string
"1.19.6-bb.2"
istio.enterprise📜
Type: bool
false
Description: Tetrate Istio Distribution - Tetrate provides FIPs verified Istio and Envoy software and support, validated through the FIPs Boring Crypto module. Find out more from Tetrate - https://www.tetrate.io/tetrate-istio-subscription
istio.ingressGateways.public-ingressgateway.type📜
Type: string
"LoadBalancer"
istio.ingressGateways.public-ingressgateway.kubernetesResourceSpec📜
Type: object
{}
Default value (formatted)
{}
istio.gateways.public.ingressGateway📜
Type: string
"public-ingressgateway"
istio.gateways.public.hosts[0]📜
Type: string
"*.{{ .Values.domain }}"
istio.gateways.public.autoHttpRedirect📜
Type: object
{"enabled":true}
Default value (formatted)
{
"enabled": true
}
Description: Controls default HTTP/8080 server entry with HTTP to HTTPS Redirect.
istio.gateways.public.tls.key📜
Type: string
""
istio.gateways.public.tls.cert📜
Type: string
""
istio.gateways.public.tls.minProtocolVersion📜
Type: string
""
istio.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Istio Package
istio.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the istio-controlplane chart: https://repo1.dso.mil/big-bang/product/packages/istio-controlplane.git
istio.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
istioOperator.enabled📜
Type: bool
true
Description: Toggle deployment of Istio Operator.
istioOperator.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
istioOperator.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/istio-operator.git"
istioOperator.git.path📜
Type: string
"./chart"
istioOperator.git.tag📜
Type: string
"1.19.6-bb.0"
istioOperator.helmRepo.repoName📜
Type: string
"registry1"
istioOperator.helmRepo.chartName📜
Type: string
"istio-operator"
istioOperator.helmRepo.tag📜
Type: string
"1.19.6-bb.0"
istioOperator.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Istio Operator Package
istioOperator.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the istio-operator chart: https://repo1.dso.mil/big-bang/product/packages/istio-operator.git
istioOperator.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
jaeger.enabled📜
Type: bool
false
Description: Toggle deployment of Jaeger.
jaeger.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
jaeger.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/jaeger.git"
jaeger.git.path📜
Type: string
"./chart"
jaeger.git.tag📜
Type: string
"2.50.1-bb.0"
jaeger.helmRepo.repoName📜
Type: string
"registry1"
jaeger.helmRepo.chartName📜
Type: string
"jaeger"
jaeger.helmRepo.tag📜
Type: string
"2.50.1-bb.0"
jaeger.flux📜
Type: object
{"install":{"crds":"CreateReplace"},"upgrade":{"crds":"CreateReplace"}}
Default value (formatted)
{
"install": {
"crds": "CreateReplace"
},
"upgrade": {
"crds": "CreateReplace"
}
}
Description: Flux reconciliation overrides specifically for the Jaeger Package
jaeger.ingress📜
Type: object
{"gateway":""}
Default value (formatted)
{
"gateway": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
jaeger.sso.enabled📜
Type: bool
false
Description: Toggle SSO for Jaeger on and off
jaeger.sso.client_id📜
Type: string
""
Description: OIDC Client ID to use for Jaeger
jaeger.sso.client_secret📜
Type: string
""
Description: OIDC Client Secret to use for Jaeger
jaeger.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to pass through to Jaeger chart: https://repo1.dso.mil/big-bang/product/packages/jaeger.git
jaeger.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
kiali.enabled📜
Type: bool
true
Description: Toggle deployment of Kiali.
kiali.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
kiali.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/kiali.git"
kiali.git.path📜
Type: string
"./chart"
kiali.git.tag📜
Type: string
"1.78.0-bb.5"
kiali.helmRepo.repoName📜
Type: string
"registry1"
kiali.helmRepo.chartName📜
Type: string
"kiali"
kiali.helmRepo.tag📜
Type: string
"1.78.0-bb.5"
kiali.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Kiali Package
kiali.ingress📜
Type: object
{"gateway":""}
Default value (formatted)
{
"gateway": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
kiali.sso.enabled📜
Type: bool
false
Description: Toggle SSO for Kiali on and off
kiali.sso.client_id📜
Type: string
""
Description: OIDC Client ID to use for Kiali
kiali.sso.client_secret📜
Type: string
""
Description: OIDC Client Secret to use for Kiali
kiali.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to pass through to Kiali chart: https://repo1.dso.mil/big-bang/product/packages/kiali
kiali.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
clusterAuditor.enabled📜
Type: bool
false
Description: Toggle deployment of Cluster Auditor.
clusterAuditor.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
clusterAuditor.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/cluster-auditor.git"
clusterAuditor.git.path📜
Type: string
"./chart"
clusterAuditor.git.tag📜
Type: string
"1.5.0-bb.14"
clusterAuditor.helmRepo.repoName📜
Type: string
"registry1"
clusterAuditor.helmRepo.chartName📜
Type: string
"cluster-auditor"
clusterAuditor.helmRepo.tag📜
Type: string
"1.5.0-bb.14"
clusterAuditor.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Cluster Auditor Package
clusterAuditor.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the cluster auditor chart: https://repo1.dso.mil/big-bang/product/packages/cluster-auditor.git
clusterAuditor.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
gatekeeper.enabled📜
Type: bool
false
Description: Toggle deployment of OPA Gatekeeper.
gatekeeper.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
gatekeeper.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/policy.git"
gatekeeper.git.path📜
Type: string
"./chart"
gatekeeper.git.tag📜
Type: string
"3.15.0-bb.0"
gatekeeper.helmRepo.repoName📜
Type: string
"registry1"
gatekeeper.helmRepo.chartName📜
Type: string
"gatekeeper"
gatekeeper.helmRepo.tag📜
Type: string
"3.15.0-bb.0"
gatekeeper.flux📜
Type: object
{"install":{"crds":"CreateReplace"},"upgrade":{"crds":"CreateReplace"}}
Default value (formatted)
{
"install": {
"crds": "CreateReplace"
},
"upgrade": {
"crds": "CreateReplace"
}
}
Description: Flux reconciliation overrides specifically for the OPA Gatekeeper Package
gatekeeper.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the gatekeeper chart: https://repo1.dso.mil/big-bang/product/packages/policy.git
gatekeeper.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
kyverno.enabled📜
Type: bool
true
Description: Toggle deployment of Kyverno.
kyverno.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
kyverno.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/kyverno.git"
kyverno.git.path📜
Type: string
"./chart"
kyverno.git.tag📜
Type: string
"3.1.4-bb.2"
kyverno.helmRepo.repoName📜
Type: string
"registry1"
kyverno.helmRepo.chartName📜
Type: string
"kyverno"
kyverno.helmRepo.tag📜
Type: string
"3.1.4-bb.2"
kyverno.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Kyverno Package
kyverno.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the kyverno chart: https://repo1.dso.mil/big-bang/product/packages/kyverno.git
kyverno.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
kyvernoPolicies.enabled📜
Type: bool
true
Description: Toggle deployment of Kyverno policies
kyvernoPolicies.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
kyvernoPolicies.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/kyverno-policies.git"
kyvernoPolicies.git.path📜
Type: string
"./chart"
kyvernoPolicies.git.tag📜
Type: string
"3.0.4-bb.24"
kyvernoPolicies.helmRepo.repoName📜
Type: string
"registry1"
kyvernoPolicies.helmRepo.chartName📜
Type: string
"kyverno-policies"
kyvernoPolicies.helmRepo.tag📜
Type: string
"3.0.4-bb.24"
kyvernoPolicies.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Kyverno Package
kyvernoPolicies.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the kyverno policies chart: https://repo1.dso.mil/big-bang/product/packages/kyverno-policies.git
kyvernoPolicies.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
kyvernoReporter.enabled📜
Type: bool
true
Description: Toggle deployment of Kyverno Reporter
kyvernoReporter.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
kyvernoReporter.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/kyverno-reporter.git"
kyvernoReporter.git.path📜
Type: string
"./chart"
kyvernoReporter.git.tag📜
Type: string
"2.22.0-bb.0"
kyvernoReporter.helmRepo.repoName📜
Type: string
"registry1"
kyvernoReporter.helmRepo.chartName📜
Type: string
"kyverno-reporter"
kyvernoReporter.helmRepo.tag📜
Type: string
"2.22.0-bb.0"
kyvernoReporter.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Kyverno Reporter Package
kyvernoReporter.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the kyverno reporter chart: https://repo1.dso.mil/big-bang/product/packages/kyverno-reporter.git
kyvernoReporter.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
elasticsearchKibana.enabled📜
Type: bool
false
Description: Toggle deployment of Logging (EFK).
