anchore-enterprise values.yaml¶
domain¶
Type: string
"dev.bigbang.mil"
routes.inbound.anchore-api.enabled¶
Type: bool
true
routes.inbound.anchore-api.selector.”app.kubernetes.io/component”¶
Type: string
"api"
routes.inbound.anchore-api.gateways[0]¶
Type: string
"istio-gateway/public-ingressgateway"
routes.inbound.anchore-api.hosts[0]¶
Type: string
"anchore-api.{{ .Values.domain }}"
routes.inbound.anchore-api.http[0].match[0].uri.prefix¶
Type: string
"/metrics"
routes.inbound.anchore-api.http[0].route[0].destination.host¶
Type: string
"anchore-enterprise-anchore-enterprise-api.anchore.svc.cluster.local"
routes.inbound.anchore-api.http[0].route[0].destination.port.number¶
Type: int
8228
routes.inbound.anchore-api.http[0].fault.abort.percentage.value¶
Type: int
100
routes.inbound.anchore-api.http[0].fault.abort.httpStatus¶
Type: int
403
routes.inbound.anchore-api.http[1].match[0].uri.prefix¶
Type: string
"/"
routes.inbound.anchore-api.http[1].route[0].destination.host¶
Type: string
"anchore-enterprise-anchore-enterprise-api.anchore.svc.cluster.local"
routes.inbound.anchore-api.http[1].route[0].destination.port.number¶
Type: int
8228
routes.inbound.anchore-ui.enabled¶
Type: bool
true
routes.inbound.anchore-ui.selector.”app.kubernetes.io/component”¶
Type: string
"ui"
routes.inbound.anchore-ui.gateways[0]¶
Type: string
"istio-gateway/public-ingressgateway"
routes.inbound.anchore-ui.hosts[0]¶
Type: string
"anchore.{{ .Values.domain }}"
routes.inbound.anchore-ui.service¶
Type: string
"anchore-enterprise-anchore-enterprise-ui.anchore.svc.cluster.local"
routes.inbound.anchore-ui.port¶
Type: int
3000
routes.outbound.anchore-data-service.enabled¶
Type: bool
true
routes.outbound.anchore-data-service.hosts[0]¶
Type: string
"data.anchore-enterprise.com"
istio.enabled¶
Type: bool
false
istio.sidecar.enabled¶
Type: bool
false
istio.sidecar.outboundTrafficPolicyMode¶
Type: string
"REGISTRY_ONLY"
istio.serviceEntries.custom¶
Type: list
[]
istio.authorizationPolicies.enabled¶
Type: bool
false
istio.authorizationPolicies.custom¶
Type: list
[]
istio.mtls.mode¶
Type: string
"STRICT"
networkPolicies.enabled¶
Type: bool
false
networkPolicies.ingress.to.catalog:8082.podSelector.matchLabels.”app.kubernetes.io/component”¶
Type: string
"catalog"
networkPolicies.ingress.to.catalog:8082.from.k8s.monitoring-monitoring-kube-prometheus@monitoring/prometheus¶
Type: bool
false
networkPolicies.ingress.to.simplequeue:8083.podSelector.matchLabels.”app.kubernetes.io/component”¶
Type: string
"simplequeue"
networkPolicies.ingress.to.simplequeue:8083.from.k8s.monitoring-monitoring-kube-prometheus@monitoring/prometheus¶
Type: bool
false
networkPolicies.ingress.to.analyzer:8084.podSelector.matchLabels.”app.kubernetes.io/component”¶
Type: string
"analyzer"
networkPolicies.ingress.to.analyzer:8084.from.k8s.monitoring-monitoring-kube-prometheus@monitoring/prometheus¶
Type: bool
false
networkPolicies.ingress.to.policy:8087.podSelector.matchLabels.”app.kubernetes.io/component”¶
Type: string
"policyengine"
