neuvector values.yaml
📜
domain📜
Type: string
"dev.bigbang.mil"
istio.enabled📜
Type: bool
false
istio.injection📜
Type: string
"enabled"
istio.hardened.enabled📜
Type: bool
false
istio.hardened.customAuthorizationPolicies📜
Type: list
[]
istio.hardened.outboundTrafficPolicyMode📜
Type: string
"REGISTRY_ONLY"
istio.hardened.monitoring.enabled📜
Type: bool
true
istio.hardened.monitoring.namespaces[0]📜
Type: string
"monitoring"
istio.hardened.monitoring.principals[0]📜
Type: string
"cluster.local/ns/monitoring/sa/monitoring-grafana"
istio.hardened.monitoring.principals[1]📜
Type: string
"cluster.local/ns/monitoring/sa/monitoring-monitoring-kube-alertmanager"
istio.hardened.monitoring.principals[2]📜
Type: string
"cluster.local/ns/monitoring/sa/monitoring-monitoring-kube-operator"
istio.hardened.monitoring.principals[3]📜
Type: string
"cluster.local/ns/monitoring/sa/monitoring-monitoring-kube-prometheus"
istio.hardened.monitoring.principals[4]📜
Type: string
"cluster.local/ns/monitoring/sa/monitoring-monitoring-kube-state-metrics"
istio.hardened.monitoring.principals[5]📜
Type: string
"cluster.local/ns/monitoring/sa/monitoring-monitoring-prometheus-node-exporter"
istio.hardened.customServiceEntries📜
Type: list
[]
istio.neuvector.enabled📜
Type: bool
true
istio.neuvector.annotations📜
Type: object
{}
istio.neuvector.labels📜
Type: object
{}
istio.neuvector.gateways[0]📜
Type: string
"istio-system/main"
istio.neuvector.hosts[0]📜
Type: string
"neuvector.{{ .Values.domain }}"
istio.mtls📜
Type: object
mode: STRICT
Description: Default neuvector peer authentication
istio.mtls.mode📜
Type: string
"STRICT"
Description: STRICT = Allow only mutual TLS traffic, PERMISSIVE = Allow both plain text and mutual TLS traffic
networkPolicies.enabled📜
Type: bool
false
networkPolicies.ingressLabels.app📜
Type: string
"public-ingressgateway"
networkPolicies.ingressLabels.istio📜
Type: string
"ingressgateway"
networkPolicies.istioNamespaceSelector.ingress📜
Type: string
"istio-gateway"
networkPolicies.istioNamespaceSelector.egress📜
Type: string
"istio-gateway"
networkPolicies.controlPlaneCidr📜
Type: string
"0.0.0.0/0"
networkPolicies.additionalPolicies📜
Type: list
[]
monitoring.enabled📜
Type: bool
false
monitoring.namespace📜
Type: string
"monitoring"
bbtests.enabled📜
Type: bool
false
bbtests.cypress.artifacts📜
Type: bool
true
bbtests.cypress.envs.cypress_url📜
Type: string
"http://neuvector-service-webui.{{ .Release.Namespace }}.svc.cluster.local:8443"
bbtests.cypress.resources.requests.cpu📜
Type: string
"2"
bbtests.cypress.resources.requests.memory📜
Type: string
"4Gi"
bbtests.cypress.resources.limits.cpu📜
Type: string
"2"
bbtests.cypress.resources.limits.memory📜
Type: string
"4Gi"
bbtests.scripts.envs.URL📜
Type: string
"http://neuvector-service-webui.{{ .Release.Namespace }}.svc.cluster.local:8443"
global.imagePullSecrets📜
Type: string
nil
global.images.neuvector_csp_pod.tag📜
Type: string
"latest"
global.images.neuvector_csp_pod.image📜
Type: string
"neuvector-billing-azure-by-suse-llc"
global.images.neuvector_csp_pod.registry📜
Type: string
"registry.suse.de/suse/sle-15-sp5/update/pubclouds/images"
global.images.neuvector_csp_pod.imagePullPolicy📜
Type: string
"Always"
global.images.controller.tag📜
Type: string
"5.4.3"
global.images.controller.image📜
Type: string
"controller"
global.images.controller.registry📜
Type: string
"registry1.dso.mil/ironbank/neuvector/neuvector"
global.images.manager.tag📜
Type: string
"5.4.3"
global.images.manager.image📜
Type: string
"manager"
global.images.manager.registry📜
Type: string
"registry1.dso.mil/ironbank/neuvector/neuvector"
global.images.enforcer.tag📜