elasticsearchKibana.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
elasticsearchKibana.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/elasticsearch-kibana.git"
elasticsearchKibana.git.path📜
Type: string
"./chart"
elasticsearchKibana.git.tag📜
Type: string
"1.10.0-bb.3"
elasticsearchKibana.helmRepo.repoName📜
Type: string
"registry1"
elasticsearchKibana.helmRepo.chartName📜
Type: string
"elasticsearch-kibana"
elasticsearchKibana.helmRepo.tag📜
Type: string
"1.10.0-bb.3"
elasticsearchKibana.flux📜
Type: object
{"timeout":"20m"}
Default value (formatted)
{
"timeout": "20m"
}
Description: Flux reconciliation overrides specifically for the Logging (EFK) Package
elasticsearchKibana.ingress📜
Type: object
{"gateway":""}
Default value (formatted)
{
"gateway": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
elasticsearchKibana.sso.enabled📜
Type: bool
false
Description: Toggle OIDC SSO for Kibana/Elasticsearch on and off. Enabling this option will auto-create any required secrets.
elasticsearchKibana.sso.client_id📜
Type: string
""
Description: Elasticsearch/Kibana OIDC client ID
elasticsearchKibana.sso.client_secret📜
Type: string
""
Description: Elasticsearch/Kibana OIDC client secret
elasticsearchKibana.license.trial📜
Type: bool
false
Description: Toggle trial license installation of elasticsearch. Note that enterprise (non trial) is required for SSO to work.
elasticsearchKibana.license.keyJSON📜
Type: string
""
Description: Elasticsearch license in json format seen here: https://repo1.dso.mil/big-bang/product/packages/elasticsearch-kibana#enterprise-license
elasticsearchKibana.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the elasticsearch-kibana chart: https://repo1.dso.mil/big-bang/product/packages/elasticsearch-kibana.git
elasticsearchKibana.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
eckOperator.enabled📜
Type: bool
false
Description: Toggle deployment of ECK Operator.
eckOperator.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
eckOperator.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/eck-operator.git"
eckOperator.git.path📜
Type: string
"./chart"
eckOperator.git.tag📜
Type: string
"2.11.1-bb.0"
eckOperator.helmRepo.repoName📜
Type: string
"registry1"
eckOperator.helmRepo.chartName📜
Type: string
"eck-operator"
eckOperator.helmRepo.tag📜
Type: string
"2.11.1-bb.0"
eckOperator.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the ECK Operator Package
eckOperator.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the eck-operator chart: https://repo1.dso.mil/big-bang/product/packages/eck-operator.git
eckOperator.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
fluentbit.enabled📜
Type: bool
false
Description: Toggle deployment of Fluent-Bit.
fluentbit.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
fluentbit.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/fluentbit.git"
fluentbit.git.path📜
Type: string
"./chart"
fluentbit.git.tag📜
Type: string
"0.43.0-bb.1"
fluentbit.helmRepo.repoName📜
Type: string
"registry1"
fluentbit.helmRepo.chartName📜
Type: string
"fluentbit"
fluentbit.helmRepo.tag📜
Type: string
"0.43.0-bb.1"
fluentbit.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Fluent-Bit Package
fluentbit.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the fluentbit chart: https://repo1.dso.mil/big-bang/product/packages/fluentbit.git
fluentbit.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
promtail.enabled📜
Type: bool
true
Description: Toggle deployment of Promtail.
promtail.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
promtail.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/promtail.git"
promtail.git.path📜
Type: string
"./chart"
promtail.git.tag📜
Type: string
"6.15.5-bb.0"
promtail.helmRepo.repoName📜
Type: string
"registry1"
promtail.helmRepo.chartName📜
Type: string
"promtail"
promtail.helmRepo.tag📜
Type: string
"6.15.5-bb.0"
promtail.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Promtail Package
promtail.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the promtail chart: https://repo1.dso.mil/big-bang/product/packages/fluentbit.git
promtail.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
loki.enabled📜
Type: bool
true
Description: Toggle deployment of Loki.
loki.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
loki.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/loki.git"
loki.git.path📜
Type: string
"./chart"
loki.git.tag📜
Type: string
"5.42.0-bb.5"
loki.helmRepo.repoName📜
Type: string
"registry1"
loki.helmRepo.chartName📜
Type: string
"loki"
loki.helmRepo.tag📜
Type: string
"5.42.0-bb.5"
loki.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Loki Package
loki.strategy📜
Type: string
"monolith"
Description: Loki architecture. Options are monolith and scalable
loki.objectStorage.endpoint📜
Type: string
""
Description: S3 compatible endpoint to use for connection information. examples: “https://s3.amazonaws.com” “https://s3.us-gov-west-1.amazonaws.com” “http://minio.minio.svc.cluster.local:9000”
loki.objectStorage.region📜
Type: string
""
Description: S3 compatible region to use for connection information.
loki.objectStorage.accessKey📜
Type: string
""
Description: Access key for connecting to object storage endpoint.
loki.objectStorage.accessSecret📜
Type: string
""
Description: Secret key for connecting to object storage endpoint. Unencoded string data. This should be placed in the secret values and then encrypted
loki.objectStorage.bucketNames📜
Type: object
{}
Default value (formatted)
{}
Description: Bucket Names for the Loki buckets as YAML chunks: loki-logs ruler: loki-ruler admin: loki-admin
loki.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the Loki chart: https://repo1.dso.mil/big-bang/product/packages/loki.git
loki.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
neuvector.enabled📜
Type: bool
true
Description: Toggle deployment of Neuvector.
neuvector.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
neuvector.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/neuvector.git"
neuvector.git.path📜
Type: string
"./chart"
neuvector.git.tag📜
Type: string
"2.6.3-bb.9"
neuvector.helmRepo.repoName📜
Type: string
"registry1"
neuvector.helmRepo.chartName📜
Type: string
"neuvector"
neuvector.helmRepo.tag📜
Type: string
"2.6.3-bb.9"
neuvector.ingress📜
Type: object
{"gateway":""}
Default value (formatted)
{
"gateway": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
neuvector.sso.enabled📜
Type: bool
false
Description: Toggle SSO for Neuvector on and off
neuvector.sso.client_id📜
Type: string
""
Description: OIDC Client ID to use for Neuvector
neuvector.sso.client_secret📜
Type: string
""
Description: OIDC Client Secret to use for Neuvector
neuvector.sso.default_role📜
Type: string
""
Description: Default role to use for Neuvector OIDC users. Supports admin, reader, or no default
neuvector.sso.group_claim📜
Type: string
""
Description: Default role to use for Neuvector OIDC users. Supports admin, reader, or no default
neuvector.sso.group_mapped_roles📜
Type: list
[]
Default value (formatted)
[]
Description: Default role to use for Neuvector OIDC users. Supports admin, reader, or no default
neuvector.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Neuvector Package
neuvector.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the Neuvector chart: https://repo1.dso.mil/big-bang/product/packages/neuvector.git
neuvector.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
tempo.enabled📜
Type: bool
true
Description: Toggle deployment of Tempo.
tempo.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
tempo.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/tempo.git"
tempo.git.path📜
Type: string
"./chart"
tempo.git.tag📜
Type: string
"1.7.1-bb.2"
tempo.helmRepo.repoName📜
Type: string
"registry1"
tempo.helmRepo.chartName📜
Type: string
"tempo"
tempo.helmRepo.tag📜
Type: string
"1.7.1-bb.2"
tempo.ingress📜
Type: object
{"gateway":""}
Default value (formatted)
{
"gateway": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
tempo.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Tempo Package
tempo.sso.enabled📜
Type: bool
false
Description: Toggle SSO for Tempo on and off
tempo.sso.client_id📜
Type: string
""
Description: OIDC Client ID to use for Tempo
tempo.sso.client_secret📜
Type: string
""
Description: OIDC Client Secret to use for Tempo
tempo.objectStorage.endpoint📜
Type: string
""
Description: S3 compatible endpoint to use for connection information. examples: “s3.amazonaws.com” “s3.us-gov-west-1.amazonaws.com” “minio.minio.svc.cluster.local:9000” Note: tempo does not require protocol prefix for URL.