networkPolicies.ingress.to.policy:8087.from.k8s.monitoring-monitoring-kube-prometheus@monitoring/prometheus¶
Type: bool
false
networkPolicies.ingress.to.api:8228.podSelector.matchLabels.”app.kubernetes.io/component”¶
Type: string
"api"
networkPolicies.ingress.to.api:8228.from.k8s.monitoring-monitoring-kube-prometheus@monitoring/prometheus¶
Type: bool
false
networkPolicies.ingress.to.reports:8558.podSelector.matchLabels.”app.kubernetes.io/component”¶
Type: string
"reports"
networkPolicies.ingress.to.reports:8558.from.k8s.monitoring-monitoring-kube-prometheus@monitoring/prometheus¶
Type: bool
false
networkPolicies.ingress.to.notifications:8668.podSelector.matchLabels.”app.kubernetes.io/component”¶
Type: string
"notifications"
networkPolicies.ingress.to.notifications:8668.from.k8s.monitoring-monitoring-kube-prometheus@monitoring/prometheus¶
Type: bool
false
networkPolicies.ingress.to.ui-redis:9121.from.k8s.monitoring-monitoring-kube-prometheus@monitoring/prometheus¶
Type: bool
false
networkPolicies.egress.definitions.anchore-data-service.to[0].ipBlock.cidr¶
Type: string
"0.0.0.0/0"
networkPolicies.egress.definitions.anchore-data-service.ports[0].port¶
Type: int
443
networkPolicies.egress.definitions.anchore-data-service.ports[0].protocol¶
Type: string
"TCP"
networkPolicies.egress.definitions.ldap-subnets.to[0].ipBlock.cidr¶
Type: string
"192.168.0.0/16"
networkPolicies.egress.definitions.ldap-subnets.to[1].ipBlock.cidr¶
Type: string
"172.16.0.0/12"
networkPolicies.egress.definitions.ldap-subnets.to[2].ipBlock.cidr¶
Type: string
"10.0.0.0/8"
networkPolicies.egress.definitions.ldap-subnets.ports[0].port¶
Type: int
636
networkPolicies.egress.definitions.ldap-subnets.ports[0].protocol¶
Type: string
"TCP"
networkPolicies.egress.definitions.notification-services.to[0].ipBlock.cidr¶
Type: string
"0.0.0.0/0"
networkPolicies.egress.definitions.redis-subnets.to[0].ipBlock.cidr¶
Type: string
"192.168.0.0/16"
networkPolicies.egress.definitions.redis-subnets.to[1].ipBlock.cidr¶
Type: string
"172.16.0.0/12"
networkPolicies.egress.definitions.redis-subnets.to[2].ipBlock.cidr¶
Type: string
"10.0.0.0/8"
networkPolicies.egress.definitions.redis-subnets.ports[0].port¶
Type: int
6379
networkPolicies.egress.definitions.redis-subnets.ports[0].protocol¶
Type: string
"TCP"
networkPolicies.egress.definitions.registry-subnets.to[0].ipBlock.cidr¶
Type: string
"0.0.0.0/0"
networkPolicies.egress.from.*.to.k8s.tempo/tempo:9411¶
Type: bool
false
networkPolicies.egress.from.analyzer.podSelector.matchLabels.”app.kubernetes.io/component”¶
Type: string
"analyzer"
networkPolicies.egress.from.analyzer.to.definition.registry-subnets¶
Type: bool
true
networkPolicies.egress.from.api.podSelector.matchLabels.”app.kubernetes.io/component”¶
Type: string
"api"
networkPolicies.egress.from.api.to.definition.redis-subnets¶
Type: bool
false
networkPolicies.egress.from.api.to.definition.notification-services¶
Type: bool
true
networkPolicies.egress.from.catalog.podSelector.matchLabels.”app.kubernetes.io/component”¶
Type: string
"catalog"