Type: string
"5.4.3"
global.images.enforcer.image📜
Type: string
"enforcer"
global.images.enforcer.registry📜
Type: string
"registry1.dso.mil/ironbank/neuvector/neuvector"
upstream.nameOverride📜
Type: string
"neuvector"
upstream.fullnameOverride📜
Type: string
"neuvector-neuvector"
upstream.openshift📜
Type: bool
false
upstream.registry📜
Type: string
"registry1.dso.mil"
upstream.tag📜
Type: string
"5.4.4"
upstream.imagePullSecrets📜
Type: string
"private-registry"
upstream.crdwebhook.enabled📜
Type: bool
false
upstream.controller.enabled📜
Type: bool
true
upstream.controller.image.repository📜
Type: string
"ironbank/neuvector/neuvector/controller"
upstream.controller.image.imagePullPolicy📜
Type: string
"Always"
upstream.controller.podAnnotations.”traffic.sidecar.istio.io/excludeInboundPorts”📜
Type: string
"18500"
upstream.controller.containerSecurityContext.privileged📜
Type: bool
true
upstream.controller.containerSecurityContext.runAsUser📜
Type: int
1000
upstream.controller.containerSecurityContext.runAsNonRoot📜
Type: bool
true
upstream.controller.containerSecurityContext.capabilities.drop[0]📜
Type: string
"ALL"
upstream.controller.certupgrader.imagePullPolicy📜
Type: string
"Always"
upstream.controller.certupgrader.podAnnotations.”traffic.sidecar.istio.io/excludeInboundPorts”📜
Type: string
"18500"
upstream.controller.certupgrader.podAnnotations.”traffic.sidecar.istio.io/excludeOutboundPorts”📜
Type: string
"18500"
upstream.controller.certupgrader.securityContext.runAsNonRoot📜
Type: bool
true
upstream.controller.certupgrader.securityContext.runAsUser📜
Type: int
1000
upstream.controller.certupgrader.securityContext.runAsGroup📜
Type: int
1000
upstream.controller.certupgrader.securityContext.fsGroup📜
Type: int
1000
upstream.controller.certupgrader.containerSecurityContext.runAsUser📜
Type: int
1000
upstream.controller.certupgrader.containerSecurityContext.runAsGroup📜
Type: int
1000
upstream.controller.certupgrader.containerSecurityContext.runAsNonRoot📜
Type: bool
true
upstream.controller.certupgrader.containerSecurityContext.capabilities.drop[0]📜
Type: string
"ALL"
upstream.controller.apisvc.type📜
Type: string
"ClusterIP"
upstream.controller.apisvc.annotations📜
Type: object
{}
upstream.controller.apisvc.nodePort📜
Type: string
nil
upstream.controller.prime.enabled📜
Type: bool
false
upstream.controller.prime.image.repository📜
Type: string
"neuvector/compliance-config"
upstream.controller.prime.image.tag📜
Type: string
"1.0.5"
upstream.enforcer.enabled📜
Type: bool
true
upstream.enforcer.image.repository📜
Type: string
"ironbank/neuvector/neuvector/enforcer"
upstream.enforcer.image.imagePullPolicy📜
Type: string
"Always"
upstream.enforcer.podAnnotations.”traffic.sidecar.istio.io/excludeInboundPorts”📜
Type: string
"18500"
upstream.enforcer.containerSecurityContext.privileged📜
Type: bool
true
upstream.enforcer.containerSecurityContext.runAsGroup📜
Type: int
1000
upstream.enforcer.containerSecurityContext.capabilities.drop[0]📜
Type: string
"ALL"
upstream.manager.enabled📜
Type: bool
true
upstream.manager.image.repository📜
Type: string
"ironbank/neuvector/neuvector/manager"
upstream.manager.image.imagePullPolicy📜
Type: string
"Always"
upstream.manager.env.ssl📜
Type: bool
false
upstream.manager.podAnnotations.”traffic.sidecar.istio.io/excludeInboundPorts”📜
Type: string
"18500"
upstream.manager.containerSecurityContext.runAsUser📜
Type: int
1000
upstream.manager.containerSecurityContext.runAsGroup📜
Type: int
1000
upstream.manager.containerSecurityContext.runAsNonRoot📜
Type: bool
true
upstream.manager.containerSecurityContext.capabilities.drop[0]📜
Type: string
"ALL"