tempo.objectStorage.region📜
Type: string
""
Description: S3 compatible region to use for connection information.
tempo.objectStorage.accessKey📜
Type: string
""
Description: Access key for connecting to object storage endpoint.
tempo.objectStorage.accessSecret📜
Type: string
""
Description: Secret key for connecting to object storage endpoint. Unencoded string data. This should be placed in the secret values and then encrypted
tempo.objectStorage.bucket📜
Type: string
""
Description: Bucket Name for Tempo examples: “tempo-traces”
tempo.objectStorage.insecure📜
Type: bool
false
Description: Whether or not objectStorage connection should require HTTPS, if connecting to in-cluster object storage on port 80/9000 set this value to true.
tempo.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the Tempo chart: https://repo1.dso.mil/big-bang/product/packages/tempo.git
tempo.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
monitoring.enabled📜
Type: bool
true
Description: Toggle deployment of Monitoring (Prometheus, Grafana, and Alertmanager).
monitoring.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
monitoring.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/monitoring.git"
monitoring.git.path📜
Type: string
"./chart"
monitoring.git.tag📜
Type: string
"56.2.1-bb.1"
monitoring.helmRepo.repoName📜
Type: string
"registry1"
monitoring.helmRepo.chartName📜
Type: string
"monitoring"
monitoring.helmRepo.tag📜
Type: string
"56.2.1-bb.1"
monitoring.flux📜
Type: object
{"install":{"crds":"CreateReplace"},"upgrade":{"crds":"CreateReplace"}}
Default value (formatted)
{
"install": {
"crds": "CreateReplace"
},
"upgrade": {
"crds": "CreateReplace"
}
}
Description: Flux reconciliation overrides specifically for the Monitoring Package
monitoring.ingress📜
Type: object
{"gateway":""}
Default value (formatted)
{
"gateway": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
monitoring.sso.enabled📜
Type: bool
false
Description: Toggle SSO for monitoring components on and off
monitoring.sso.prometheus.client_id📜
Type: string
""
Description: Prometheus OIDC client ID
monitoring.sso.prometheus.client_secret📜
Type: string
""
Description: Prometheus OIDC client secret
monitoring.sso.alertmanager.client_id📜
Type: string
""
Description: Alertmanager OIDC client ID
monitoring.sso.alertmanager.client_secret📜
Type: string
""
Description: Alertmanager OIDC client secret
monitoring.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the monitoring chart: https://repo1.dso.mil/big-bang/product/packages/monitoring.git
monitoring.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
grafana.enabled📜
Type: bool
true
Description: Toggle deployment of Grafana
grafana.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
grafana.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/grafana.git"
grafana.git.path📜
Type: string
"./chart"
grafana.git.tag📜
Type: string
"7.3.0-bb.1"
grafana.helmRepo.repoName📜
Type: string
"registry1"
grafana.helmRepo.chartName📜
Type: string
"grafana"
grafana.helmRepo.tag📜
Type: string
"7.3.0-bb.1"
grafana.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Monitoring Package
grafana.ingress📜
Type: object
{"gateway":""}
Default value (formatted)
{
"gateway": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
grafana.sso.enabled📜
Type: bool
false
Description: Toggle SSO for grafana components on and off
grafana.sso.grafana.client_id📜
Type: string
""
Description: Grafana OIDC client ID
grafana.sso.grafana.client_secret📜
Type: string
""
Description: Grafana OIDC client secret
grafana.sso.grafana.scopes📜
Type: string
""
Description: Grafana OIDC client scopes, comma separated, see https://grafana.com/docs/grafana/latest/auth/generic-oauth/
grafana.sso.grafana.allow_sign_up📜
Type: bool
true
grafana.sso.grafana.role_attribute_path📜
Type: string
"Viewer"
grafana.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the grafana chart: https://repo1.dso.mil/big-bang/product/packages/grafana.git
grafana.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
twistlock.enabled📜
Type: bool
false
Description: Toggle deployment of Twistlock.
twistlock.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
twistlock.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/twistlock.git"
twistlock.git.path📜
Type: string
"./chart"
twistlock.git.tag📜
Type: string
"0.15.0-bb.0"
twistlock.helmRepo.repoName📜
Type: string
"registry1"
twistlock.helmRepo.chartName📜
Type: string
"twistlock"
twistlock.helmRepo.tag📜
Type: string
"0.15.0-bb.0"
twistlock.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Twistlock Package
twistlock.ingress📜
Type: object
{"gateway":""}
Default value (formatted)
{
"gateway": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
twistlock.sso.enabled📜
Type: bool
false
Description: Toggle SAML SSO, requires a license and enabling the init job - see https://repo1.dso.mil/big-bang/product/packages/initialization.md
twistlock.sso.client_id📜
Type: string
""
Description: SAML client ID
twistlock.sso.provider_type📜
Type: string
"shibboleth"
Description: SAML Identity Provider. shibboleth
is recommended by Twistlock support for Keycloak Possible values: okta, gsuite, ping, shibboleth, azure, adfs
twistlock.sso.groups📜
Type: string
""
Description: Groups attribute (optional)
twistlock.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the twistlock chart: https://repo1.dso.mil/big-bang/product/packages/twistlock.git
twistlock.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
addons.argocd.enabled📜
Type: bool
false
Description: Toggle deployment of ArgoCD.
addons.argocd.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
addons.argocd.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/argocd.git"
addons.argocd.git.path📜
Type: string
"./chart"
addons.argocd.git.tag📜
Type: string
"6.1.0-bb.2"
addons.argocd.helmRepo.repoName📜
Type: string
"registry1"
addons.argocd.helmRepo.chartName📜
Type: string
"argocd"
addons.argocd.helmRepo.tag📜
Type: string
"6.1.0-bb.2"
addons.argocd.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the ArgoCD Package
addons.argocd.ingress📜
Type: object
{"gateway":""}
Default value (formatted)
{
"gateway": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
addons.argocd.redis.host📜
Type: string
""
Description: Hostname of a pre-existing Redis to use for ArgoCD. Entering connection info will enable external Redis and will auto-create any required secrets.
addons.argocd.redis.port📜
Type: string
""
Description: Port of a pre-existing Redis to use for ArgoCD.
addons.argocd.sso.enabled📜
Type: bool
false
Description: Toggle SSO for ArgoCD on and off
addons.argocd.sso.client_id📜
Type: string
""
Description: ArgoCD OIDC client ID
addons.argocd.sso.client_secret📜
Type: string
""
Description: ArgoCD OIDC client secret
addons.argocd.sso.groups📜
Type: string
"g, Impact Level 2 Authorized, role:admin\n"
Default value (formatted)
g, Impact Level 2 Authorized, role:admin
Description: ArgoCD SSO group roles, see docs for more details: https://argo-cd.readthedocs.io/en/stable/operator-manual/rbac/
addons.argocd.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the argocd chart: https://repo1.dso.mil/big-bang/product/packages/argocd.git
addons.argocd.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
addons.authservice.enabled📜
Type: bool
false
Description: Toggle deployment of Authservice. if enabling authservice, a filter needs to be provided by either enabling sso for monitoring or istio, or manually adding a filter chain in the values here: values: chain: minimal: callback_uri: “https://somecallback”
addons.authservice.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
addons.authservice.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/authservice.git"
addons.authservice.git.path📜
Type: string
"./chart"
addons.authservice.git.tag📜
Type: string
"0.5.3-bb.28"
addons.authservice.helmRepo.repoName📜
Type: string
"registry1"
addons.authservice.helmRepo.chartName📜
Type: string
"authservice"
addons.authservice.helmRepo.tag📜
Type: string
"0.5.3-bb.28"
addons.authservice.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Authservice Package
addons.authservice.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the authservice chart: https://repo1.dso.mil/big-bang/product/packages/authservice.git
addons.authservice.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
addons.authservice.chains📜
Type: object
{}
Default value (formatted)
{}
Description: Additional authservice chain configurations.
