istiod values.yaml
📜
networkPolicies.enabled📜
Type: bool
false
networkPolicies.additionalPolicies📜
Type: list
[]
monitoring.enabled📜
Type: bool
true
mtls.mode📜
Type: string
"STRICT"
defaultSecurityHeaders.enabled📜
Type: bool
true
upstream.autoscaleEnabled📜
Type: bool
true
upstream.autoscaleMin📜
Type: int
1
upstream.autoscaleMax📜
Type: int
5
upstream.autoscaleBehavior📜
Type: object
{}
upstream.replicaCount📜
Type: int
1
upstream.rollingMaxSurge📜
Type: string
"100%"
upstream.rollingMaxUnavailable📜
Type: string
"25%"
upstream.hub📜
Type: string
""
upstream.tag📜
Type: string
""
upstream.variant📜
Type: string
""
upstream.image📜
Type: string
"pilot"
upstream.traceSampling📜
Type: float
1
upstream.resources.requests.cpu📜
Type: string
"500m"
upstream.resources.requests.memory📜
Type: string
"2048Mi"
upstream.seccompProfile📜
Type: object
{}
upstream.cni.enabled📜
Type: bool
false
upstream.cni.provider📜
Type: string
"default"
upstream.extraContainerArgs📜
Type: list
[]
upstream.env.ENABLE_NATIVE_SIDECARS📜
Type: string
"true"
upstream.taint.enabled📜
Type: bool
false
upstream.taint.namespace📜
Type: string
""
upstream.affinity📜
Type: object
{}
upstream.tolerations📜
Type: list
[]
upstream.cpu.targetAverageUtilization📜
Type: int
80
upstream.memory📜
Type: object
{}
upstream.volumeMounts📜
Type: list
[]
upstream.volumes📜
Type: list
[]
upstream.initContainers📜
Type: list
[]
upstream.nodeSelector📜
Type: object
{}
upstream.podAnnotations📜
Type: object
{}
upstream.serviceAnnotations📜
Type: object
{}
upstream.serviceAccountAnnotations📜
Type: object
{}
upstream.sidecarInjectorWebhookAnnotations📜
Type: object
{}
upstream.topologySpreadConstraints📜
Type: list
[]
upstream.jwksResolverExtraRootCA📜
Type: string
""
upstream.keepaliveMaxServerConnectionAge📜
Type: string
"30m"
upstream.deploymentLabels📜
Type: object
{}
upstream.configMap📜
Type: bool
true
upstream.podLabels📜
Type: object
{}
upstream.ipFamilyPolicy📜
Type: string
""
upstream.ipFamilies📜
Type: list
[]
upstream.trustedZtunnelNamespace📜
Type: string
""
upstream.sidecarInjectorWebhook.neverInjectSelector📜
Type: list
[]
upstream.sidecarInjectorWebhook.alwaysInjectSelector📜
Type: list
[]
upstream.sidecarInjectorWebhook.injectedAnnotations📜
Type: object
{}
upstream.sidecarInjectorWebhook.enableNamespacesByDefault📜
Type: bool
false
upstream.sidecarInjectorWebhook.reinvocationPolicy📜
Type: string
"Never"
upstream.sidecarInjectorWebhook.rewriteAppHTTPProbe📜
Type: bool
true
upstream.sidecarInjectorWebhook.templates📜
Type: object
{}
upstream.sidecarInjectorWebhook.defaultTemplates📜
Type: list
[]
upstream.istiodRemote.enabled📜
Type: bool
false
upstream.istiodRemote.injectionURL📜
Type: string
""
upstream.istiodRemote.injectionPath📜
Type: string
"/inject"
upstream.istiodRemote.injectionCABundle📜
Type: string
""
upstream.telemetry.enabled📜
Type: bool
true
upstream.telemetry.v2.enabled📜
Type: bool
true
upstream.telemetry.v2.prometheus.enabled📜
Type: bool
true
upstream.telemetry.v2.stackdriver.enabled📜
Type: bool
false
upstream.revision📜
Type: string
""
upstream.revisionTags📜
Type: list
[]
upstream.ownerName📜
Type: string
""
upstream.meshConfig.enablePrometheusMerge📜
Type: bool
true
upstream.meshConfig.accessLogFile📜
Type: string
"/dev/stdout"
upstream.meshConfig.meshMTLS.minProtocolVersion📜
Type: string
"TLSV1_2"
upstream.experimental.stableValidationPolicy📜
Type: bool
false
upstream.global.istioNamespace📜
Type: string
"istio-system"
upstream.global.certSigners📜
Type: list
[]
upstream.global.defaultPodDisruptionBudget.enabled📜
