Skip to content

Big Bang values.yaml📜

domain📜

Type: string

Default value
"dev.bigbang.mil"

Description: Domain used for BigBang created exposed services, can be overridden by individual packages.

offline📜

Type: bool

Default value
false

Description: (experimental) Toggle sourcing from external repos. All this does right now is toggle GitRepositories, it is not fully functional

helmRepositories📜

Type: list

Default value
[]

Description: List of Helm repositories/credentials to pull helm charts from. OCI Type: Must specify username/password or existingSecret if repository requires auth. Using “private-registry” for existingSecret will reuse credentials from registryCredentials above. Default Type: Must specify existingSecret with auth - see https://fluxcd.io/flux/components/source/helmrepositories/#secret-reference for details on secret data required.

registryCredentials📜

Type: object

Default value
email: ''
password: ''
registry: registry1.dso.mil
username: ''

Description: Single set of registry credentials used to pull all images deployed by BigBang.

openshift📜

Type: bool

Default value
false

Description: Multiple sets of registry credentials used to pull all images deployed by BigBang. Credentials will only be created when a valid combination exists, registry, username, and password (email is optional) Or a list of registires: - registry: registry1.dso.mil username: “” password: “” email: “” - registry: registry.dso.mil username: “” password: “” email: “” Openshift Container Platform Feature Toggle

git📜

Type: object

Default value
credentials:
  caFile: ''
  knownHosts: ''
  password: ''
  privateKey: ''
  publicKey: ''
  username: ''
existingSecret: ''

Description: Git credential settings for accessing private repositories Order of precedence is: 1. existingSecret 2. http credentials (username/password/caFile) 3. ssh credentials (privateKey/publicKey/knownHosts)

git.existingSecret📜

Type: string

Default value
""

Description: Existing secret to use for git credentials, must be in the appropriate format: https://toolkit.fluxcd.io/components/source/gitrepositories/#https-authentication

git.credentials📜

Type: object

Default value
caFile: ''
knownHosts: ''
password: ''
privateKey: ''
publicKey: ''
username: ''

Description: Chart created secrets with user defined values

git.credentials.username📜

Type: string

Default value
""

Description: HTTP git credentials, both username and password must be provided

git.credentials.caFile📜

Type: string

Default value
""

Description: HTTPS certificate authority file. Required for any repo with a self signed certificate

git.credentials.privateKey📜

Type: string

Default value
""

Description: SSH git credentials, privateKey, publicKey, and knownHosts must be provided

sso📜

Type: object

Default value
certificateAuthority:
  cert: ''
  secretName: tls-ca-sso
name: SSO
oidc:
  authorization: '{{ .Values.sso.url }}/protocol/openid-connect/auth'
  claims:
    email: email
    groups: groups
    name: name
    username: preferred_username
  endSession: '{{ .Values.sso.url }}/protocol/openid-connect/logout'
  jwks: ''
  jwksUri: '{{ .Values.sso.url }}/protocol/openid-connect/certs'
  token: '{{ .Values.sso.url }}/protocol/openid-connect/token'
  userinfo: '{{ .Values.sso.url }}/protocol/openid-connect/userinfo'
saml:
  entityDescriptor: '{{ .Values.sso.url }}/protocol/saml/descriptor'
  metadata: ''
  service: '{{ .Values.sso.url }}/protocol/saml'
url: https://login.dso.mil/auth/realms/baby-yoda

Description: Global SSO values used for BigBang deployments when sso is enabled

sso.name📜

Type: string

Default value
"SSO"

Description: Name of the identity provider. This is used by some packages as the SSO login label.

sso.url📜

Type: string

Default value
"https://login.dso.mil/auth/realms/baby-yoda"

Description: Base URL for the identity provider. For OIDC, this is the issuer. For SAML this is the entityID.

sso.certificateAuthority📜

Type: object

Default value
cert: ''
secretName: tls-ca-sso

Description: Certificate authority for the identity provider’s certificates

sso.certificateAuthority.cert📜

Type: string

Default value
""

Description: The certificate authority public certificate in .pem format. Populating this will create a secret in each namespace that enables SSO.

sso.certificateAuthority.secretName📜

Type: string

Default value
"tls-ca-sso"

Description: The secret name to use for the certificate authority. Can be manually populated if cert is blank.

sso.saml.entityDescriptor📜

Type: string

Default value
"{{ .Values.sso.url }}/protocol/saml/descriptor"

Description: SAML entityDescriptor (metadata) path

sso.saml.service📜

Type: string

Default value
"{{ .Values.sso.url }}/protocol/saml"

Description: SAML SSO Service path

sso.saml.metadata📜

Type: string

Default value
""

Description: Literal SAML XML metadata retrieved from {{ .Values.sso.saml.entityDescriptor }}. Required for SSO in Nexus, Twistlock, or Sonarqube.

sso.oidc📜

Type: object

Default value
authorization: '{{ .Values.sso.url }}/protocol/openid-connect/auth'
claims:
  email: email
  groups: groups
  name: name
  username: preferred_username
endSession: '{{ .Values.sso.url }}/protocol/openid-connect/logout'
jwks: ''
jwksUri: '{{ .Values.sso.url }}/protocol/openid-connect/certs'
token: '{{ .Values.sso.url }}/protocol/openid-connect/token'
userinfo: '{{ .Values.sso.url }}/protocol/openid-connect/userinfo'

Description: OIDC endpoints can be retrieved from {{ .Values.sso.url }}/.well-known/openid-configuration

sso.oidc.authorization📜

Type: string

Default value
"{{ .Values.sso.url }}/protocol/openid-connect/auth"

Description: OIDC authorization path

sso.oidc.endSession📜

Type: string

Default value
"{{ .Values.sso.url }}/protocol/openid-connect/logout"

Description: OIDC logout / end session path

sso.oidc.jwksUri📜

Type: string

Default value
"{{ .Values.sso.url }}/protocol/openid-connect/certs"

Description: OIDC JSON Web Key Set (JWKS) path

sso.oidc.token📜

Type: string

Default value
"{{ .Values.sso.url }}/protocol/openid-connect/token"

Description: OIDC token path

sso.oidc.userinfo📜

Type: string

Default value
"{{ .Values.sso.url }}/protocol/openid-connect/userinfo"

Description: OIDC user information path

sso.oidc.jwks📜

Type: string

Default value
""

Description: Literal OIDC JWKS data retrieved from JWKS Uri. Only needed if jwsksUri is not defined.

sso.oidc.claims📜

Type: object

Default value
email: email
groups: groups
name: name
username: preferred_username

Description: Identity provider claim names that store metadata about the authenticated user.

sso.oidc.claims.email📜

Type: string

Default value
"email"

Description: IdP’s claim name used for the user’s email address.

sso.oidc.claims.name📜

Type: string

Default value
"name"

Description: IdP’s claim name used for the user’s full name

sso.oidc.claims.username📜

Type: string

Default value
"preferred_username"

Description: IdP’s claim name used for the username

sso.oidc.claims.groups📜

Type: string

Default value
"groups"

Description: IdP’s claim name used for the user’s groups or roles

flux📜

Type: object

Default value
install:
  remediation:
    retries: -1
interval: 2m
rollback:
  cleanupOnFail: true
  timeout: 10m
test:
  enable: false
timeout: 10m
upgrade:
  cleanupOnFail: true
  remediation:
    remediateLastFailure: true
    retries: 3

Description: (Advanced) Flux reconciliation parameters. The default values provided will be sufficient for the majority of workloads.

networkPolicies📜

Type: object

Default value
controlPlaneCidr: 0.0.0.0/0
enabled: true
nodeCidr: ''
vpcCidr: 0.0.0.0/0

Description: Global NetworkPolicies settings

networkPolicies.enabled📜

Type: bool

Default value
true

Description: Toggle all package NetworkPolicies, can disable specific packages with package.values.networkPolicies.enabled

networkPolicies.controlPlaneCidr📜

Type: string

Default value
"0.0.0.0/0"

Description: Control Plane CIDR, defaults to 0.0.0.0/0, use kubectl get endpoints -n default kubernetes to get the CIDR range needed for your cluster Must be an IP CIDR range (x.x.x.x/x - ideally with /32 for the specific IP of a single endpoint, broader range for multiple masters/endpoints) Used by package NetworkPolicies to allow Kube API access

networkPolicies.nodeCidr📜

Type: string

Default value
""

Description: Node CIDR, defaults to allowing “10.0.0.0/8” “172.16.0.0/12” “192.168.0.0/16” “100.64.0.0/10” networks. use kubectl get nodes -owide and review the INTERNAL-IP column to derive CIDR range. Must be an IP CIDR range (x.x.x.x/x - ideally a /16 or /24 to include multiple IPs)

networkPolicies.vpcCidr📜

Type: string

Default value
"0.0.0.0/0"

Description: VPC CIDR, defaults to 0.0.0.0/0 In a production environment, it is recommended to setup a Private Endpoint for your AWS services like KMS or S3. Please review https://docs.aws.amazon.com/kms/latest/developerguide/kms-vpc-endpoint.html to setup routing to AWS services that never leave the AWS network. Once created update networkPolicies.vpcCidr to match the CIDR of your VPC so Vault will be able to reach your VPCs DNS and new KMS endpoint.

imagePullPolicy📜

Type: string

Default value
"IfNotPresent"

Description: Global ImagePullPolicy value for all packages Permitted values are: None, Always, IfNotPresent

istio.enabled📜

Type: bool

Default value
true

Description: Toggle deployment of Istio.