addons.minioOperator.enabled📜
Type: bool
false
Description: Toggle deployment of minio operator and instance.
addons.minioOperator.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
addons.minioOperator.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/minio-operator.git"
addons.minioOperator.git.path📜
Type: string
"./chart"
addons.minioOperator.git.tag📜
Type: string
"5.0.12-bb.0"
addons.minioOperator.helmRepo.repoName📜
Type: string
"registry1"
addons.minioOperator.helmRepo.chartName📜
Type: string
"minio-operator"
addons.minioOperator.helmRepo.tag📜
Type: string
"5.0.12-bb.0"
addons.minioOperator.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Minio Operator Package
addons.minioOperator.ingress📜
Type: object
{"gateway":""}
Default value (formatted)
{
"gateway": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
addons.minioOperator.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the minio operator chart: https://repo1.dso.mil/big-bang/product/packages/minio-operator.git
addons.minioOperator.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
addons.minio.enabled📜
Type: bool
false
Description: Toggle deployment of minio.
addons.minio.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
addons.minio.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/minio.git"
addons.minio.git.path📜
Type: string
"./chart"
addons.minio.git.tag📜
Type: string
"5.0.12-bb.1"
addons.minio.helmRepo.repoName📜
Type: string
"registry1"
addons.minio.helmRepo.chartName📜
Type: string
"minio-instance"
addons.minio.helmRepo.tag📜
Type: string
"5.0.12-bb.1"
addons.minio.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Minio Package
addons.minio.ingress📜
Type: object
{"gateway":""}
Default value (formatted)
{
"gateway": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
addons.minio.accesskey📜
Type: string
""
Description: Default access key to use for minio.
addons.minio.secretkey📜
Type: string
""
Description: Default secret key to intstantiate with minio, you should change/delete this after installation.
addons.minio.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the minio instance chart: https://repo1.dso.mil/big-bang/product/packages/minio.git
addons.minio.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
addons.gitlab.enabled📜
Type: bool
false
Description: Toggle deployment of Gitlab
addons.gitlab.hostnames.gitlab📜
Type: string
"gitlab"
addons.gitlab.hostnames.registry📜
Type: string
"registry"
addons.gitlab.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
addons.gitlab.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/gitlab.git"
addons.gitlab.git.path📜
Type: string
"./chart"
addons.gitlab.git.tag📜
Type: string
"7.9.1-bb.0"
addons.gitlab.helmRepo.repoName📜
Type: string
"registry1"
addons.gitlab.helmRepo.chartName📜
Type: string
"gitlab"
addons.gitlab.helmRepo.tag📜
Type: string
"7.9.1-bb.0"
addons.gitlab.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Gitlab Package
addons.gitlab.ingress📜
Type: object
{"gateway":""}
Default value (formatted)
{
"gateway": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
addons.gitlab.sso.enabled📜
Type: bool
false
Description: Toggle OIDC SSO for Gitlab on and off. Enabling this option will auto-create any required secrets.
addons.gitlab.sso.client_id📜
Type: string
""
Description: Gitlab OIDC client ID
addons.gitlab.sso.client_secret📜
Type: string
""
Description: Gitlab OIDC client secret
addons.gitlab.sso.scopes📜
Type: list
["Gitlab"]
Default value (formatted)
[
"Gitlab"
]
Description: Gitlab SSO Scopes, default is [“Gitlab”]
addons.gitlab.sso.groups📜
Type: list
[]
Default value (formatted)
[]
Description: Fill out the groups block below and populate with Keycloak groups according to your desired Gitlab membership requirements. The default groupsAttribute is “groups”. Full documentation: https://docs.gitlab.com/ee/administration/auth/oidc.html?tab=Linux+package+%28Omnibus%29#configure-users-based-on-oidc-group-membership
addons.gitlab.database.host📜
Type: string
""
Description: Hostname of a pre-existing PostgreSQL database to use for Gitlab. Entering connection info will disable the deployment of an internal database and will auto-create any required secrets.
addons.gitlab.database.port📜
Type: int
5432
Description: Port of a pre-existing PostgreSQL database to use for Gitlab.
addons.gitlab.database.database📜
Type: string
""
Description: Database name to connect to on host.
addons.gitlab.database.username📜
Type: string
""
Description: Username to connect as to external database, the user must have all privileges on the database.
addons.gitlab.database.password📜
Type: string
""
Description: Database password for the username used to connect to the existing database.
addons.gitlab.objectStorage.type📜
Type: string
""
Description: Type of object storage to use for Gitlab, setting to s3 will assume an external, pre-existing object storage is to be used. Entering connection info will enable this option and will auto-create any required secrets
addons.gitlab.objectStorage.endpoint📜
Type: string
""
Description: S3 compatible endpoint to use for connection information. examples: “https://s3.amazonaws.com” “https://s3.us-gov-west-1.amazonaws.com” “http://minio.minio.svc.cluster.local:9000”
addons.gitlab.objectStorage.region📜
Type: string
""
Description: S3 compatible region to use for connection information.
addons.gitlab.objectStorage.accessKey📜
Type: string
""
Description: Access key for connecting to object storage endpoint. – If using accessKey and accessSecret, the iamProfile must be left as an empty string: “”
addons.gitlab.objectStorage.accessSecret📜
Type: string
""
Description: Secret key for connecting to object storage endpoint. Unencoded string data. This should be placed in the secret values and then encrypted
addons.gitlab.objectStorage.bucketPrefix📜
Type: string
""
Description: Bucket prefix to use for identifying buckets. Example: “prod” will produce “prod-gitlab-bucket”
addons.gitlab.objectStorage.iamProfile📜
Type: string
""
Description: NOTE: Current bug with AWS IAM Profiles and Object Storage where only artifacts are stored. Fixed in Gitlab 14.5 – Name of AWS IAM profile to use. – If using an AWS IAM profile, the accessKey and accessSecret values must be left as empty strings eg: “”
addons.gitlab.smtp.password📜
Type: string
""
Description: Passwords should be placed in an encrypted file. Example: environment-bb-secret.enc.yaml If a value is provided BigBang will create a k8s secret named gitlab-smtp-password in the gitlab namespace
addons.gitlab.redis.password📜
Type: string
""
Description: Redis plain text password to connect to the redis server. If empty (“”), the gitlab charts will create the gitlab-redis-secret with a random password. – This needs to be set to a non-empty value in order for the Grafana Redis Datasource and Dashboards to be installed.
addons.gitlab.railsSecret📜
Type: string
""
Description: Rails plain text secret to define. If empty (“”), the gitlab charts will create the gitlab-rails-secret with randomized data. Read the following for more information on setting Gitlab rails secrets: https://docs.gitlab.com/charts/installation/secrets#gitlab-rails-secret
addons.gitlab.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the gitlab chart: https://repo1.dso.mil/big-bang/product/packages/gitlab.git
addons.gitlab.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
addons.gitlabRunner.enabled📜
Type: bool
false
Description: Toggle deployment of Gitlab Runner
addons.gitlabRunner.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
addons.gitlabRunner.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/gitlab-runner.git"
addons.gitlabRunner.git.path📜
Type: string
"./chart"
addons.gitlabRunner.git.tag📜
Type: string
"0.59.1-bb.3"
addons.gitlabRunner.helmRepo.repoName📜
Type: string
"registry1"
addons.gitlabRunner.helmRepo.chartName📜
Type: string
"gitlab-runner"
addons.gitlabRunner.helmRepo.tag📜
Type: string
"0.59.1-bb.3"
addons.gitlabRunner.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Gitlab Runner Package
addons.gitlabRunner.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the gitlab runner chart: https://repo1.dso.mil/big-bang/product/packages/gitlab-runner.git
addons.gitlabRunner.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
addons.nexusRepositoryManager.enabled📜
Type: bool
false
Description: Toggle deployment of Nexus Repository Manager.
addons.nexusRepositoryManager.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
addons.nexusRepositoryManager.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/nexus.git"
addons.nexusRepositoryManager.git.path📜
Type: string
"./chart"
addons.nexusRepositoryManager.git.tag📜
Type: string
"64.0.0-bb.0"
addons.nexusRepositoryManager.helmRepo.repoName📜
Type: string
"registry1"
addons.nexusRepositoryManager.helmRepo.chartName📜
Type: string
"nexus-repository-manager"
addons.nexusRepositoryManager.helmRepo.tag📜
Type: string
"64.0.0-bb.0"
addons.nexusRepositoryManager.license_key📜
Type: string
""
Description: Base64 encoded license file.
