DEV Community

KHAN
KHAN

Posted on

Rendering Helm Scripts Locally woth Mirror

# Values for the cert-manager Google CAS issuer chart.
#
# Only the ServiceAccount ANNOTATION is set, not its name: the chart derives the
# KSA name from the release name and its schema rejects serviceAccount.name.
# That annotation is what binds the pod to the Google service account through
# Workload Identity - the matching binding is in ../../cas.tf.
serviceAccount:
  annotations:
    iam.gke.io/gcp-service-account: sa-google-cas-issuer@saudi-dev-gke-0.iam.gserviceaccount.com

image:
  repository: asia-south1-docker.pkg.dev/saudi-prod-artifacts-0/shared-docker/cert-manager-google-cas-issuer

Enter fullscreen mode Exit fullscreen mode
# Values for the cert-manager chart. Each of these is load-bearing for a reason
# recorded in FAST-DEPLOYMENT-LOG.md - none is cosmetic.

# The CAS issuer's custom resources need cert-manager's CRDs, so they ship with
# the chart rather than out of band.
crds:
  enabled: true

# REQUIRED ON AUTOPILOT. cert-manager puts its leader-election lease in
# kube-system by default and Autopilot refuses writes there:
#   leases.coordination.k8s.io is forbidden ... namespace "kube-system"
#   GKE Warden authz [denied by managed-namespaces-limitation]
# Without this the controller and cainjector run but never win leadership, so
# cainjector never injects the CA bundle into the webhook configuration and every
# Certificate fails with "x509: certificate signed by unknown authority".
# The pods still report Running, so no health check catches it.
global:
  leaderElection:
    namespace: cert-manager

# Image repositories. The chart defaults EVERY component to quay.io, so each one
# is redirected individually - overriding the chart source alone would leave the
# pods still pulling externally while appearing migrated.
image:
  repository: asia-south1-docker.pkg.dev/saudi-prod-artifacts-0/shared-docker/cert-manager-controller
webhook:
  image:
    repository: asia-south1-docker.pkg.dev/saudi-prod-artifacts-0/shared-docker/cert-manager-webhook
cainjector:
  image:
    repository: asia-south1-docker.pkg.dev/saudi-prod-artifacts-0/shared-docker/cert-manager-cainjector
acmesolver:
  image:
    repository: asia-south1-docker.pkg.dev/saudi-prod-artifacts-0/shared-docker/cert-manager-acmesolver

startupapicheck:
  # startupapicheck is a post-install Helm HOOK JOB that calls the cert-manager
  # API to prove it answers. On Autopilot it reliably fails with
  # BackoffLimitExceeded - the job pod waits for Autopilot to provision capacity,
  # which outlives the job's own deadline. cert-manager itself comes up fine.
  # Under Helm this marked the whole release failed; under Config Sync a hook job
  # would be applied as an ordinary Job and simply fail forever.
  enabled: false
  image:
    repository: asia-south1-docker.pkg.dev/saudi-prod-artifacts-0/shared-docker/cert-manager-startupapicheck

Enter fullscreen mode Exit fullscreen mode

Top comments (0)