istio.mtls.mode📜

Type: string

Default value
"STRICT"

Description: STRICT = Allow only mutual TLS traffic, PERMISSIVE = Allow both plain text and mutual TLS traffic

istio.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

istio.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/istio-controlplane.git"

istio.git.path📜

Type: string

Default value
"./chart"

istio.git.tag📜

Type: string

Default value
"1.20.4-bb.1"

istio.helmRepo.repoName📜

Type: string

Default value
"registry1"

istio.helmRepo.chartName📜

Type: string

Default value
"istio"

istio.helmRepo.tag📜

Type: string

Default value
"1.20.4-bb.1"

istio.enterprise📜

Type: bool

Default value
false

Description: Tetrate Istio Distribution - Tetrate provides FIPs verified Istio and Envoy software and support, validated through the FIPs Boring Crypto module. Find out more from Tetrate - https://www.tetrate.io/tetrate-istio-subscription

istio.ingressGateways.public-ingressgateway.type📜

Type: string

Default value
"LoadBalancer"

istio.ingressGateways.public-ingressgateway.kubernetesResourceSpec📜

Type: object

Default value
{}

istio.gateways.public.ingressGateway📜

Type: string

Default value
"public-ingressgateway"

istio.gateways.public.hosts[0]📜

Type: string

Default value
"*.{{ .Values.domain }}"

istio.gateways.public.autoHttpRedirect📜

Type: object

Default value
enabled: true

Description: Controls default HTTP/8080 server entry with HTTP to HTTPS Redirect.

istio.gateways.public.tls.key📜

Type: string

Default value
""

istio.gateways.public.tls.cert📜

Type: string

Default value
""

istio.gateways.public.tls.minProtocolVersion📜

Type: string

Default value
""

istio.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Istio Package

istio.values📜

Type: object

Default value
{}

Description: Values to passthrough to the istio-controlplane chart: https://repo1.dso.mil/big-bang/product/packages/istio-controlplane.git

istio.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

istioOperator.enabled📜

Type: bool

Default value
true

Description: Toggle deployment of Istio Operator.

istioOperator.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

istioOperator.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/istio-operator.git"

istioOperator.git.path📜

Type: string

Default value
"./chart"

istioOperator.git.tag📜

Type: string

Default value
"1.20.4-bb.0"

istioOperator.helmRepo.repoName📜

Type: string

Default value
"registry1"

istioOperator.helmRepo.chartName📜

Type: string

Default value
"istio-operator"

istioOperator.helmRepo.tag📜

Type: string

Default value
"1.20.4-bb.0"

istioOperator.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Istio Operator Package

istioOperator.values📜

Type: object

Default value
{}

Description: Values to passthrough to the istio-operator chart: https://repo1.dso.mil/big-bang/product/packages/istio-operator.git

istioOperator.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

jaeger.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of Jaeger.

jaeger.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

jaeger.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/jaeger.git"

jaeger.git.path📜

Type: string

Default value
"./chart"

jaeger.git.tag📜

Type: string

Default value
"2.50.1-bb.2"

jaeger.helmRepo.repoName📜

Type: string

Default value
"registry1"

jaeger.helmRepo.chartName📜

Type: string

Default value
"jaeger"

jaeger.helmRepo.tag📜

Type: string

Default value
"2.50.1-bb.2"

jaeger.flux📜

Type: object

Default value
install:
  crds: CreateReplace
upgrade:
  crds: CreateReplace

Description: Flux reconciliation overrides specifically for the Jaeger Package

jaeger.ingress📜

Type: object

Default value
gateway: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

jaeger.sso.enabled📜

Type: bool

Default value
false

Description: Toggle SSO for Jaeger on and off

jaeger.sso.client_id📜

Type: string

Default value
""

Description: OIDC Client ID to use for Jaeger

jaeger.sso.client_secret📜

Type: string

Default value
""

Description: OIDC Client Secret to use for Jaeger

jaeger.values📜

Type: object

Default value
{}

Description: Values to pass through to Jaeger chart: https://repo1.dso.mil/big-bang/product/packages/jaeger.git

jaeger.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

kiali.enabled📜

Type: bool

Default value
true

Description: Toggle deployment of Kiali.

kiali.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

kiali.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/kiali.git"

kiali.git.path📜

Type: string

Default value
"./chart"

kiali.git.tag📜

Type: string

Default value
"1.82.0-bb.3"

kiali.helmRepo.repoName📜

Type: string

Default value
"registry1"

kiali.helmRepo.chartName📜

Type: string

Default value
"kiali"

kiali.helmRepo.tag📜

Type: string

Default value
"1.82.0-bb.3"

kiali.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Kiali Package

kiali.ingress📜

Type: object

Default value
gateway: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

kiali.sso.enabled📜

Type: bool

Default value
false

Description: Toggle SSO for Kiali on and off

kiali.sso.client_id📜

Type: string

Default value
""

Description: OIDC Client ID to use for Kiali

kiali.sso.client_secret📜

Type: string

Default value
""

Description: OIDC Client Secret to use for Kiali

kiali.values📜

Type: object

Default value
{}

Description: Values to pass through to Kiali chart: https://repo1.dso.mil/big-bang/product/packages/kiali

kiali.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

clusterAuditor.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of Cluster Auditor.

clusterAuditor.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

clusterAuditor.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/cluster-auditor.git"

clusterAuditor.git.path📜

Type: string

Default value
"./chart"

clusterAuditor.git.tag📜

Type: string

Default value
"1.5.0-bb.15"

clusterAuditor.helmRepo.repoName📜

Type: string

Default value
"registry1"

clusterAuditor.helmRepo.chartName📜

Type: string

Default value
"cluster-auditor"

clusterAuditor.helmRepo.tag📜

Type: string

Default value
"1.5.0-bb.15"

clusterAuditor.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Cluster Auditor Package

clusterAuditor.values📜

Type: object

Default value
{}

Description: Values to passthrough to the cluster auditor chart: https://repo1.dso.mil/big-bang/product/packages/cluster-auditor.git

clusterAuditor.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

gatekeeper.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of OPA Gatekeeper.

gatekeeper.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

gatekeeper.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/policy.git"

gatekeeper.git.path📜

Type: string

Default value
"./chart"

gatekeeper.git.tag📜

Type: string

Default value
"3.15.0-bb.4"

gatekeeper.helmRepo.repoName📜

Type: string

Default value
"registry1"

gatekeeper.helmRepo.chartName📜

Type: string

Default value
"gatekeeper"

gatekeeper.helmRepo.tag📜

Type: string

Default value
"3.15.0-bb.4"

gatekeeper.flux📜

Type: object

Default value
install:
  crds: CreateReplace
upgrade:
  crds: CreateReplace

Description: Flux reconciliation overrides specifically for the OPA Gatekeeper Package

gatekeeper.values📜

Type: object

Default value
{}

Description: Values to passthrough to the gatekeeper chart: https://repo1.dso.mil/big-bang/product/packages/policy.git

gatekeeper.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

kyverno.enabled📜

Type: bool

Default value
true

Description: Toggle deployment of Kyverno.

kyverno.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

kyverno.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/kyverno.git"

kyverno.git.path📜

Type: string

Default value
"./chart"

kyverno.git.tag📜

Type: string

Default value
"3.1.4-bb.5"

kyverno.helmRepo.repoName📜

Type: string

Default value
"registry1"

kyverno.helmRepo.chartName📜

Type: string

Default value
"kyverno"

kyverno.helmRepo.tag📜

Type: string

Default value
"3.1.4-bb.5"

kyverno.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Kyverno Package

kyverno.values📜

Type: object

Default value
{}

Description: Values to passthrough to the kyverno chart: https://repo1.dso.mil/big-bang/product/packages/kyverno.git

kyverno.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

kyvernoPolicies.enabled📜

Type: bool

Default value
true

Description: Toggle deployment of Kyverno policies

kyvernoPolicies.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

kyvernoPolicies.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/kyverno-policies.git"

kyvernoPolicies.git.path📜

Type: string

Default value
"./chart"

kyvernoPolicies.git.tag📜

Type: string

Default value
"3.0.4-bb.28"

kyvernoPolicies.helmRepo.repoName📜

Type: string

Default value
"registry1"

kyvernoPolicies.helmRepo.chartName📜

Type: string

Default value
"kyverno-policies"

kyvernoPolicies.helmRepo.tag📜

Type: string

Default value
"3.0.4-bb.28"

kyvernoPolicies.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Kyverno Package

kyvernoPolicies.values📜

Type: object

Default value
{}

Description: Values to passthrough to the kyverno policies chart: https://repo1.dso.mil/big-bang/product/packages/kyverno-policies.git

kyvernoPolicies.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

kyvernoReporter.enabled📜

Type: bool

Default value
true

Description: Toggle deployment of Kyverno Reporter

kyvernoReporter.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

kyvernoReporter.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/kyverno-reporter.git"

kyvernoReporter.git.path📜

Type: string

Default value
"./chart"

kyvernoReporter.git.tag📜

Type: string

Default value
"2.22.4-bb.2"

kyvernoReporter.helmRepo.repoName📜

Type: string

Default value
"registry1"

kyvernoReporter.helmRepo.chartName📜

Type: string

Default value
"kyverno-reporter"

kyvernoReporter.helmRepo.tag📜

Type: string

Default value
"2.22.4-bb.2"

kyvernoReporter.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Kyverno Reporter Package

kyvernoReporter.values📜

Type: object

Default value
{}

Description: Values to passthrough to the kyverno reporter chart: https://repo1.dso.mil/big-bang/product/packages/kyverno-reporter.git

kyvernoReporter.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

elasticsearchKibana.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of Logging (EFK).