Type: bool
true
upstream.global.defaultResources.requests.cpu📜
Type: string
"10m"
upstream.global.hub📜
Type: string
"registry1.dso.mil/ironbank/opensource/istio"
upstream.global.tag📜
Type: string
"1.25.1"
upstream.global.variant📜
Type: string
""
upstream.global.imagePullPolicy📜
Type: string
""
upstream.global.imagePullSecrets📜
Type: list
[]
upstream.global.istiod.enableAnalysis📜
Type: bool
false
upstream.global.logAsJson📜
Type: bool
false
upstream.global.logging.level📜
Type: string
"default:info"
upstream.global.omitSidecarInjectorConfigMap📜
Type: bool
false
upstream.global.operatorManageWebhooks📜
Type: bool
false
upstream.global.priorityClassName📜
Type: string
""
upstream.global.proxy.image📜
Type: string
"proxyv2"
upstream.global.proxy.autoInject📜
Type: string
"enabled"
upstream.global.proxy.clusterDomain📜
Type: string
"cluster.local"
upstream.global.proxy.componentLogLevel📜
Type: string
"misc:error"
upstream.global.proxy.excludeInboundPorts📜
Type: string
""
upstream.global.proxy.includeInboundPorts📜
Type: string
"*"
upstream.global.proxy.includeIPRanges📜
Type: string
"*"
upstream.global.proxy.excludeIPRanges📜
Type: string
""
upstream.global.proxy.includeOutboundPorts📜
Type: string
""
upstream.global.proxy.excludeOutboundPorts📜
Type: string
""
upstream.global.proxy.logLevel📜
Type: string
"warning"
upstream.global.proxy.outlierLogPath📜
Type: string
""
upstream.global.proxy.privileged📜
Type: bool
false
upstream.global.proxy.readinessFailureThreshold📜
Type: int
4
upstream.global.proxy.readinessInitialDelaySeconds📜
Type: int
0
upstream.global.proxy.readinessPeriodSeconds📜
Type: int
15
upstream.global.proxy.startupProbe.enabled📜
Type: bool
true
upstream.global.proxy.startupProbe.failureThreshold📜
Type: int
600
upstream.global.proxy.resources.requests.cpu📜
Type: string
"100m"
upstream.global.proxy.resources.requests.memory📜
Type: string
"128Mi"
upstream.global.proxy.resources.limits.memory📜
Type: string
"512Mi"
upstream.global.proxy.statusPort📜
Type: int
15020
upstream.global.proxy.tracer📜
Type: string
"none"
upstream.global.proxy_init.image📜
Type: string
"proxyv2"
upstream.global.proxy_init.forceApplyIptables📜
Type: bool
false
upstream.global.remotePilotAddress📜
Type: string
""
upstream.global.caAddress📜
Type: string
""
upstream.global.externalIstiod📜
Type: bool
false
upstream.global.configCluster📜
Type: bool
false
upstream.global.configValidation📜
Type: bool
true
upstream.global.meshID📜
Type: string
""
upstream.global.meshNetworks📜
Type: object
{}
upstream.global.mountMtlsCerts📜
Type: bool
false
upstream.global.multiCluster.enabled📜
Type: bool
false
upstream.global.multiCluster.clusterName📜
Type: string
""
upstream.global.network📜
Type: string
""
upstream.global.pilotCertProvider📜
Type: string
"istiod"
upstream.global.sds.token.aud📜
Type: string
"istio-ca"
upstream.global.sts.servicePort📜
Type: int
0
upstream.global.caName📜
Type: string
""
upstream.global.waypoint.resources.requests.cpu📜
Type: string
"100m"
upstream.global.waypoint.resources.requests.memory📜
Type: string
"128Mi"
upstream.global.waypoint.resources.limits.memory📜
Type: string
"256Mi"
upstream.global.waypoint.affinity📜
Type: object
{}
upstream.global.waypoint.topologySpreadConstraints📜
Type: list
[]
upstream.global.waypoint.nodeSelector📜
Type: object
{}
upstream.global.waypoint.tolerations📜
Type: list
[]
upstream.base.enableIstioConfigCRDs📜
Type: bool
true
upstream.gateways.securityContext📜
Type: object
{}
upstream.gateways.seccompProfile📜
Type: object
{}