addons.nexusRepositoryManager.ingress📜
Type: object
{"gateway":""}
Default value (formatted)
{
"gateway": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
addons.nexusRepositoryManager.sso.enabled📜
Type: bool
false
Description: Toggle SAML SSO for NXRM. – handles SAML SSO, a Client must be configured in Keycloak or IdP – to complete setup. – https://support.sonatype.com/hc/en-us/articles/1500000976522-SAML-integration-for-Nexus-Repository-Manager-Pro-3-and-Nexus-IQ-Server-with-Keycloak#h_01EV7CWCYH3YKAPMAHG8XMQ599
addons.nexusRepositoryManager.sso.idp_data📜
Type: object
{"email":"","entityId":"","firstName":"","groups":"","lastName":"","username":""}
Default value (formatted)
{
"email": "",
"entityId": "",
"firstName": "",
"groups": "",
"lastName": "",
"username": ""
}
Description: NXRM SAML SSO Integration data
addons.nexusRepositoryManager.sso.idp_data.username📜
Type: string
""
Description: IdP Field Mappings – NXRM username attribute
addons.nexusRepositoryManager.sso.idp_data.firstName📜
Type: string
""
Description: NXRM firstname attribute (optional)
addons.nexusRepositoryManager.sso.idp_data.lastName📜
Type: string
""
Description: NXRM lastname attribute (optional)
addons.nexusRepositoryManager.sso.idp_data.email📜
Type: string
""
Description: NXRM email attribute (optional)
addons.nexusRepositoryManager.sso.idp_data.groups📜
Type: string
""
Description: NXRM groups attribute (optional)
addons.nexusRepositoryManager.sso.role📜
Type: list
[{"description":"","id":"","name":"","privileges":[],"roles":[]}]
Default value (formatted)
[
{
"description": "",
"id": "",
"name": "",
"privileges": [],
"roles": []
}
]
Description: NXRM Role
addons.nexusRepositoryManager.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Nexus Repository Manager Package
addons.nexusRepositoryManager.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the nxrm chart: https://repo1.dso.mil/big-bang/product/packages/nexus.git
addons.nexusRepositoryManager.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
addons.sonarqube.enabled📜
Type: bool
false
Description: Toggle deployment of SonarQube.
addons.sonarqube.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
addons.sonarqube.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/sonarqube.git"
addons.sonarqube.git.path📜
Type: string
"./chart"
addons.sonarqube.git.tag📜
Type: string
"8.0.3-bb.2"
addons.sonarqube.helmRepo.repoName📜
Type: string
"registry1"
addons.sonarqube.helmRepo.chartName📜
Type: string
"sonarqube"
addons.sonarqube.helmRepo.tag📜
Type: string
"8.0.3-bb.2"
addons.sonarqube.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Sonarqube Package
addons.sonarqube.ingress📜
Type: object
{"gateway":""}
Default value (formatted)
{
"gateway": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
addons.sonarqube.sso.enabled📜
Type: bool
false
Description: Toggle SAML SSO for SonarQube. Enabling this option will auto-create any required secrets.
addons.sonarqube.sso.client_id📜
Type: string
""
Description: SonarQube SAML client ID
addons.sonarqube.sso.login📜
Type: string
"login"
Description: SonarQube login sso attribute.
addons.sonarqube.sso.name📜
Type: string
"name"
Description: SonarQube name sso attribute.
addons.sonarqube.sso.email📜
Type: string
"email"
Description: SonarQube email sso attribute.
addons.sonarqube.sso.group📜
Type: string
"group"
Description: (optional) SonarQube group sso attribute.
addons.sonarqube.database.host📜
Type: string
""
Description: Hostname of a pre-existing PostgreSQL database to use for SonarQube.
addons.sonarqube.database.port📜
Type: int
5432
Description: Port of a pre-existing PostgreSQL database to use for SonarQube.
addons.sonarqube.database.database📜
Type: string
""
Description: Database name to connect to on host.
addons.sonarqube.database.username📜
Type: string
""
Description: Username to connect as to external database, the user must have all privileges on the database.
addons.sonarqube.database.password📜
Type: string
""
Description: Database password for the username used to connect to the existing database.
addons.sonarqube.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the sonarqube chart: https://repo1.dso.mil/big-bang/product/packages/sonarqube.git
addons.sonarqube.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
addons.fortify.enabled📜
Type: bool
false
Description: Toggle deployment of Fortify.
addons.fortify.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
addons.fortify.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/fortify.git"
addons.fortify.git.path📜
Type: string
"./chart"
addons.fortify.git.tag📜
Type: string
"1.1.2320154-bb.1"
addons.fortify.helmRepo.repoName📜
Type: string
"registry1"
addons.fortify.helmRepo.chartName📜
Type: string
"fortify-ssc"
addons.fortify.helmRepo.tag📜
Type: string
"1.1.2320154-bb.1"
addons.fortify.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Fortify Package
addons.fortify.ingress📜
Type: object
{"gateway":""}
Default value (formatted)
{
"gateway": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
addons.fortify.sso.enabled📜
Type: bool
false
Description: Toggle SSO for Harbor on and off
addons.fortify.sso.client_id📜
Type: string
""
Description: OIDC Client ID to use for Harbor
addons.fortify.sso.client_secret📜
Type: string
""
Description: OIDC Client Secret to use for Harbor
addons.fortify.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the fortify chart: https://repo1.dso.mil/big-bang/product/packages/fortify.git
addons.fortify.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
addons.haproxy.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
addons.haproxy.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/haproxy.git"
addons.haproxy.git.path📜
Type: string
"./chart"
addons.haproxy.git.tag📜
Type: string
"1.19.3-bb.3"
addons.haproxy.helmRepo.repoName📜
Type: string
"registry1"
addons.haproxy.helmRepo.chartName📜
Type: string
"haproxy"
addons.haproxy.helmRepo.tag📜
Type: string
"1.19.3-bb.3"
addons.haproxy.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the HAProxy Package
addons.haproxy.ingress📜
Type: object
{"gateway":""}
Default value (formatted)
{
"gateway": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
addons.haproxy.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the haproxy chart: https://repo1.dso.mil/big-bang/product/packages/haproxy.git
addons.haproxy.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
addons.anchore.enabled📜
Type: bool
false
Description: Toggle deployment of Anchore.
addons.anchore.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
addons.anchore.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/anchore-enterprise.git"
addons.anchore.git.path📜
Type: string
"./chart"
addons.anchore.git.tag📜
Type: string
"1.27.4-bb.7"
addons.anchore.helmRepo.repoName📜
Type: string
"registry1"
addons.anchore.helmRepo.chartName📜
Type: string
"anchore"
addons.anchore.helmRepo.tag📜
Type: string
"1.27.4-bb.7"
addons.anchore.flux📜
Type: object
{"upgrade":{"disableWait":true}}
Default value (formatted)
{
"upgrade": {
"disableWait": true
}
}
Description: Flux reconciliation overrides specifically for the Anchore Package
addons.anchore.adminPassword📜
Type: string
""
Description: Initial admin password used to authenticate to Anchore.
addons.anchore.enterprise📜
Type: object
{"enabled":false,"licenseYaml":"FULL LICENSE\n"}
Default value (formatted)
{
"enabled": false,
"licenseYaml": "FULL LICENSE
"
}
Description: Anchore Enterprise functionality.
addons.anchore.enterprise.enabled📜
Type: bool
false
Description: Toggle the installation of Anchore Enterprise. This must be accompanied by a valid license.
addons.anchore.enterprise.licenseYaml📜
Type: string
"FULL LICENSE\n"
Default value (formatted)
FULL LICENSE
Description: License for Anchore Enterprise. For formatting examples see https://repo1.dso.mil/big-bang/product/packages/CHART.md#enabling-enterprise-services
addons.anchore.ingress📜
Type: object
{"gateway":""}
Default value (formatted)
{
"gateway": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
addons.anchore.sso.enabled📜
Type: bool
false
Description: Toggle SAML SSO for Anchore on and off. Enabling this option will auto-create any required secrets (Note: SSO requires an Enterprise license).