networkPolicies.egress.from.catalog.to.definition.registry-subnets¶
Type: bool
true
networkPolicies.egress.from.datasyncer.podSelector.matchLabels.”app.kubernetes.io/component”¶
Type: string
"datasyncer"
networkPolicies.egress.from.datasyncer.to.definition.anchore-data-service¶
Type: bool
true
networkPolicies.egress.from.notifications.podSelector.matchLabels.”app.kubernetes.io/component”¶
Type: string
"notifications"
networkPolicies.egress.from.notifications.to.definition.notification-services¶
Type: bool
true
networkPolicies.egress.from.smoketest.podSelector.matchLabels.”app.kubernetes.io/component”¶
Type: string
"smoketest"
networkPolicies.egress.from.smoketest.to.definition.registry-subnets¶
Type: bool
true
networkPolicies.egress.from.ui.podSelector.matchLabels.”app.kubernetes.io/component”¶
Type: string
"ui"
networkPolicies.egress.from.ui.to.definition.ldap-subnets¶
Type: bool
true
networkPolicies.egress.from.ui.to.definition.redis-subnets¶
Type: bool
false
networkPolicies.additionalPolicies¶
Type: list
[]
sso.enabled¶
Type: bool
false
sso.name¶
Type: string
"keycloak"
sso.acsHttpsPort¶
Type: int
-1
sso.spEntityId¶
Type: string
"platform1_a8604cc9-f5e9-4656-802d-d05624370245_bb8-anchore"
sso.acsUrl¶
Type: string
"https://anchore.bigbang.dev/service/sso/auth/keycloak"
sso.defaultAccount¶
Type: string
"user"
sso.defaultRole¶
Type: string
"read-write"
sso.roleAttribute¶
Type: string
""
sso.requireSignedAssertions¶
Type: bool
false
sso.requireSignedResponse¶
Type: bool
true
sso.idpMetadataUrl¶
Type: string
"https://login.dso.mil/auth/realms/baby-yoda/protocol/saml/descriptor"
sso.idpMetadataXml¶
Type: string
""
sso.host¶
Type: string
"login.dso.mil"
sso.realm¶
Type: string
"baby-yoda"
sso.resources.limits.cpu¶
Type: string
"100m"
sso.resources.limits.memory¶
Type: string
"256Mi"
sso.resources.requests.cpu¶
Type: string
"100m"
sso.resources.requests.memory¶
Type: string
"256Mi"
sso.containerSecurityContext.runAsUser¶
Type: int
1001
sso.containerSecurityContext.runAsGroup¶
Type: int
1001
sso.containerSecurityContext.capabilities.drop[0]¶
Type: string
"ALL"
monitoring.enabled¶
Type: bool
false
monitoring.namespace¶
Type: string
"monitoring"
monitoring.serviceMonitor.scheme¶
Type: string
""
monitoring.serviceMonitor.tlsConfig¶
Type: object
{}
bbtests.enabled¶
Type: bool
false
bbtests.scripts.image¶
Type: string
"registry1.dso.mil/ironbank/anchore/cli/cli:0.9.4"
bbtests.scripts.envs.ANCHORE_CLI_URL¶
Type: string
"http://{{ include \"enterprise.api.fullname\" . }}:{{ .Values.upstream.api.service.port }}/v2"
bbtests.scripts.envs.ANCHORE_CLI_USER¶
Type: string
"admin"
bbtests.scripts.envs.ANCHORE_SCAN_IMAGE¶
Type: string
"quay.io/prometheus/node-exporter:latest"
bbtests.scripts.secretEnvs[0].name¶
Type: string
"ANCHORE_CLI_PASS"
bbtests.scripts.secretEnvs[0].valueFrom.secretKeyRef.name¶
Type: string
"{{ include \"enterprise.fullname\" . }}"
bbtests.scripts.secretEnvs[0].valueFrom.secretKeyRef.key¶
Type: string
"ANCHORE_ADMIN_PASSWORD"
bbtests.cypress.artifacts¶
Type: bool
true
bbtests.cypress.envs.cypress_url¶