elasticsearchKibana.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

elasticsearchKibana.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/elasticsearch-kibana.git"

elasticsearchKibana.git.path📜

Type: string

Default value
"./chart"

elasticsearchKibana.git.tag📜

Type: string

Default value
"1.12.0-bb.1"

elasticsearchKibana.helmRepo.repoName📜

Type: string

Default value
"registry1"

elasticsearchKibana.helmRepo.chartName📜

Type: string

Default value
"elasticsearch-kibana"

elasticsearchKibana.helmRepo.tag📜

Type: string

Default value
"1.12.0-bb.1"

elasticsearchKibana.flux📜

Type: object

Default value
timeout: 20m

Description: Flux reconciliation overrides specifically for the Logging (EFK) Package

elasticsearchKibana.ingress📜

Type: object

Default value
gateway: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

elasticsearchKibana.sso.enabled📜

Type: bool

Default value
false

Description: Toggle OIDC SSO for Kibana/Elasticsearch on and off. Enabling this option will auto-create any required secrets.

elasticsearchKibana.sso.client_id📜

Type: string

Default value
""

Description: Elasticsearch/Kibana OIDC client ID

elasticsearchKibana.sso.client_secret📜

Type: string

Default value
""

Description: Elasticsearch/Kibana OIDC client secret

elasticsearchKibana.license.trial📜

Type: bool

Default value
false

Description: Toggle trial license installation of elasticsearch. Note that enterprise (non trial) is required for SSO to work.

elasticsearchKibana.license.keyJSON📜

Type: string

Default value
""

Description: Elasticsearch license in json format seen here: https://repo1.dso.mil/big-bang/product/packages/elasticsearch-kibana#enterprise-license

elasticsearchKibana.values📜

Type: object

Default value
{}

Description: Values to passthrough to the elasticsearch-kibana chart: https://repo1.dso.mil/big-bang/product/packages/elasticsearch-kibana.git

elasticsearchKibana.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

eckOperator.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of ECK Operator.

eckOperator.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

eckOperator.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/eck-operator.git"

eckOperator.git.path📜

Type: string

Default value
"./chart"

eckOperator.git.tag📜

Type: string

Default value
"2.12.1-bb.0"

eckOperator.helmRepo.repoName📜

Type: string

Default value
"registry1"

eckOperator.helmRepo.chartName📜

Type: string

Default value
"eck-operator"

eckOperator.helmRepo.tag📜

Type: string

Default value
"2.12.1-bb.0"

eckOperator.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the ECK Operator Package

eckOperator.values📜

Type: object

Default value
{}

Description: Values to passthrough to the eck-operator chart: https://repo1.dso.mil/big-bang/product/packages/eck-operator.git

eckOperator.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

fluentbit.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of Fluent-Bit.

fluentbit.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

fluentbit.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/fluentbit.git"

fluentbit.git.path📜

Type: string

Default value
"./chart"

fluentbit.git.tag📜

Type: string

Default value
"0.46.0-bb.0"

fluentbit.helmRepo.repoName📜

Type: string

Default value
"registry1"

fluentbit.helmRepo.chartName📜

Type: string

Default value
"fluentbit"

fluentbit.helmRepo.tag📜

Type: string

Default value
"0.46.0-bb.0"

fluentbit.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Fluent-Bit Package

fluentbit.values📜

Type: object

Default value
{}

Description: Values to passthrough to the fluentbit chart: https://repo1.dso.mil/big-bang/product/packages/fluentbit.git

fluentbit.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

promtail.enabled📜

Type: bool

Default value
true

Description: Toggle deployment of Promtail.

promtail.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

promtail.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/promtail.git"

promtail.git.path📜

Type: string

Default value
"./chart"

promtail.git.tag📜

Type: string

Default value
"6.15.5-bb.3"

promtail.helmRepo.repoName📜

Type: string

Default value
"registry1"

promtail.helmRepo.chartName📜

Type: string

Default value
"promtail"

promtail.helmRepo.tag📜

Type: string

Default value
"6.15.5-bb.3"

promtail.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Promtail Package

promtail.values📜

Type: object

Default value
{}

Description: Values to passthrough to the promtail chart: https://repo1.dso.mil/big-bang/product/packages/fluentbit.git

promtail.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

loki.enabled📜

Type: bool

Default value
true

Description: Toggle deployment of Loki.

loki.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

loki.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/loki.git"

loki.git.path📜

Type: string

Default value
"./chart"

loki.git.tag📜

Type: string

Default value
"5.47.2-bb.2"

loki.helmRepo.repoName📜

Type: string

Default value
"registry1"

loki.helmRepo.chartName📜

Type: string

Default value
"loki"

loki.helmRepo.tag📜

Type: string

Default value
"5.47.2-bb.2"

loki.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Loki Package

loki.strategy📜

Type: string

Default value
"monolith"

Description: Loki architecture. Options are monolith and scalable

loki.objectStorage.endpoint📜

Type: string

Default value
""

Description: S3 compatible endpoint to use for connection information. examples: “https://s3.amazonaws.com” “https://s3.us-gov-west-1.amazonaws.com” “http://minio.minio.svc.cluster.local:9000”

loki.objectStorage.region📜

Type: string

Default value
""

Description: S3 compatible region to use for connection information.

loki.objectStorage.accessKey📜

Type: string

Default value
""

Description: Access key for connecting to object storage endpoint.

loki.objectStorage.accessSecret📜

Type: string

Default value
""

Description: Secret key for connecting to object storage endpoint. Unencoded string data. This should be placed in the secret values and then encrypted

loki.objectStorage.bucketNames📜

Type: object

Default value
{}

Description: Bucket Names for the Loki buckets as YAML chunks: loki-logs ruler: loki-ruler admin: loki-admin

loki.values📜

Type: object

Default value
{}

Description: Values to passthrough to the Loki chart: https://repo1.dso.mil/big-bang/product/packages/loki.git

loki.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

neuvector.enabled📜

Type: bool

Default value
true

Description: Toggle deployment of Neuvector.

neuvector.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

neuvector.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/neuvector.git"

neuvector.git.path📜

Type: string

Default value
"./chart"

neuvector.git.tag📜

Type: string

Default value
"2.6.3-bb.18"

neuvector.helmRepo.repoName📜

Type: string

Default value
"registry1"

neuvector.helmRepo.chartName📜

Type: string

Default value
"neuvector"

neuvector.helmRepo.tag📜

Type: string

Default value
"2.6.3-bb.18"

neuvector.ingress📜

Type: object

Default value
gateway: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

neuvector.sso.enabled📜

Type: bool

Default value
false

Description: Toggle SSO for Neuvector on and off

neuvector.sso.client_id📜

Type: string

Default value
""

Description: OIDC Client ID to use for Neuvector

neuvector.sso.client_secret📜

Type: string

Default value
""

Description: OIDC Client Secret to use for Neuvector

neuvector.sso.default_role📜

Type: string

Default value
""

Description: Default role to use for Neuvector OIDC users. Supports admin, reader, or no default

neuvector.sso.group_claim📜

Type: string

Default value
""

Description: Default role to use for Neuvector OIDC users. Supports admin, reader, or no default

neuvector.sso.group_mapped_roles📜

Type: list

Default value
[]

Description: Default role to use for Neuvector OIDC users. Supports admin, reader, or no default

neuvector.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Neuvector Package

neuvector.values📜

Type: object

Default value
{}

Description: Values to passthrough to the Neuvector chart: https://repo1.dso.mil/big-bang/product/packages/neuvector.git

neuvector.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

tempo.enabled📜

Type: bool

Default value
true

Description: Toggle deployment of Tempo.

tempo.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

tempo.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/tempo.git"

tempo.git.path📜

Type: string

Default value
"./chart"

tempo.git.tag📜

Type: string

Default value
"1.7.1-bb.6"

tempo.helmRepo.repoName📜

Type: string

Default value
"registry1"

tempo.helmRepo.chartName📜

Type: string

Default value
"tempo"

tempo.helmRepo.tag📜

Type: string

Default value
"1.7.1-bb.6"

tempo.ingress📜

Type: object

Default value
gateway: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

tempo.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Tempo Package

tempo.sso.enabled📜

Type: bool

Default value
false

Description: Toggle SSO for Tempo on and off

tempo.sso.client_id📜

Type: string

Default value
""

Description: OIDC Client ID to use for Tempo

tempo.sso.client_secret📜

Type: string

Default value
""

Description: OIDC Client Secret to use for Tempo

tempo.objectStorage.endpoint📜

Type: string

Default value
""

Description: S3 compatible endpoint to use for connection information. examples: “s3.amazonaws.com” “s3.us-gov-west-1.amazonaws.com” “minio.minio.svc.cluster.local:9000” Note: tempo does not require protocol prefix for URL.

tempo.objectStorage.region📜

Type: string

Default value
""

Description: S3 compatible region to use for connection information.

tempo.objectStorage.accessKey📜

Type: string

Default value
""

Description: Access key for connecting to object storage endpoint.

tempo.objectStorage.accessSecret📜

Type: string

Default value
""

Description: Secret key for connecting to object storage endpoint. Unencoded string data. This should be placed in the secret values and then encrypted

tempo.objectStorage.bucket📜

Type: string

Default value
""

Description: Bucket Name for Tempo examples: “tempo-traces”

tempo.objectStorage.insecure📜

Type: bool

Default value
false

Description: Whether or not objectStorage connection should require HTTPS, if connecting to in-cluster object storage on port 80/9000 set this value to true.