addons.anchore.sso.client_id📜
Type: string
""
Description: Anchore SAML client ID
addons.anchore.sso.role_attribute📜
Type: string
""
Description: Anchore SAML client role attribute
addons.anchore.database.host📜
Type: string
""
Description: Hostname of a pre-existing PostgreSQL database to use for Anchore. Entering connection info will disable the deployment of an internal database and will auto-create any required secrets.
addons.anchore.database.port📜
Type: string
""
Description: Port of a pre-existing PostgreSQL database to use for Anchore.
addons.anchore.database.username📜
Type: string
""
Description: Username to connect as to external database, the user must have all privileges on the database.
addons.anchore.database.password📜
Type: string
""
Description: Database password for the username used to connect to the existing database.
addons.anchore.database.database📜
Type: string
""
Description: Database name to connect to on host (Note: database name CANNOT contain hyphens).
addons.anchore.database.feeds_database📜
Type: string
""
Description: Feeds database name to connect to on host (Note: feeds database name CANNOT contain hyphens). Only required for enterprise edition of anchore. By default, feeds database will be configured with the same username and password as the main database. For formatting examples on how to use a separate username and password for the feeds database see https://repo1.dso.mil/big-bang/product/packages/CHART.md#handling-dependencies
addons.anchore.redis.host📜
Type: string
""
Description: Hostname of a pre-existing Redis to use for Anchore Enterprise. Entering connection info will enable external redis and will auto-create any required secrets. Anchore only requires redis for enterprise deployments and will not provision an instance if using external
addons.anchore.redis.port📜
Type: string
""
Description: Port of a pre-existing Redis to use for Anchore Enterprise.
addons.anchore.redis.username📜
Type: string
""
Description: OPTIONAL: Username to connect to a pre-existing Redis (for password-only auth leave empty)
addons.anchore.redis.password📜
Type: string
""
Description: Password to connect to pre-existing Redis.
addons.anchore.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the anchore chart: https://repo1.dso.mil/big-bang/product/packages/anchore-enterprise.git
addons.anchore.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
addons.mattermostOperator.enabled📜
Type: bool
false
Description: Toggle deployment of Mattermost Operator.
addons.mattermostOperator.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
addons.mattermostOperator.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/mattermost-operator.git"
addons.mattermostOperator.git.path📜
Type: string
"./chart"
addons.mattermostOperator.git.tag📜
Type: string
"1.20.1-bb.1"
addons.mattermostOperator.helmRepo.repoName📜
Type: string
"registry1"
addons.mattermostOperator.helmRepo.chartName📜
Type: string
"mattermost-operator"
addons.mattermostOperator.helmRepo.tag📜
Type: string
"1.20.1-bb.1"
addons.mattermostOperator.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Mattermost Operator Package
addons.mattermostOperator.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the mattermost operator chart: https://repo1.dso.mil/big-bang/product/packages/values.yaml
addons.mattermostOperator.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
addons.mattermost.enabled📜
Type: bool
false
Description: Toggle deployment of Mattermost.
addons.mattermost.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
addons.mattermost.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/mattermost.git"
addons.mattermost.git.path📜
Type: string
"./chart"
addons.mattermost.git.tag📜
Type: string
"9.5.1-bb.0"
addons.mattermost.helmRepo.repoName📜
Type: string
"registry1"
addons.mattermost.helmRepo.chartName📜
Type: string
"mattermost"
addons.mattermost.helmRepo.tag📜
Type: string
"9.5.1-bb.0"
addons.mattermost.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Mattermost Package
addons.mattermost.enterprise📜
Type: object
{"enabled":false,"license":""}
Default value (formatted)
{
"enabled": false,
"license": ""
}
Description: Mattermost Enterprise functionality.
addons.mattermost.enterprise.enabled📜
Type: bool
false
Description: Toggle the Mattermost Enterprise. This must be accompanied by a valid license unless you plan to start a trial post-install.
addons.mattermost.enterprise.license📜
Type: string
""
Description: License for Mattermost. This should be the entire contents of the license file from Mattermost (should be one line), example below license: “eyJpZCI6InIxM205bjR3eTdkYjludG95Z3RiOD—REST—IS—HIDDEN
addons.mattermost.ingress📜
Type: object
{"gateway":""}
Default value (formatted)
{
"gateway": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
addons.mattermost.sso.enabled📜
Type: bool
false
Description: Toggle OIDC SSO for Mattermost on and off. Enabling this option will auto-create any required secrets.
addons.mattermost.sso.client_id📜
Type: string
""
Description: Mattermost OIDC client ID
addons.mattermost.sso.client_secret📜
Type: string
""
Description: Mattermost OIDC client secret
addons.mattermost.database.host📜
Type: string
""
Description: Hostname of a pre-existing PostgreSQL database to use for Mattermost. Entering connection info will disable the deployment of an internal database and will auto-create any required secrets.
addons.mattermost.database.port📜
Type: string
""
Description: Port of a pre-existing PostgreSQL database to use for Mattermost.
addons.mattermost.database.username📜
Type: string
""
Description: Username to connect as to external database, the user must have all privileges on the database.
addons.mattermost.database.password📜
Type: string
""
Description: Database password for the username used to connect to the existing database.
addons.mattermost.database.database📜
Type: string
""
Description: Database name to connect to on host.
addons.mattermost.database.ssl_mode📜
Type: string
""
Description: SSL Mode to use when connecting to the database. Allowable values for this are viewable in the postgres documentation: https://www.postgresql.org/docs/current/libpq-ssl.html#LIBPQ-SSL-SSLMODE-STATEMENTS
addons.mattermost.objectStorage.endpoint📜
Type: string
""
Description: S3 compatible endpoint to use for connection information. Entering connection info will enable this option and will auto-create any required secrets. examples: “s3.amazonaws.com” “s3.us-gov-west-1.amazonaws.com” “minio.minio.svc.cluster.local:9000”
addons.mattermost.objectStorage.accessKey📜
Type: string
""
Description: Access key for connecting to object storage endpoint.
addons.mattermost.objectStorage.accessSecret📜
Type: string
""
Description: Secret key for connecting to object storage endpoint. Unencoded string data. This should be placed in the secret values and then encrypted
addons.mattermost.objectStorage.bucket📜
Type: string
""
Description: Bucket name to use for Mattermost - will be auto-created.
addons.mattermost.elasticsearch📜
Type: object
{"enabled":false}
Default value (formatted)
{
"enabled": false
}
Description: Mattermost Elasticsearch integration - requires enterprise E20 license - https://docs.mattermost.com/deployment/elasticsearch.html Connection info defaults to the BB deployed Elastic, all values can be overridden via the “values” passthrough for other connections. See values spec in MM chart “elasticsearch” yaml block - https://repo1.dso.mil/big-bang/product/packages/values.yaml
addons.mattermost.elasticsearch.enabled📜
Type: bool
false
Description: Toggle interaction with Elastic for optimized search indexing
addons.mattermost.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the Mattermost chart: https://repo1.dso.mil/big-bang/product/packages/values.yaml
addons.mattermost.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
addons.velero.enabled📜
Type: bool
false
Description: Toggle deployment of Velero.
addons.velero.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
addons.velero.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/velero.git"
addons.velero.git.path📜
Type: string
"./chart"
addons.velero.git.tag📜
Type: string
"5.2.2-bb.0"
addons.velero.helmRepo.repoName📜
Type: string
"registry1"
addons.velero.helmRepo.chartName📜
Type: string
"velero"
addons.velero.helmRepo.tag📜
Type: string
"5.2.2-bb.0"
addons.velero.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Velero Package
addons.velero.plugins📜
Type: list
[]
Default value (formatted)
[]
Description: Plugin provider for Velero - requires at least one plugin installed. Current supported values: aws, azure, csi
addons.velero.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the Velero chart: https://repo1.dso.mil/big-bang/product/packages/values.yaml
addons.velero.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
addons.keycloak.enabled📜
Type: bool
false
Description: Toggle deployment of Keycloak. if you enable Keycloak you should uncomment the istio passthrough configurations above istio.ingressGateways.passthrough-ingressgateway and istio.gateways.passthrough
addons.keycloak.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
addons.keycloak.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/keycloak.git"
addons.keycloak.git.path📜
Type: string
"./chart"
addons.keycloak.git.tag📜
Type: string
"18.4.3-bb.13"
addons.keycloak.helmRepo.repoName📜
Type: string
"registry1"
addons.keycloak.helmRepo.chartName📜
Type: string
"keycloak"
addons.keycloak.helmRepo.tag📜
Type: string
"18.4.3-bb.13"
addons.keycloak.database.host📜
Type: string
""
Description: Hostname of a pre-existing database to use for Keycloak. Entering connection info will disable the deployment of an internal database and will auto-create any required secrets.