upstream.manager.securityContext.runAsNonRoot📜
Type: bool
true
upstream.manager.securityContext.runAsUser📜
Type: int
1000
upstream.manager.securityContext.runAsGroup📜
Type: int
1000
upstream.manager.securityContext.fsGroup📜
Type: int
1000
upstream.cve.adapter.enabled📜
Type: bool
false
upstream.cve.adapter.image.repository📜
Type: string
"neuvector/registry-adapter"
upstream.cve.adapter.image.tag📜
Type: string
"0.1.7"
upstream.cve.adapter.image.”traffic.sidecar.istio.io/excludeInboundPorts”📜
Type: string
"18500"
upstream.cve.adapter.securityContext.runAsUser📜
Type: int
1000
upstream.cve.adapter.securityContext.runAsGroup📜
Type: int
1000
upstream.cve.adapter.securityContext.fsGroup📜
Type: int
1000
upstream.cve.adapter.securityContext.runAsNonRoot📜
Type: bool
true
upstream.cve.updater.enabled📜
Type: bool
true
upstream.cve.updater.secure📜
Type: bool
false
upstream.cve.updater.cacert📜
Type: string
"/var/run/secrets/kubernetes.io/serviceaccount/ca.crt"
upstream.cve.updater.image.registry📜
Type: string
"registry1.dso.mil"
upstream.cve.updater.image.repository📜
Type: string
"ironbank/big-bang/base"
upstream.cve.updater.image.imagePullPolicy📜
Type: string
"Always"
upstream.cve.updater.image.tag📜
Type: string
"2.1.0"
upstream.cve.updater.podAnnotations.”traffic.sidecar.istio.io/excludeInboundPorts”📜
Type: string
"18500"
upstream.cve.updater.securityContext.runAsUser📜
Type: int
1000
upstream.cve.updater.securityContext.runAsGroup📜
Type: int
1000
upstream.cve.updater.securityContext.fsGroup📜
Type: int
1000
upstream.cve.updater.securityContext.runAsNonRoot📜
Type: bool
true
upstream.cve.updater.containerSecurityContext.runAsUser📜
Type: int
1000
upstream.cve.updater.containerSecurityContext.runAsGroup📜
Type: int
1000
upstream.cve.updater.containerSecurityContext.runAsNonRoot📜
Type: bool
true
upstream.cve.updater.containerSecurityContext.capabilities.drop[0]📜
Type: string
"ALL"
upstream.cve.scanner.enabled📜
Type: bool
true
upstream.cve.scanner.image.repository📜
Type: string
"ironbank/neuvector/neuvector/scanner"
upstream.cve.scanner.image.imagePullPolicy📜
Type: string
"Always"
upstream.cve.scanner.image.tag📜
Type: string
"6"
upstream.cve.scanner.podAnnotations.”traffic.sidecar.istio.io/excludeInboundPorts”📜
Type: string
"18500"
upstream.cve.scanner.runAsUser📜
Type: string
nil
upstream.cve.scanner.securityContext.runAsUser📜
Type: int
1000
upstream.cve.scanner.securityContext.runAsGroup📜
Type: int
1000
upstream.cve.scanner.securityContext.fsGroup📜
Type: int
1000
upstream.cve.scanner.securityContext.runAsNonRoot📜
Type: bool
true
upstream.cve.scanner.containerSecurityContext.runAsUser📜
Type: int
1000
upstream.cve.scanner.containerSecurityContext.runAsGroup📜
Type: int
1000
upstream.cve.scanner.containerSecurityContext.runAsNonRoot📜
Type: bool
true
upstream.cve.scanner.containerSecurityContext.capabilities.drop[0]📜
Type: string
"ALL"
monitor.imagePullSecrets📜
Type: string
"private-registry"
monitor.install📜
Type: bool
false
monitor.serviceAccount📜
Type: string
"default"
monitor.registry📜
Type: string
"registry1.dso.mil"
monitor.exporter.enabled📜
Type: bool
false
monitor.exporter.serviceMonitor.enabled📜
Type: bool
false
monitor.exporter.svc.enabled📜
Type: bool
false
monitor.exporter.image.repository📜
Type: string
"ironbank/neuvector/neuvector/prometheus-exporter"
monitor.exporter.image.tag📜
Type: string
"1-1.0.0"
monitor.exporter.image.imagePullPolicy📜
Type: string
"Always"
monitor.exporter.containerSecurityContext.runAsUser📜
Type: int
1001
monitor.exporter.containerSecurityContext.runAsGroup📜
Type: int
1001
monitor.exporter.containerSecurityContext.capabilities.drop[0]📜
Type: string
"ALL"