Type: string
"http://{{ include \"enterprise.ui.fullname\" . }}:{{ .Values.upstream.ui.service.port }}"
bbtests.cypress.envs.cypress_user¶
Type: string
"admin"
bbtests.cypress.envs.cypress_registry¶
Type: string
"docker.io"
bbtests.cypress.envs.cypress_repository¶
Type: string
"anchore/grype"
bbtests.cypress.envs.cypress_tag¶
Type: string
"latest"
bbtests.cypress.secretEnvs[0].name¶
Type: string
"cypress_password"
bbtests.cypress.secretEnvs[0].valueFrom.secretKeyRef.name¶
Type: string
"{{ include \"enterprise.fullname\" . }}"
bbtests.cypress.secretEnvs[0].valueFrom.secretKeyRef.key¶
Type: string
"ANCHORE_ADMIN_PASSWORD"
global.fullnameOverride¶
Type: string
""
global.nameOverride¶
Type: string
"anchore-enterprise"
ui-redis.enabled¶
Type: bool
true
ui-redis.istio.enabled¶
Type: string
"{{ .Values.istio.enabled }}"
ui-redis.upstream.nameOverride¶
Type: string
"ui-redis"
ui-redis.upstream.fullnameOverride¶
Type: string
"anchore-enterprise-ui-redis"
ui-redis.upstream.auth.password¶
Type: string
"anchore-redis,123"
ui-redis.upstream.architecture¶
Type: string
"standalone"
ui-redis.upstream.master.persistence.enabled¶
Type: bool
false
ui-redis.upstream.commonConfiguration¶
Type: string
"maxmemory 200mb\nsave \"\""
ui-redis.cleanUpgrade.redisLabel¶
Type: string
"app.kubernetes.io/name: ui-redis"
postgresql.enabled¶
Type: bool
true
postgresql.image.registry¶
Type: string
"registry1.dso.mil"
postgresql.image.repository¶
Type: string
"ironbank/opensource/postgres/postgresql"
postgresql.image.tag¶
Type: string
"18.4"
postgresql.global.security.allowInsecureImages¶
Type: bool
true
postgresql.global.postgresql.auth.username¶
Type: string
"anchore"
Description: PostgreSQL User to create
postgresql.global.postgresql.auth.password¶
Type: string
"anchore-postgres,123"
Description: PostgreSQL Password for the new user
postgresql.global.postgresql.auth.database¶
Type: string
"anchore"
Description: PostgreSQL Database to create
postgresql.primary.networkPolicy.enabled¶
Type: bool
false
postgresql.primary.persistence.mountPath¶
Type: string
"/var/lib/postgresql"
postgresql.primary.extraVolumes[0].name¶
Type: string
"run-postgresql"
postgresql.primary.extraVolumes[0].emptyDir¶
Type: object
{}
postgresql.primary.extraVolumeMounts[0].name¶
Type: string
"run-postgresql"
postgresql.primary.extraVolumeMounts[0].mountPath¶
Type: string
"/run/postgresql"
postgresql.primary.resources.limits.cpu¶
Type: string
"1000m"
postgresql.primary.resources.limits.memory¶
Type: string
"4096Mi"
postgresql.primary.resources.requests.cpu¶
Type: string
"1000m"
postgresql.primary.resources.requests.memory¶
Type: string
"4096Mi"
postgresql.metrics.resources.limits.cpu¶
Type: string
"200m"
postgresql.metrics.resources.limits.memory¶
Type: string
"256Mi"
postgresql.metrics.resources.requests.cpu¶
Type: string
"200m"
postgresql.metrics.resources.requests.memory¶
Type: string
"256Mi"
postgresql.postgresqlDataDir¶
Type: string
"/var/lib/postgresql/pgdata/data"
postgresql.volumePermissions.enabled¶
Type: bool
false