addons.keycloak.database.type📜
Type: string
"postgres"
Description: Pre-existing database type (e.g. postgres) to use for Keycloak.
addons.keycloak.database.port📜
Type: int
5432
Description: Port of a pre-existing database to use for Keycloak.
addons.keycloak.database.database📜
Type: string
""
Description: Database name to connect to on host.
addons.keycloak.database.username📜
Type: string
""
Description: Username to connect as to external database, the user must have all privileges on the database.
addons.keycloak.database.password📜
Type: string
""
Description: Database password for the username used to connect to the existing database.
addons.keycloak.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the OPA Gatekeeper Package
addons.keycloak.ingress📜
Type: object
{"cert":"","gateway":"passthrough","key":""}
Default value (formatted)
{
"cert": "",
"gateway": "passthrough",
"key": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
addons.keycloak.ingress.key📜
Type: string
""
Description: Certificate/Key pair to use as the certificate for exposing Keycloak Setting the ingress cert here will automatically create the volume and volumemounts in the Keycloak Package chart
addons.keycloak.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the keycloak chart: https://repo1.dso.mil/big-bang/product/packages/keycloak.git
addons.keycloak.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
addons.vault.enabled📜
Type: bool
false
Description: Toggle deployment of Vault.
addons.vault.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
addons.vault.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/vault.git"
addons.vault.git.path📜
Type: string
"./chart"
addons.vault.git.tag📜
Type: string
"0.25.0-bb.14"
addons.vault.helmRepo.repoName📜
Type: string
"registry1"
addons.vault.helmRepo.chartName📜
Type: string
"vault"
addons.vault.helmRepo.tag📜
Type: string
"0.25.0-bb.14"
addons.vault.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Vault Package
addons.vault.ingress📜
Type: object
{"cert":"","gateway":"","key":""}
Default value (formatted)
{
"cert": "",
"gateway": "",
"key": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
addons.vault.ingress.key📜
Type: string
""
Description: Certificate/Key pair to use as the certificate for exposing Vault Setting the ingress cert here will automatically create the volume and volumemounts in the Vault package chart
addons.vault.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the vault chart: https://repo1.dso.mil/big-bang/product/packages/vault.git
addons.vault.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
addons.metricsServer.enabled📜
Type: string
"auto"
Description: Toggle deployment of metrics server Acceptable options are enabled: true, enabled: false, enabled: auto true = enabled / false = disabled / auto = automatic (Installs only if metrics API endpoint is not present)
addons.metricsServer.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
addons.metricsServer.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/metrics-server.git"
addons.metricsServer.git.path📜
Type: string
"./chart"
addons.metricsServer.git.tag📜
Type: string
"3.11.0-bb.3"
addons.metricsServer.helmRepo.repoName📜
Type: string
"registry1"
addons.metricsServer.helmRepo.chartName📜
Type: string
"metrics-server"
addons.metricsServer.helmRepo.tag📜
Type: string
"3.11.0-bb.3"
addons.metricsServer.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the metrics server Package
addons.metricsServer.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the metrics server chart: https://repo1.dso.mil/big-bang/product/packages/metrics-server.git
addons.metricsServer.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
addons.harbor.enabled📜
Type: bool
false
Description: Toggle deployment of harbor
addons.harbor.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
addons.harbor.git.repo📜
Type: string
"https://repo1.dso.mil/platform-one/big-bang/apps/sandbox/harbor.git"
addons.harbor.git.tag📜
Type: string
"1.14.0-bb.2"
addons.harbor.git.path📜
Type: string
"./chart"
addons.harbor.helmRepo.repoName📜
Type: string
"registry1"
addons.harbor.helmRepo.chartName📜
Type: string
"harbor"
addons.harbor.helmRepo.tag📜
Type: string
"1.14.0-bb.2"
addons.harbor.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Jaeger Package
addons.harbor.ingress📜
Type: object
{"gateway":""}
Default value (formatted)
{
"gateway": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
addons.harbor.sso.enabled📜
Type: bool
false
Description: Toggle SSO for Harbor on and off
addons.harbor.sso.client_id📜
Type: string
""
Description: OIDC Client ID to use for Harbor
addons.harbor.sso.client_secret📜
Type: string
""
Description: OIDC Client Secret to use for Harbor
addons.harbor.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to pass through to Habor chart: https://repo1.dso.mil/big-bang/product/packages/harbor.git
addons.harbor.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
addons.holocron.enabled📜
Type: bool
false
Description: Toggle deployment of Holocron.
addons.holocron.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
addons.holocron.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/holocron.git"
addons.holocron.git.tag📜
Type: string
"1.0.0"
addons.holocron.git.path📜
Type: string
"./chart"
addons.holocron.helmRepo.repoName📜
Type: string
"registry1"
addons.holocron.helmRepo.chartName📜
Type: string
"holocron"
addons.holocron.helmRepo.tag📜
Type: string
"1.0.0"
addons.holocron.collectorAuth.existingSecret📜
Type: string
""
Description: Name of existing secret with auth tokens for collector services: https://repo1.dso.mil/groups/big-bang/apps/sandbox/holocron/-/wikis/Administrator-Guide – Default keys for secret are: – gitlab-scm-0, gitlab-workflow-0, gitlab-build-0, jira-workflow-0, sonarqube-project-analysis-0 – If not provided, one will be created
addons.holocron.collectorAuth.gitlabToken📜
Type: string
"mygitlabtoken"
Description: Tokens for the secret to be created
addons.holocron.collectorAuth.jiraToken📜
Type: string
"myjiratoken"
addons.holocron.collectorAuth.sonarToken📜
Type: string
"mysonartoken"
addons.holocron.jira.enabled📜
Type: bool
false
Description: If there is a Jira deployment, enable a collector for it
addons.holocron.jira.service.name📜
Type: string
""
Description: The service name to communicate with
addons.holocron.jira.service.label📜
Type: object
{"key":"value"}
Default value (formatted)
{
"key": "value"
}
Description: If network policies are enabled, a label to match the namespace for egress policy
addons.holocron.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Holocron Package
addons.holocron.ingress📜
Type: object
{"gateway":""}
Default value (formatted)
{
"gateway": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
addons.holocron.sso.enabled📜
Type: bool
false
Description: Toggle SSO for Holocron on and off
addons.holocron.sso.groups📜
Type: object
{"admin":"","leadership":""}
Default value (formatted)
{
"admin": "",
"leadership": ""
}
Description: Holocron SSO group roles: https://repo1.dso.mil/groups/big-bang/apps/sandbox/holocron/-/wikis/Administrator-Guide
addons.holocron.database.host📜
Type: string
""
Description: Hostname of a pre-existing PostgreSQL database to use for Gitlab. – Entering connection info will disable the deployment of an internal database and will auto-create any required secrets.
addons.holocron.database.port📜
Type: int
5432
Description: Port of a pre-existing PostgreSQL database to use for Gitlab.
addons.holocron.database.database📜
Type: string
"holocron"
Description: Database name to connect to on host.
addons.holocron.database.username📜
Type: string
"holocron"
Description: Username to connect as to external database, the user must have all privileges on the database.
addons.holocron.database.password📜
Type: string
"holocron"
Description: Database password for the username used to connect to the existing database.
addons.holocron.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: Post Renderers. See docs/postrenders.md
addons.holocron.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to passthrough to the Holocron chart: https://repo1.dso.mil/big-bang/product/packages/holocron.git
addons.thanos.enabled📜
Type: bool
false
Description: Toggle deployment of thanos
addons.thanos.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
addons.thanos.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/thanos.git"
addons.thanos.git.tag📜
Type: string
"12.23.0-bb.2"
addons.thanos.git.path📜
Type: string
"./chart"
addons.thanos.helmRepo.repoName📜
Type: string
"registry1"
addons.thanos.helmRepo.chartName📜
Type: string
"thanos"
addons.thanos.helmRepo.tag📜
Type: string
"12.23.0-bb.2"
addons.thanos.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Flux reconciliation overrides specifically for the Jaeger Package
addons.thanos.ingress📜
Type: object
{"gateway":""}
Default value (formatted)
{
"gateway": ""
}
Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways
). The default is “public”.