tempo.values📜

Type: object

Default value
{}

Description: Values to passthrough to the Tempo chart: https://repo1.dso.mil/big-bang/product/packages/tempo.git

tempo.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

monitoring.enabled📜

Type: bool

Default value
true

Description: Toggle deployment of Monitoring (Prometheus, Grafana, and Alertmanager).

monitoring.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

monitoring.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/monitoring.git"

monitoring.git.path📜

Type: string

Default value
"./chart"

monitoring.git.tag📜

Type: string

Default value
"58.0.0-bb.0"

monitoring.helmRepo.repoName📜

Type: string

Default value
"registry1"

monitoring.helmRepo.chartName📜

Type: string

Default value
"monitoring"

monitoring.helmRepo.tag📜

Type: string

Default value
"58.0.0-bb.0"

monitoring.flux📜

Type: object

Default value
install:
  crds: CreateReplace
upgrade:
  crds: CreateReplace

Description: Flux reconciliation overrides specifically for the Monitoring Package

monitoring.ingress📜

Type: object

Default value
gateway: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

monitoring.sso.enabled📜

Type: bool

Default value
false

Description: Toggle SSO for monitoring components on and off

monitoring.sso.prometheus.client_id📜

Type: string

Default value
""

Description: Prometheus OIDC client ID

monitoring.sso.prometheus.client_secret📜

Type: string

Default value
""

Description: Prometheus OIDC client secret

monitoring.sso.alertmanager.client_id📜

Type: string

Default value
""

Description: Alertmanager OIDC client ID

monitoring.sso.alertmanager.client_secret📜

Type: string

Default value
""

Description: Alertmanager OIDC client secret

monitoring.values📜

Type: object

Default value
{}

Description: Values to passthrough to the monitoring chart: https://repo1.dso.mil/big-bang/product/packages/monitoring.git

monitoring.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

grafana.enabled📜

Type: bool

Default value
true

Description: Toggle deployment of Grafana

grafana.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

grafana.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/grafana.git"

grafana.git.path📜

Type: string

Default value
"./chart"

grafana.git.tag📜

Type: string

Default value
"7.3.7-bb.1"

grafana.helmRepo.repoName📜

Type: string

Default value
"registry1"

grafana.helmRepo.chartName📜

Type: string

Default value
"grafana"

grafana.helmRepo.tag📜

Type: string

Default value
"7.3.7-bb.1"

grafana.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Monitoring Package

grafana.ingress📜

Type: object

Default value
gateway: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

grafana.sso.enabled📜

Type: bool

Default value
false

Description: Toggle SSO for grafana components on and off

grafana.sso.grafana.client_id📜

Type: string

Default value
""

Description: Grafana OIDC client ID

grafana.sso.grafana.client_secret📜

Type: string

Default value
""

Description: Grafana OIDC client secret

grafana.sso.grafana.scopes📜

Type: string

Default value
""

Description: Grafana OIDC client scopes, comma separated, see https://grafana.com/docs/grafana/latest/auth/generic-oauth/

grafana.sso.grafana.allow_sign_up📜

Type: bool

Default value
true

grafana.sso.grafana.role_attribute_path📜

Type: string

Default value
"Viewer"

grafana.values📜

Type: object

Default value
{}

Description: Values to passthrough to the grafana chart: https://repo1.dso.mil/big-bang/product/packages/grafana.git

grafana.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

twistlock.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of Twistlock.

twistlock.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

twistlock.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/twistlock.git"

twistlock.git.path📜

Type: string

Default value
"./chart"

twistlock.git.tag📜

Type: string

Default value
"0.15.0-bb.5"

twistlock.helmRepo.repoName📜

Type: string

Default value
"registry1"

twistlock.helmRepo.chartName📜

Type: string

Default value
"twistlock"

twistlock.helmRepo.tag📜

Type: string

Default value
"0.15.0-bb.5"

twistlock.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Twistlock Package

twistlock.ingress📜

Type: object

Default value
gateway: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

twistlock.sso.enabled📜

Type: bool

Default value
false

Description: Toggle SAML SSO, requires a license and enabling the init job - see https://repo1.dso.mil/big-bang/product/packages/initialization.md

twistlock.sso.client_id📜

Type: string

Default value
""

Description: SAML client ID

twistlock.sso.provider_type📜

Type: string

Default value
"shibboleth"

Description: SAML Identity Provider. shibboleth is recommended by Twistlock support for Keycloak Possible values: okta, gsuite, ping, shibboleth, azure, adfs

twistlock.sso.groups📜

Type: string

Default value
""

Description: Groups attribute (optional)

twistlock.values📜

Type: object

Default value
{}

Description: Values to passthrough to the twistlock chart: https://repo1.dso.mil/big-bang/product/packages/twistlock.git

twistlock.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

addons.argocd.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of ArgoCD.

addons.argocd.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

addons.argocd.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/argocd.git"

addons.argocd.git.path📜

Type: string

Default value
"./chart"

addons.argocd.git.tag📜

Type: string

Default value
"6.7.2-bb.1"

addons.argocd.helmRepo.repoName📜

Type: string

Default value
"registry1"

addons.argocd.helmRepo.chartName📜

Type: string

Default value
"argocd"

addons.argocd.helmRepo.tag📜

Type: string

Default value
"6.7.2-bb.1"

addons.argocd.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the ArgoCD Package

addons.argocd.ingress📜

Type: object

Default value
gateway: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

addons.argocd.redis.host📜

Type: string

Default value
""

Description: Hostname of a pre-existing Redis to use for ArgoCD. Entering connection info will enable external Redis and will auto-create any required secrets.

addons.argocd.redis.port📜

Type: string

Default value
""

Description: Port of a pre-existing Redis to use for ArgoCD.

addons.argocd.sso.enabled📜

Type: bool

Default value
false

Description: Toggle SSO for ArgoCD on and off

addons.argocd.sso.client_id📜

Type: string

Default value
""

Description: ArgoCD OIDC client ID

addons.argocd.sso.client_secret📜

Type: string

Default value
""

Description: ArgoCD OIDC client secret

addons.argocd.sso.groups📜

Type: string

Default value
"g, Impact Level 2 Authorized, role:admin\n"

Description: ArgoCD SSO group roles, see docs for more details: https://argo-cd.readthedocs.io/en/stable/operator-manual/rbac/

addons.argocd.values📜

Type: object

Default value
{}

Description: Values to passthrough to the argocd chart: https://repo1.dso.mil/big-bang/product/packages/argocd.git

addons.argocd.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

addons.authservice.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of Authservice. if enabling authservice, a filter needs to be provided by either enabling sso for monitoring or istio, or manually adding a filter chain in the values here: values: chain: minimal: callback_uri: “https://somecallback”

addons.authservice.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

addons.authservice.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/authservice.git"

addons.authservice.git.path📜

Type: string

Default value
"./chart"

addons.authservice.git.tag📜

Type: string

Default value
"1.0.0-bb.0"

addons.authservice.helmRepo.repoName📜

Type: string

Default value
"registry1"

addons.authservice.helmRepo.chartName📜

Type: string

Default value
"authservice"

addons.authservice.helmRepo.tag📜

Type: string

Default value
"1.0.0-bb.0"

addons.authservice.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Authservice Package

addons.authservice.values📜

Type: object

Default value
{}

Description: Values to passthrough to the authservice chart: https://repo1.dso.mil/big-bang/product/packages/authservice.git

addons.authservice.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

addons.authservice.chains📜

Type: object

Default value
{}

Description: Additional authservice chain configurations.

addons.minioOperator.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of minio operator and instance.

addons.minioOperator.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

addons.minioOperator.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/minio-operator.git"

addons.minioOperator.git.path📜

Type: string

Default value
"./chart"

addons.minioOperator.git.tag📜

Type: string

Default value
"5.0.14-bb.2"

addons.minioOperator.helmRepo.repoName📜

Type: string

Default value
"registry1"

addons.minioOperator.helmRepo.chartName📜

Type: string

Default value
"minio-operator"

addons.minioOperator.helmRepo.tag📜

Type: string

Default value
"5.0.14-bb.2"

addons.minioOperator.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Minio Operator Package

addons.minioOperator.ingress📜

Type: object

Default value
gateway: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

addons.minioOperator.values📜

Type: object

Default value
{}

Description: Values to passthrough to the minio operator chart: https://repo1.dso.mil/big-bang/product/packages/minio-operator.git

addons.minioOperator.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

addons.minio.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of minio.

addons.minio.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

addons.minio.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/minio.git"

addons.minio.git.path📜

Type: string

Default value
"./chart"

addons.minio.git.tag📜

Type: string

Default value
"5.0.12-bb.11"

addons.minio.helmRepo.repoName📜

Type: string

Default value
"registry1"

addons.minio.helmRepo.chartName📜

Type: string

Default value
"minio-instance"

addons.minio.helmRepo.tag📜

Type: string

Default value
"5.0.12-bb.11"

addons.minio.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Minio Package

addons.minio.ingress📜

Type: object

Default value
gateway: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

addons.minio.accesskey📜

Type: string

Default value
""

Description: Default access key to use for minio.

addons.minio.secretkey📜

Type: string

Default value
""

Description: Default secret key to intstantiate with minio, you should change/delete this after installation.

addons.minio.values📜

Type: object

Default value
{}

Description: Values to passthrough to the minio instance chart: https://repo1.dso.mil/big-bang/product/packages/minio.git

addons.minio.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

addons.gitlab.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of Gitlab

addons.gitlab.hostnames.gitlab📜

Type: string

Default value
"gitlab"

addons.gitlab.hostnames.registry📜

Type: string

Default value
"registry"

addons.gitlab.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

addons.gitlab.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/gitlab.git"

addons.gitlab.git.path📜

Type: string

Default value
"./chart"

addons.gitlab.git.tag📜

Type: string

Default value
"7.10.2-bb.0"

addons.gitlab.helmRepo.repoName📜

Type: string

Default value
"registry1"

addons.gitlab.helmRepo.chartName📜

Type: string

Default value
"gitlab"

addons.gitlab.helmRepo.tag📜

Type: string

Default value
"7.10.2-bb.0"

addons.gitlab.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Gitlab Package

addons.gitlab.ingress📜

Type: object

Default value
gateway: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

addons.gitlab.sso.enabled📜

Type: bool

Default value
false

Description: Toggle OIDC SSO for Gitlab on and off. Enabling this option will auto-create any required secrets.

addons.gitlab.sso.client_id📜

Type: string

Default value
""

Description: Gitlab OIDC client ID

addons.gitlab.sso.client_secret📜

Type: string

Default value
""

Description: Gitlab OIDC client secret

addons.gitlab.sso.scopes📜

Type: list

Default value
- Gitlab

Description: Gitlab SSO Scopes, default is [“Gitlab”]

addons.gitlab.sso.groups📜

Type: list

Default value
[]

Description: Fill out the groups block below and populate with Keycloak groups according to your desired Gitlab membership requirements. The default groupsAttribute is “groups”. Full documentation: https://docs.gitlab.com/ee/administration/auth/oidc.html?tab=Linux+package+%28Omnibus%29#configure-users-based-on-oidc-group-membership

addons.gitlab.database.host📜

Type: string

Default value
""

Description: Hostname of a pre-existing PostgreSQL database to use for Gitlab. Entering connection info will disable the deployment of an internal database and will auto-create any required secrets.

addons.gitlab.database.port📜

Type: int

Default value
5432

Description: Port of a pre-existing PostgreSQL database to use for Gitlab.

addons.gitlab.database.database📜

Type: string

Default value
""

Description: Database name to connect to on host.

addons.gitlab.database.username📜

Type: string

Default value
""

Description: Username to connect as to external database, the user must have all privileges on the database.

addons.gitlab.database.password📜

Type: string

Default value
""

Description: Database password for the username used to connect to the existing database.

addons.gitlab.objectStorage.type📜

Type: string

Default value
""

Description: Type of object storage to use for Gitlab, setting to s3 will assume an external, pre-existing object storage is to be used. Entering connection info will enable this option and will auto-create any required secrets

addons.gitlab.objectStorage.endpoint📜

Type: string

Default value
""

Description: S3 compatible endpoint to use for connection information. examples: “https://s3.amazonaws.com” “https://s3.us-gov-west-1.amazonaws.com” “http://minio.minio.svc.cluster.local:9000”

addons.gitlab.objectStorage.region📜

Type: string

Default value
""

Description: S3 compatible region to use for connection information.

addons.gitlab.objectStorage.accessKey📜

Type: string

Default value
""

Description: Access key for connecting to object storage endpoint. – If using accessKey and accessSecret, the iamProfile must be left as an empty string: “”

addons.gitlab.objectStorage.accessSecret📜

Type: string

Default value
""

Description: Secret key for connecting to object storage endpoint. Unencoded string data. This should be placed in the secret values and then encrypted

addons.gitlab.objectStorage.bucketPrefix📜

Type: string

Default value
""

Description: Bucket prefix to use for identifying buckets. Example: “prod” will produce “prod-gitlab-bucket”

addons.gitlab.objectStorage.iamProfile📜

Type: string

Default value
""

Description: NOTE: Current bug with AWS IAM Profiles and Object Storage where only artifacts are stored. Fixed in Gitlab 14.5 – Name of AWS IAM profile to use. – If using an AWS IAM profile, the accessKey and accessSecret values must be left as empty strings eg: “”

addons.gitlab.smtp.password📜

Type: string

Default value
""

Description: Passwords should be placed in an encrypted file. Example: environment-bb-secret.enc.yaml If a value is provided BigBang will create a k8s secret named gitlab-smtp-password in the gitlab namespace

addons.gitlab.redis.password📜

Type: string

Default value
""

Description: Redis plain text password to connect to the redis server. If empty (“”), the gitlab charts will create the gitlab-redis-secret with a random password. – This needs to be set to a non-empty value in order for the Grafana Redis Datasource and Dashboards to be installed.

addons.gitlab.railsSecret📜

Type: string

Default value
""

Description: Rails plain text secret to define. If empty (“”), the gitlab charts will create the gitlab-rails-secret with randomized data. Read the following for more information on setting Gitlab rails secrets: https://docs.gitlab.com/charts/installation/secrets#gitlab-rails-secret

addons.gitlab.values📜

Type: object

Default value
{}

Description: Values to passthrough to the gitlab chart: https://repo1.dso.mil/big-bang/product/packages/gitlab.git

addons.gitlab.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

addons.gitlabRunner.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of Gitlab Runner

addons.gitlabRunner.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

addons.gitlabRunner.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/gitlab-runner.git"

addons.gitlabRunner.git.path📜

Type: string

Default value
"./chart"

addons.gitlabRunner.git.tag📜

Type: string

Default value
"0.63.0-bb.2"

addons.gitlabRunner.helmRepo.repoName📜

Type: string

Default value
"registry1"

addons.gitlabRunner.helmRepo.chartName📜

Type: string

Default value
"gitlab-runner"

addons.gitlabRunner.helmRepo.tag📜

Type: string

Default value
"0.63.0-bb.2"

addons.gitlabRunner.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Gitlab Runner Package

addons.gitlabRunner.values📜

Type: object

Default value
{}

Description: Values to passthrough to the gitlab runner chart: https://repo1.dso.mil/big-bang/product/packages/gitlab-runner.git

addons.gitlabRunner.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

addons.nexusRepositoryManager.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of Nexus Repository Manager.

addons.nexusRepositoryManager.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

addons.nexusRepositoryManager.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/nexus.git"

addons.nexusRepositoryManager.git.path📜

Type: string

Default value
"./chart"

addons.nexusRepositoryManager.git.tag📜

Type: string

Default value
"67.1.0-bb.0"

addons.nexusRepositoryManager.helmRepo.repoName📜

Type: string

Default value
"registry1"

addons.nexusRepositoryManager.helmRepo.chartName📜

Type: string

Default value
"nexus-repository-manager"

addons.nexusRepositoryManager.helmRepo.tag📜

Type: string

Default value
"67.1.0-bb.0"

addons.nexusRepositoryManager.license_key📜

Type: string

Default value
""

Description: Base64 encoded license file.

addons.nexusRepositoryManager.ingress📜

Type: object

Default value
gateway: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

addons.nexusRepositoryManager.sso.enabled📜

Type: bool

Default value
false

Description: Toggle SAML SSO for NXRM. – handles SAML SSO, a Client must be configured in Keycloak or IdP – to complete setup. – https://support.sonatype.com/hc/en-us/articles/1500000976522-SAML-integration-for-Nexus-Repository-Manager-Pro-3-and-Nexus-IQ-Server-with-Keycloak#h_01EV7CWCYH3YKAPMAHG8XMQ599

addons.nexusRepositoryManager.sso.idp_data📜

Type: object

Default value
email: ''
entityId: ''
firstName: ''
groups: ''
lastName: ''
username: ''

Description: NXRM SAML SSO Integration data

addons.nexusRepositoryManager.sso.idp_data.username📜

Type: string

Default value
""

Description: IdP Field Mappings – NXRM username attribute

addons.nexusRepositoryManager.sso.idp_data.firstName📜

Type: string

Default value
""

Description: NXRM firstname attribute (optional)

addons.nexusRepositoryManager.sso.idp_data.lastName📜

Type: string

Default value
""

Description: NXRM lastname attribute (optional)

addons.nexusRepositoryManager.sso.idp_data.email📜

Type: string

Default value
""

Description: NXRM email attribute (optional)

addons.nexusRepositoryManager.sso.idp_data.groups📜

Type: string

Default value
""

Description: NXRM groups attribute (optional)

addons.nexusRepositoryManager.sso.role📜

Type: list

Default value
- description: ''
  id: ''
  name: ''
  privileges: []
  roles: []

Description: NXRM Role

addons.nexusRepositoryManager.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Nexus Repository Manager Package

addons.nexusRepositoryManager.values📜

Type: object

Default value
{}

Description: Values to passthrough to the nxrm chart: https://repo1.dso.mil/big-bang/product/packages/nexus.git

addons.nexusRepositoryManager.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

addons.sonarqube.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of SonarQube.

addons.sonarqube.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

addons.sonarqube.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/sonarqube.git"

addons.sonarqube.git.path📜

Type: string

Default value
"./chart"

addons.sonarqube.git.tag📜

Type: string

Default value
"8.0.4-bb.1"

addons.sonarqube.helmRepo.repoName📜

Type: string

Default value
"registry1"

addons.sonarqube.helmRepo.chartName📜

Type: string

Default value
"sonarqube"

addons.sonarqube.helmRepo.tag📜

Type: string

Default value
"8.0.4-bb.1"

addons.sonarqube.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Sonarqube Package

addons.sonarqube.ingress📜

Type: object

Default value
gateway: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

addons.sonarqube.sso.enabled📜

Type: bool

Default value
false

Description: Toggle SAML SSO for SonarQube. Enabling this option will auto-create any required secrets.