addons.thanos.objstoreConfig📜
Type: string
""
Description: Configure the object storage for Thanos. The monitoring.prometheus thanos-sidecar and Thanos will use this configuration if defined
addons.thanos.values📜
Type: object
{}
Default value (formatted)
{}
addons.thanos.postRenderers📜
Type: list
[]
Default value (formatted)
[]
wrapper📜
Type: object
{"git":{"path":"chart","repo":"https://repo1.dso.mil/big-bang/product/packages/wrapper.git","tag":"0.4.5"},"helmRepo":{"chartName":"wrapper","repoName":"registry1","tag":"0.4.5"},"sourceType":"git"}
Default value (formatted)
{
"git": {
"path": "chart",
"repo": "https://repo1.dso.mil/big-bang/product/packages/wrapper.git",
"tag": "0.4.5"
},
"helmRepo": {
"chartName": "wrapper",
"repoName": "registry1",
"tag": "0.4.5"
},
"sourceType": "git"
}
Description: Wrapper chart for integrating Big Bang components alongside a package
wrapper.sourceType📜
Type: string
"git"
Description: Choose source type of “git” or “helmRepo”
wrapper.helmRepo.repoName📜
Type: string
"registry1"
Description: Repository holding OCI chart, corresponding to helmRepositories
name
wrapper.helmRepo.chartName📜
Type: string
"wrapper"
Description: Name of the OCI chart in repo
wrapper.helmRepo.tag📜
Type: string
"0.4.5"
Description: Tag of the OCI chart in repo
wrapper.git.repo📜
Type: string
"https://repo1.dso.mil/big-bang/product/packages/wrapper.git"
Description: Git repo holding the wrapper helm chart, example: https://repo1.dso.mil/big-bang/product/packages/wrapper
wrapper.git.path📜
Type: string
"chart"
Description: Path inside of the git repo to find the helm chart, example: chart
wrapper.git.tag📜
Type: string
"0.4.5"
Description: Git tag to check out. Takes precedence over branch. More info, example: 0.0.2
packages📜
Type: object
{"sample":{"configMaps":{},"dependsOn":[],"enabled":false,"flux":{},"git":{"branch":null,"commit":null,"credentials":{"caFile":"","knownHosts":"","password":"","privateKey":"","publicKey":"","username":""},"existingSecret":"","path":null,"repo":null,"semver":null,"tag":null},"helmRepo":{"chartName":null,"repoName":null,"tag":null},"istio":{},"kustomize":false,"monitor":{},"network":{},"postRenderers":[],"secrets":{},"sourceType":"git","values":{},"wrapper":{"enabled":false}}}
Default value (formatted)
{
"sample": {
"configMaps": {},
"dependsOn": [],
"enabled": false,
"flux": {},
"git": {
"branch": null,
"commit": null,
"credentials": {
"caFile": "",
"knownHosts": "",
"password": "",
"privateKey": "",
"publicKey": "",
"username": ""
},
"existingSecret": "",
"path": null,
"repo": null,
"semver": null,
"tag": null
},
"helmRepo": {
"chartName": null,
"repoName": null,
"tag": null
},
"istio": {},
"kustomize": false,
"monitor": {},
"network": {},
"postRenderers": [],
"secrets": {},
"sourceType": "git",
"values": {},
"wrapper": {
"enabled": false
}
}
}
Description: Packages to deploy with Big Bang @default - ‘{}’
packages.sample.sourceType📜
Type: string
"git"
Description: Choose source type of “git” (“helmRepo” not supported yet)
packages.sample.kustomize📜
Type: bool
false
Description: Use a kustomize deployment rather than Helm
packages.sample.helmRepo📜
Type: object
{"chartName":null,"repoName":null,"tag":null}
Default value (formatted)
{
"chartName": null,
"repoName": null,
"tag": null
}
Description: HelmRepo source is supported as an option for Helm deployments. If both git
and helmRepo
are provided git
will take precedence.
packages.sample.helmRepo.repoName📜
Type: string
nil
Description: Name of the HelmRepo specified in helmRepositories
packages.sample.helmRepo.chartName📜
Type: string
nil
Description: Name of the chart stored in the Helm repository
packages.sample.helmRepo.tag📜
Type: string
nil
Description: Tag of the chart in the Helm repo, required
packages.sample.git📜
Type: object
{"branch":null,"commit":null,"credentials":{"caFile":"","knownHosts":"","password":"","privateKey":"","publicKey":"","username":""},"existingSecret":"","path":null,"repo":null,"semver":null,"tag":null}
Default value (formatted)
{
"branch": null,
"commit": null,
"credentials": {
"caFile": "",
"knownHosts": "",
"password": "",
"privateKey": "",
"publicKey": "",
"username": ""
},
"existingSecret": "",
"path": null,
"repo": null,
"semver": null,
"tag": null
}
Description: Git source is supported for both Helm and Kustomize deployments. If both git
and helmRepo
are provided git
will take precedence.
packages.sample.git.repo📜
Type: string
nil
Description: Git repo URL holding the helm chart for this package, required if using git
packages.sample.git.commit📜
Type: string
nil
Description: Git commit to check out. Takes precedence over semver, tag, and branch. More info
packages.sample.git.semver📜
Type: string
nil
Description: Git semVer tag expression to check out. Takes precedence over tag. More info
packages.sample.git.tag📜
Type: string
nil
Description: Git tag to check out. Takes precedence over branch. More info
packages.sample.git.branch📜
Type: string
nil
Description: Git branch to check out. More info.
packages.sample.git.path📜
Type: string
nil
Description: Path inside of the git repo to find the helm chart or kustomize
packages.sample.git.existingSecret📜
Type: string
""
Description: Optional, alternative existing secret to use for git credentials, must be in the appropriate format: https://toolkit.fluxcd.io/components/source/gitrepositories/#https-authentication
packages.sample.git.credentials📜
Type: object
{"caFile":"","knownHosts":"","password":"","privateKey":"","publicKey":"","username":""}
Default value (formatted)
{
"caFile": "",
"knownHosts": "",
"password": "",
"privateKey": "",
"publicKey": "",
"username": ""
}
Description: Optional, alternative Chart created secrets with user defined values
packages.sample.git.credentials.username📜
Type: string
""
Description: HTTP git credentials, both username and password must be provided
packages.sample.git.credentials.caFile📜
Type: string
""
Description: HTTPS certificate authority file. Required for any repo with a self signed certificate
packages.sample.git.credentials.privateKey📜
Type: string
""
Description: SSH git credentials, privateKey, publicKey, and knownHosts must be provided
packages.sample.flux📜
Type: object
{}
Default value (formatted)
{}
Description: Override flux settings for this package
packages.sample.postRenderers📜
Type: list
[]
Default value (formatted)
[]
Description: After deployment, patch resources. More info
packages.sample.dependsOn📜
Type: list
[]
Default value (formatted)
[]
Description: Specify dependencies for the package. Only used for HelmRelease, does not effect Kustomization. See here for a reference.
packages.sample.istio📜
Type: object
{}
Default value (formatted)
{}
Description: Package details for Istio. See wrapper values for settings.
packages.sample.monitor📜
Type: object
{}
Default value (formatted)
{}
Description: Package details for monitoring. See wrapper values for settings.
packages.sample.network📜
Type: object
{}
Default value (formatted)
{}
Description: Package details for network policies. See wrapper values for settings.
packages.sample.secrets📜
Type: object
{}
Default value (formatted)
{}
Description: Secrets that should be created prior to package installation. See wrapper values for settings.
packages.sample.configMaps📜
Type: object
{}
Default value (formatted)
{}
Description: ConfigMaps that should be created prior to package installation. See wrapper values for settings.
packages.sample.values📜
Type: object
{}
Default value (formatted)
{}
Description: Values to pass through to package Helm chart