addons.sonarqube.sso.client_id📜

Type: string

Default value
""

Description: SonarQube SAML client ID

addons.sonarqube.sso.login📜

Type: string

Default value
"login"

Description: SonarQube login sso attribute.

addons.sonarqube.sso.name📜

Type: string

Default value
"name"

Description: SonarQube name sso attribute.

addons.sonarqube.sso.email📜

Type: string

Default value
"email"

Description: SonarQube email sso attribute.

addons.sonarqube.sso.group📜

Type: string

Default value
"group"

Description: (optional) SonarQube group sso attribute.

addons.sonarqube.database.host📜

Type: string

Default value
""

Description: Hostname of a pre-existing PostgreSQL database to use for SonarQube.

addons.sonarqube.database.port📜

Type: int

Default value
5432

Description: Port of a pre-existing PostgreSQL database to use for SonarQube.

addons.sonarqube.database.database📜

Type: string

Default value
""

Description: Database name to connect to on host.

addons.sonarqube.database.username📜

Type: string

Default value
""

Description: Username to connect as to external database, the user must have all privileges on the database.

addons.sonarqube.database.password📜

Type: string

Default value
""

Description: Database password for the username used to connect to the existing database.

addons.sonarqube.values📜

Type: object

Default value
{}

Description: Values to passthrough to the sonarqube chart: https://repo1.dso.mil/big-bang/product/packages/sonarqube.git

addons.sonarqube.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

addons.fortify.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of Fortify.

addons.fortify.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

addons.fortify.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/fortify.git"

addons.fortify.git.path📜

Type: string

Default value
"./chart"

addons.fortify.git.tag📜

Type: string

Default value
"1.1.2320154-bb.3"

addons.fortify.helmRepo.repoName📜

Type: string

Default value
"registry1"

addons.fortify.helmRepo.chartName📜

Type: string

Default value
"fortify-ssc"

addons.fortify.helmRepo.tag📜

Type: string

Default value
"1.1.2320154-bb.3"

addons.fortify.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Fortify Package

addons.fortify.ingress📜

Type: object

Default value
gateway: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

addons.fortify.sso.enabled📜

Type: bool

Default value
false

Description: Toggle SSO for Fortify on and off

addons.fortify.sso.client_id📜

Type: string

Default value
""

Description: SAML Client ID to use for Fortify

addons.fortify.sso.client_secret📜

Type: string

Default value
""

Description: SAML Client Secret to use for Fortify

addons.fortify.values📜

Type: object

Default value
{}

Description: Values to passthrough to the fortify chart: https://repo1.dso.mil/big-bang/product/packages/fortify.git

addons.fortify.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

addons.haproxy.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

addons.haproxy.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/haproxy.git"

addons.haproxy.git.path📜

Type: string

Default value
"./chart"

addons.haproxy.git.tag📜

Type: string

Default value
"1.19.3-bb.4"

addons.haproxy.helmRepo.repoName📜

Type: string

Default value
"registry1"

addons.haproxy.helmRepo.chartName📜

Type: string

Default value
"haproxy"

addons.haproxy.helmRepo.tag📜

Type: string

Default value
"1.19.3-bb.4"

addons.haproxy.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the HAProxy Package

addons.haproxy.ingress📜

Type: object

Default value
gateway: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

addons.haproxy.values📜

Type: object

Default value
{}

Description: Values to passthrough to the haproxy chart: https://repo1.dso.mil/big-bang/product/packages/haproxy.git

addons.haproxy.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

addons.anchore.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of Anchore.

addons.anchore.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

addons.anchore.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/anchore-enterprise.git"

addons.anchore.git.path📜

Type: string

Default value
"./chart"

addons.anchore.git.tag📜

Type: string

Default value
"2.4.2-bb.8"

addons.anchore.helmRepo.repoName📜

Type: string

Default value
"registry1"

addons.anchore.helmRepo.chartName📜

Type: string

Default value
"anchore"

addons.anchore.helmRepo.tag📜

Type: string

Default value
"2.4.2-bb.8"

addons.anchore.flux📜

Type: object

Default value
upgrade:
  disableWait: true

Description: Flux reconciliation overrides specifically for the Anchore Package

addons.anchore.adminPassword📜

Type: string

Default value
""

Description: Initial admin password used to authenticate to Anchore.

addons.anchore.enterprise📜

Type: object

Default value
licenseYaml: 'FULL LICENSE

  '

Description: Anchore Enterprise functionality.

addons.anchore.enterprise.licenseYaml📜

Type: string

Default value
"FULL LICENSE\n"

Description: License for Anchore Enterprise. Enterprise is the only option available for the chart starting with chart major version 2.X. For formatting examples see https://repo1.dso.mil/big-bang/product/packages/CHART.md#enabling-enterprise-services

addons.anchore.ingress📜

Type: object

Default value
gateway: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

addons.anchore.sso.enabled📜

Type: bool

Default value
false

Description: Toggle SAML SSO for Anchore on and off. Enabling this option will auto-create any required secrets (Note: SSO requires an Enterprise license).

addons.anchore.sso.client_id📜

Type: string

Default value
""

Description: Anchore SAML client ID

addons.anchore.sso.role_attribute📜

Type: string

Default value
""

Description: Anchore SAML client role attribute

addons.anchore.database.host📜

Type: string

Default value
""

Description: Hostname of a pre-existing PostgreSQL database to use for Anchore. Entering connection info will disable the deployment of an internal database and will auto-create any required secrets.

addons.anchore.database.port📜

Type: string

Default value
""

Description: Port of a pre-existing PostgreSQL database to use for Anchore.

addons.anchore.database.username📜

Type: string

Default value
""

Description: Username to connect as to external database, the user must have all privileges on the database.

addons.anchore.database.password📜

Type: string

Default value
""

Description: Database password for the username used to connect to the existing database.

addons.anchore.database.database📜

Type: string

Default value
""

Description: Database name to connect to on host (Note: database name CANNOT contain hyphens).

addons.anchore.database.feeds_database📜

Type: string

Default value
""

Description: Feeds database name to connect to on host (Note: feeds database name CANNOT contain hyphens). Only required for enterprise edition of anchore. By default, feeds database will be configured with the same username and password as the main database. For formatting examples on how to use a separate username and password for the feeds database see https://repo1.dso.mil/big-bang/product/packages/CHART.md#handling-dependencies

addons.anchore.redis.host📜

Type: string

Default value
""

Description: Hostname of a pre-existing Redis to use for Anchore Enterprise. Entering connection info will enable external redis and will auto-create any required secrets. Anchore only requires redis for enterprise deployments and will not provision an instance if using external

addons.anchore.redis.port📜

Type: string

Default value
""

Description: Port of a pre-existing Redis to use for Anchore Enterprise.

addons.anchore.redis.username📜

Type: string

Default value
""

Description: OPTIONAL: Username to connect to a pre-existing Redis (for password-only auth leave empty)

addons.anchore.redis.password📜

Type: string

Default value
""

Description: Password to connect to pre-existing Redis.

addons.anchore.values📜

Type: object

Default value
{}

Description: Values to passthrough to the anchore chart: https://repo1.dso.mil/big-bang/product/packages/anchore-enterprise.git

addons.anchore.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

addons.mattermostOperator.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of Mattermost Operator.

addons.mattermostOperator.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

addons.mattermostOperator.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/mattermost-operator.git"

addons.mattermostOperator.git.path📜

Type: string

Default value
"./chart"

addons.mattermostOperator.git.tag📜

Type: string

Default value
"1.21.0-bb.0"

addons.mattermostOperator.helmRepo.repoName📜

Type: string

Default value
"registry1"

addons.mattermostOperator.helmRepo.chartName📜

Type: string

Default value
"mattermost-operator"

addons.mattermostOperator.helmRepo.tag📜

Type: string

Default value
"1.21.0-bb.0"

addons.mattermostOperator.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Mattermost Operator Package

addons.mattermostOperator.values📜

Type: object

Default value
{}

Description: Values to passthrough to the mattermost operator chart: https://repo1.dso.mil/big-bang/product/packages/values.yaml

addons.mattermostOperator.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

addons.mattermost.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of Mattermost.

addons.mattermost.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

addons.mattermost.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/mattermost.git"

addons.mattermost.git.path📜

Type: string

Default value
"./chart"

addons.mattermost.git.tag📜

Type: string

Default value
"9.6.1-bb.0"

addons.mattermost.helmRepo.repoName📜

Type: string

Default value
"registry1"

addons.mattermost.helmRepo.chartName📜

Type: string

Default value
"mattermost"

addons.mattermost.helmRepo.tag📜

Type: string

Default value
"9.6.1-bb.0"

addons.mattermost.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Mattermost Package

addons.mattermost.enterprise📜

Type: object

Default value
enabled: false
license: ''

Description: Mattermost Enterprise functionality.

addons.mattermost.enterprise.enabled📜

Type: bool

Default value
false

Description: Toggle the Mattermost Enterprise. This must be accompanied by a valid license unless you plan to start a trial post-install.

addons.mattermost.enterprise.license📜

Type: string

Default value
""

Description: License for Mattermost. This should be the entire contents of the license file from Mattermost (should be one line), example below license: “eyJpZCI6InIxM205bjR3eTdkYjludG95Z3RiOD—REST—IS—HIDDEN

addons.mattermost.ingress📜

Type: object

Default value
gateway: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

addons.mattermost.sso.enabled📜

Type: bool

Default value
false

Description: Toggle OIDC SSO for Mattermost on and off. Enabling this option will auto-create any required secrets.

addons.mattermost.sso.client_id📜

Type: string

Default value
""

Description: Mattermost OIDC client ID

addons.mattermost.sso.client_secret📜

Type: string

Default value
""

Description: Mattermost OIDC client secret

addons.mattermost.database.host📜

Type: string

Default value
""

Description: Hostname of a pre-existing PostgreSQL database to use for Mattermost. Entering connection info will disable the deployment of an internal database and will auto-create any required secrets.

addons.mattermost.database.port📜

Type: string

Default value
""

Description: Port of a pre-existing PostgreSQL database to use for Mattermost.

addons.mattermost.database.username📜

Type: string

Default value
""

Description: Username to connect as to external database, the user must have all privileges on the database.

addons.mattermost.database.password📜

Type: string

Default value
""

Description: Database password for the username used to connect to the existing database.

addons.mattermost.database.database📜

Type: string

Default value
""

Description: Database name to connect to on host.

addons.mattermost.database.ssl_mode📜

Type: string

Default value
""

Description: SSL Mode to use when connecting to the database. Allowable values for this are viewable in the postgres documentation: https://www.postgresql.org/docs/current/libpq-ssl.html#LIBPQ-SSL-SSLMODE-STATEMENTS

addons.mattermost.objectStorage.endpoint📜

Type: string

Default value
""

Description: S3 compatible endpoint to use for connection information. Entering connection info will enable this option and will auto-create any required secrets. examples: “s3.amazonaws.com” “s3.us-gov-west-1.amazonaws.com” “minio.minio.svc.cluster.local:9000”

addons.mattermost.objectStorage.accessKey📜

Type: string

Default value
""

Description: Access key for connecting to object storage endpoint.

addons.mattermost.objectStorage.accessSecret📜

Type: string

Default value
""

Description: Secret key for connecting to object storage endpoint. Unencoded string data. This should be placed in the secret values and then encrypted

addons.mattermost.objectStorage.bucket📜

Type: string

Default value
""

Description: Bucket name to use for Mattermost - will be auto-created.

addons.mattermost.elasticsearch📜

Type: object

Default value
enabled: false

Description: Mattermost Elasticsearch integration - requires enterprise E20 license - https://docs.mattermost.com/deployment/elasticsearch.html Connection info defaults to the BB deployed Elastic, all values can be overridden via the “values” passthrough for other connections. See values spec in MM chart “elasticsearch” yaml block - https://repo1.dso.mil/big-bang/product/packages/values.yaml

addons.mattermost.elasticsearch.enabled📜

Type: bool

Default value
false

Description: Toggle interaction with Elastic for optimized search indexing

addons.mattermost.values📜

Type: object

Default value
{}

Description: Values to passthrough to the Mattermost chart: https://repo1.dso.mil/big-bang/product/packages/values.yaml

addons.mattermost.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

addons.velero.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of Velero.

addons.velero.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

addons.velero.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/velero.git"

addons.velero.git.path📜

Type: string

Default value
"./chart"

addons.velero.git.tag📜

Type: string

Default value
"6.0.0-bb.4"

addons.velero.helmRepo.repoName📜

Type: string

Default value
"registry1"

addons.velero.helmRepo.chartName📜

Type: string

Default value
"velero"

addons.velero.helmRepo.tag📜

Type: string

Default value
"6.0.0-bb.4"

addons.velero.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Velero Package

addons.velero.plugins📜

Type: list

Default value
[]

Description: Plugin provider for Velero - requires at least one plugin installed. Current supported values: aws, azure, csi

addons.velero.values📜

Type: object

Default value
{}

Description: Values to passthrough to the Velero chart: https://repo1.dso.mil/big-bang/product/packages/values.yaml

addons.velero.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

addons.keycloak.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of Keycloak. if you enable Keycloak you should uncomment the istio passthrough configurations above istio.ingressGateways.passthrough-ingressgateway and istio.gateways.passthrough

addons.keycloak.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

addons.keycloak.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/keycloak.git"

addons.keycloak.git.path📜

Type: string

Default value
"./chart"

addons.keycloak.git.tag📜

Type: string

Default value
"23.0.7-bb.3"

addons.keycloak.helmRepo.repoName📜

Type: string

Default value
"registry1"

addons.keycloak.helmRepo.chartName📜

Type: string

Default value
"keycloak"

addons.keycloak.helmRepo.tag📜

Type: string

Default value
"23.0.7-bb.3"

addons.keycloak.database.host📜

Type: string

Default value
""

Description: Hostname of a pre-existing database to use for Keycloak. Entering connection info will disable the deployment of an internal database and will auto-create any required secrets.

addons.keycloak.database.type📜

Type: string

Default value
"postgres"

Description: Pre-existing database type (e.g. postgres) to use for Keycloak.

addons.keycloak.database.port📜

Type: int

Default value
5432

Description: Port of a pre-existing database to use for Keycloak.

addons.keycloak.database.database📜

Type: string

Default value
""

Description: Database name to connect to on host.

addons.keycloak.database.username📜

Type: string

Default value
""

Description: Username to connect as to external database, the user must have all privileges on the database.

addons.keycloak.database.password📜

Type: string

Default value
""

Description: Database password for the username used to connect to the existing database.

addons.keycloak.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the OPA Gatekeeper Package

addons.keycloak.ingress📜

Type: object

Default value
cert: ''
gateway: passthrough
key: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

addons.keycloak.ingress.key📜

Type: string

Default value
""

Description: Certificate/Key pair to use as the certificate for exposing Keycloak Setting the ingress cert here will automatically create the volume and volumemounts in the Keycloak Package chart

addons.keycloak.values📜

Type: object

Default value
{}

Description: Values to passthrough to the keycloak chart: https://repo1.dso.mil/big-bang/product/packages/keycloak.git

addons.keycloak.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

addons.vault.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of Vault.

addons.vault.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

addons.vault.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/vault.git"

addons.vault.git.path📜

Type: string

Default value
"./chart"

addons.vault.git.tag📜

Type: string

Default value
"0.25.0-bb.20"

addons.vault.helmRepo.repoName📜

Type: string

Default value
"registry1"

addons.vault.helmRepo.chartName📜

Type: string

Default value
"vault"

addons.vault.helmRepo.tag📜

Type: string

Default value
"0.25.0-bb.20"

addons.vault.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Vault Package

addons.vault.ingress📜

Type: object

Default value
cert: ''
gateway: ''
key: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

addons.vault.ingress.key📜

Type: string

Default value
""

Description: Certificate/Key pair to use as the certificate for exposing Vault Setting the ingress cert here will automatically create the volume and volumemounts in the Vault package chart

addons.vault.values📜

Type: object

Default value
{}

Description: Values to passthrough to the vault chart: https://repo1.dso.mil/big-bang/product/packages/vault.git

addons.vault.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

addons.metricsServer.enabled📜

Type: string

Default value
"auto"

Description: Toggle deployment of metrics server Acceptable options are enabled: true, enabled: false, enabled: auto true = enabled / false = disabled / auto = automatic (Installs only if metrics API endpoint is not present)

addons.metricsServer.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

addons.metricsServer.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/metrics-server.git"

addons.metricsServer.git.path📜

Type: string

Default value
"./chart"

addons.metricsServer.git.tag📜

Type: string

Default value
"3.12.0-bb.1"

addons.metricsServer.helmRepo.repoName📜

Type: string

Default value
"registry1"

addons.metricsServer.helmRepo.chartName📜

Type: string

Default value
"metrics-server"

addons.metricsServer.helmRepo.tag📜

Type: string

Default value
"3.12.0-bb.1"

addons.metricsServer.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the metrics server Package

addons.metricsServer.values📜

Type: object

Default value
{}

Description: Values to passthrough to the metrics server chart: https://repo1.dso.mil/big-bang/product/packages/metrics-server.git

addons.metricsServer.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

addons.harbor.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of harbor

addons.harbor.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

addons.harbor.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/platform-one/big-bang/apps/sandbox/harbor.git"

addons.harbor.git.tag📜

Type: string

Default value
"1.14.1-bb.0"

addons.harbor.git.path📜

Type: string

Default value
"./chart"

addons.harbor.helmRepo.repoName📜

Type: string

Default value
"registry1"

addons.harbor.helmRepo.chartName📜

Type: string

Default value
"harbor"

addons.harbor.helmRepo.tag📜

Type: string

Default value
"1.14.1-bb.0"

addons.harbor.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Jaeger Package

addons.harbor.ingress📜

Type: object

Default value
gateway: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

addons.harbor.sso.enabled📜

Type: bool

Default value
false

Description: Toggle SSO for Harbor on and off

addons.harbor.sso.client_id📜

Type: string

Default value
""

Description: OIDC Client ID to use for Harbor

addons.harbor.sso.client_secret📜

Type: string

Default value
""

Description: OIDC Client Secret to use for Harbor

addons.harbor.values📜

Type: object

Default value
{}

Description: Values to pass through to Habor chart: https://repo1.dso.mil/big-bang/product/packages/harbor.git

addons.harbor.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

addons.holocron.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of Holocron.

addons.holocron.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

addons.holocron.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/holocron.git"

addons.holocron.git.tag📜

Type: string

Default value
"1.0.4"

addons.holocron.git.path📜

Type: string

Default value
"./chart"

addons.holocron.helmRepo.repoName📜

Type: string

Default value
"registry1"

addons.holocron.helmRepo.chartName📜

Type: string

Default value
"holocron"

addons.holocron.helmRepo.tag📜

Type: string

Default value
"1.0.4"

addons.holocron.collectorAuth.existingSecret📜

Type: string

Default value
""

Description: Name of existing secret with auth tokens for collector services: https://repo1.dso.mil/groups/big-bang/apps/sandbox/holocron/-/wikis/Administrator-Guide – Default keys for secret are: – gitlab-scm-0, gitlab-workflow-0, gitlab-build-0, jira-workflow-0, sonarqube-project-analysis-0 – If not provided, one will be created

addons.holocron.collectorAuth.gitlabToken📜

Type: string

Default value
"mygitlabtoken"

Description: Tokens for the secret to be created

addons.holocron.collectorAuth.jiraToken📜

Type: string

Default value
"myjiratoken"

addons.holocron.collectorAuth.sonarToken📜

Type: string

Default value
"mysonartoken"

addons.holocron.jira.enabled📜

Type: bool

Default value
false

Description: If there is a Jira deployment, enable a collector for it

addons.holocron.jira.service.name📜

Type: string

Default value
""

Description: The service name to communicate with

addons.holocron.jira.service.label📜

Type: object

Default value
key: value

Description: If network policies are enabled, a label to match the namespace for egress policy

addons.holocron.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Holocron Package

addons.holocron.ingress📜

Type: object

Default value
gateway: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

addons.holocron.sso.enabled📜

Type: bool

Default value
false

Description: Toggle SSO for Holocron on and off

addons.holocron.sso.groups📜

Type: object

Default value
admin: ''
leadership: ''

Description: Holocron SSO group roles: https://repo1.dso.mil/groups/big-bang/apps/sandbox/holocron/-/wikis/Administrator-Guide

addons.holocron.database.host📜

Type: string

Default value
""

Description: Hostname of a pre-existing PostgreSQL database to use for Gitlab. – Entering connection info will disable the deployment of an internal database and will auto-create any required secrets.

addons.holocron.database.port📜

Type: int

Default value
5432

Description: Port of a pre-existing PostgreSQL database to use for Gitlab.

addons.holocron.database.database📜

Type: string

Default value
"holocron"

Description: Database name to connect to on host.

addons.holocron.database.username📜

Type: string

Default value
"holocron"

Description: Username to connect as to external database, the user must have all privileges on the database.

addons.holocron.database.password📜

Type: string

Default value
"holocron"

Description: Database password for the username used to connect to the existing database.

addons.holocron.postRenderers📜

Type: list

Default value
[]

Description: Post Renderers. See docs/postrenders.md

addons.holocron.values📜

Type: object

Default value
{}

Description: Values to passthrough to the Holocron chart: https://repo1.dso.mil/big-bang/product/packages/holocron.git

addons.thanos.enabled📜

Type: bool

Default value
false

Description: Toggle deployment of thanos

addons.thanos.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

addons.thanos.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/thanos.git"

addons.thanos.git.tag📜

Type: string

Default value
"13.2.2-bb.4"

addons.thanos.git.path📜

Type: string

Default value
"./chart"

addons.thanos.helmRepo.repoName📜

Type: string

Default value
"registry1"

addons.thanos.helmRepo.chartName📜

Type: string

Default value
"thanos"

addons.thanos.helmRepo.tag📜

Type: string

Default value
"13.2.2-bb.4"

addons.thanos.flux📜

Type: object

Default value
{}

Description: Flux reconciliation overrides specifically for the Jaeger Package

addons.thanos.ingress📜

Type: object

Default value
gateway: ''

Description: Redirect the package ingress to a specific Istio Gateway (listed in istio.gateways). The default is “public”.

addons.thanos.values📜

Type: object

Default value
{}

addons.thanos.postRenderers📜

Type: list

Default value
[]

wrapper📜

Type: object

Default value
git:
  path: chart
  repo: https://repo1.dso.mil/big-bang/product/packages/wrapper.git
  tag: 0.4.7
helmRepo:
  chartName: wrapper
  repoName: registry1
  tag: 0.4.7
sourceType: git

Description: Wrapper chart for integrating Big Bang components alongside a package

wrapper.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” or “helmRepo”

wrapper.helmRepo.repoName📜

Type: string

Default value
"registry1"

Description: Repository holding OCI chart, corresponding to helmRepositories name

wrapper.helmRepo.chartName📜

Type: string

Default value
"wrapper"

Description: Name of the OCI chart in repo

wrapper.helmRepo.tag📜

Type: string

Default value
"0.4.7"

Description: Tag of the OCI chart in repo

wrapper.git.repo📜

Type: string

Default value
"https://repo1.dso.mil/big-bang/product/packages/wrapper.git"

Description: Git repo holding the wrapper helm chart, example: https://repo1.dso.mil/big-bang/product/packages/wrapper

wrapper.git.path📜

Type: string

Default value
"chart"

Description: Path inside of the git repo to find the helm chart, example: chart

wrapper.git.tag📜

Type: string

Default value
"0.4.7"

Description: Git tag to check out. Takes precedence over branch. More info, example: 0.0.2

packages📜

Type: object

Default value
sample:
  configMaps: {}
  dependsOn: []
  enabled: false
  flux: {}
  git:
    branch: null
    commit: null
    credentials:
      caFile: ''
      knownHosts: ''
      password: ''
      privateKey: ''
      publicKey: ''
      username: ''
    existingSecret: ''
    path: null
    repo: null
    semver: null
    tag: null
  helmRepo:
    chartName: null
    repoName: null
    tag: null
  istio: {}
  kustomize: false
  monitor: {}
  network: {}
  postRenderers: []
  secrets: {}
  sourceType: git
  values: {}
  wrapper:
    enabled: false

Description: Packages to deploy with Big Bang @default - ‘{}’

packages.sample.sourceType📜

Type: string

Default value
"git"

Description: Choose source type of “git” (“helmRepo” not supported yet)

packages.sample.kustomize📜

Type: bool

Default value
false

Description: Use a kustomize deployment rather than Helm

packages.sample.helmRepo📜

Type: object

Default value
chartName: null
repoName: null
tag: null

Description: HelmRepo source is supported as an option for Helm deployments. If both git and helmRepo are provided git will take precedence.

packages.sample.helmRepo.repoName📜

Type: string

Default value
nil

Description: Name of the HelmRepo specified in helmRepositories

packages.sample.helmRepo.chartName📜

Type: string

Default value
nil

Description: Name of the chart stored in the Helm repository

packages.sample.helmRepo.tag📜

Type: string

Default value
nil

Description: Tag of the chart in the Helm repo, required

packages.sample.git📜

Type: object

Default value
branch: null
commit: null
credentials:
  caFile: ''
  knownHosts: ''
  password: ''
  privateKey: ''
  publicKey: ''
  username: ''
existingSecret: ''
path: null
repo: null
semver: null
tag: null

Description: Git source is supported for both Helm and Kustomize deployments. If both git and helmRepo are provided git will take precedence.

packages.sample.git.repo📜

Type: string

Default value
nil

Description: Git repo URL holding the helm chart for this package, required if using git

packages.sample.git.commit📜

Type: string

Default value
nil

Description: Git commit to check out. Takes precedence over semver, tag, and branch. More info

packages.sample.git.semver📜

Type: string

Default value
nil

Description: Git semVer tag expression to check out. Takes precedence over tag. More info

packages.sample.git.tag📜

Type: string

Default value
nil

Description: Git tag to check out. Takes precedence over branch. More info

packages.sample.git.branch📜

Type: string

Default value
nil

Description: Git branch to check out. More info.

packages.sample.git.path📜

Type: string

Default value
nil

Description: Path inside of the git repo to find the helm chart or kustomize

packages.sample.git.existingSecret📜

Type: string

Default value
""

Description: Optional, alternative existing secret to use for git credentials, must be in the appropriate format: https://toolkit.fluxcd.io/components/source/gitrepositories/#https-authentication

packages.sample.git.credentials📜

Type: object

Default value
caFile: ''
knownHosts: ''
password: ''
privateKey: ''
publicKey: ''
username: ''

Description: Optional, alternative Chart created secrets with user defined values

packages.sample.git.credentials.username📜

Type: string

Default value
""

Description: HTTP git credentials, both username and password must be provided

packages.sample.git.credentials.caFile📜

Type: string

Default value
""

Description: HTTPS certificate authority file. Required for any repo with a self signed certificate

packages.sample.git.credentials.privateKey📜

Type: string

Default value
""

Description: SSH git credentials, privateKey, publicKey, and knownHosts must be provided

packages.sample.flux📜

Type: object

Default value
{}

Description: Override flux settings for this package

packages.sample.postRenderers📜

Type: list

Default value
[]

Description: After deployment, patch resources. More info

packages.sample.dependsOn📜

Type: list

Default value
[]

Description: Specify dependencies for the package. Only used for HelmRelease, does not effect Kustomization. See here for a reference.

packages.sample.istio📜

Type: object

Default value
{}

Description: Package details for Istio. See wrapper values for settings.

packages.sample.monitor📜

Type: object

Default value
{}

Description: Package details for monitoring. See wrapper values for settings.

packages.sample.network📜

Type: object

Default value
{}

Description: Package details for network policies. See wrapper values for settings.

packages.sample.secrets📜

Type: object

Default value
{}

Description: Secrets that should be created prior to package installation. See wrapper values for settings.

packages.sample.configMaps📜

Type: object

Default value
{}

Description: ConfigMaps that should be created prior to package installation. See wrapper values for settings.

packages.sample.values📜

Type: object

Default value
{}

Description: Values to pass through to package Helm chart