Skip to content

Latest commit

 

History

History
217 lines (206 loc) · 35.5 KB

File metadata and controls

217 lines (206 loc) · 35.5 KB

crowd

Version: 2.0.13 Type: application AppVersion: 7.1.5

A chart for installing Crowd Data Center on Kubernetes

Homepage: https://atlassian.github.io/data-center-helm-charts/

Source Code

Requirements

Kubernetes: >=1.21.x-0

Repository Name Version
https://atlassian.github.io/data-center-helm-charts common 1.2.7

Values

Key Type Default Description
additionalConfigMaps list [] Create additional ConfigMaps with given names, keys and content. Ther Helm release name will be used as a prefix for a ConfigMap name, fileName is used as subPath
additionalContainers list [] Additional container definitions that will be added to all Crowd pods
additionalFiles list [] Additional existing ConfigMaps and Secrets not managed by Helm that should be mounted into service container. Configuration details below (camelCase is important!): 'name' - References existing ConfigMap or secret name. 'type' - 'configMap' or 'secret' 'key' - The file name. 'mountPath' - The destination directory in a container. VolumeMount and Volumes are added with this name and index position, for example; custom-config-0, keystore-2
additionalHosts list [] Additional host aliases for each pod, equivalent to adding them to the /etc/hosts file. https://kubernetes.io/docs/concepts/services-networking/add-entries-to-pod-etc-hosts-with-host-aliases/
additionalInitContainers list [] Additional initContainer definitions that will be added to all Crowd pods
additionalLabels object {} Additional labels that should be applied to all resources
affinity object {} Standard K8s affinities that will be applied to all Crowd pods
atlassianAnalyticsAndSupport.analytics.enabled bool true Mount ConfigMap with selected Helm chart values as a JSON which DC products will read and send analytics events to Atlassian data pipelines
atlassianAnalyticsAndSupport.helmValues.enabled bool true Mount ConfigMap with selected Helm chart values as a YAML file which can be optionally including to support.zip
crowd.accessLog.enabled bool true Set to 'true' if access logging should be enabled.
crowd.accessLog.localHomeSubPath string "logs" The subdirectory within the local-home volume where access logs should be stored.
crowd.accessLog.mountPath string "/opt/atlassian/crowd/apache-tomcat/logs" The path within the Crowd container where the local-home volume should be mounted in order to capture access logs.
crowd.additionalAnnotations object {} Defines additional annotations to the Bamboo StateFulSet. This might be required when deploying using a GitOps approach
crowd.additionalBundledPlugins list [] Specifies a list of additional Crowd plugins that should be added to the Crowd container. Note plugins installed via this method will appear as bundled plugins rather than user plugins. These should be specified in the same manner as the 'additionalLibraries' property. Additional details: https://atlassian.github.io/data-center-helm-charts/examples/external_libraries/EXTERNAL_LIBS/ NOTE: only .jar files can be loaded using this approach. OBR's can be extracted (unzipped) to access the associated .jar An alternative to this method is to install the plugins via "Manage Apps" in the product system administration UI.
crowd.additionalCertificates object {"customCmd":null,"initContainer":{"resources":{},"securityContext":{}},"secretList":[],"secretName":null} Certificates to be added to Java truststore. Provide reference to a secret that contains the certificates
crowd.additionalCertificates.customCmd string nil Custom command to be executed in the init container to import certificates
crowd.additionalCertificates.initContainer.resources object {} Resources allocated to the import-certs init container
crowd.additionalCertificates.initContainer.securityContext object {} Custom SecurityContext for the import-certs init container
crowd.additionalCertificates.secretList list [] A list of secrets with their respective keys holding certificates to be added to the Java truststore. It is mandatory to specify which keys from secret data need to be mounted as files to the init container
crowd.additionalCertificates.secretName string nil Name of the Kubernetes secret with certificates in its data. All secret keys in the secret data will be treated as certificates to be added to Java truststore. If defined, this takes precedence over secretList.
crowd.additionalEnvironmentVariables list [] Defines any additional environment variables to be passed to the Crowd container. See https://hub.docker.com/r/atlassian/crowd for supported variables.
crowd.additionalJvmArgs list [] Specifies a list of additional arguments that can be passed to the Crowd JVM, e.g. system properties.
crowd.additionalLibraries list [] Specifies a list of additional Java libraries that should be added to the Crowd container. Each item in the list should specify the name of the volume that contains the library, as well as the name of the library file within that volume's root directory. Optionally, a subDirectory field can be included to specify which directory in the volume contains the library file. Additional details: https://atlassian.github.io/data-center-helm-charts/examples/external_libraries/EXTERNAL_LIBS/
crowd.additionalPorts list [] Defines any additional ports for the Crowd container.
crowd.additionalVolumeClaimTemplates list [] Defines additional volumeClaimTemplates that should be applied to the Crowd pod. Note that this will not create any corresponding volume mounts; those needs to be defined in crowd.additionalVolumeMounts
crowd.additionalVolumeMounts list [] Defines any additional volumes mounts for the Crowd container. These can refer to existing volumes, or new volumes can be defined in volumes.additional.
crowd.containerSecurityContext object {} Standard K8s field that holds security configurations that will be applied to a container. https://kubernetes.io/docs/tasks/configure-pod-container/security-context/
crowd.livenessProbe.customProbe object {} Custom livenessProbe to override the default tcpSocket probe
crowd.livenessProbe.enabled bool false Whether to apply the livenessProbe check to pod.
crowd.livenessProbe.failureThreshold int 12 The number of consecutive failures of the Crowd container liveness probe before the pod fails liveness checks.
crowd.livenessProbe.initialDelaySeconds int 60 Time to wait before starting the first probe
crowd.livenessProbe.periodSeconds int 5 How often (in seconds) the Crowd container liveness probe will run
crowd.livenessProbe.timeoutSeconds int 1 Number of seconds after which the probe times out
crowd.ports.http int 8095 The port on which the Crowd container listens for HTTP traffic
crowd.postStart object {"command":null} PostStart is executed immediately after a container is created. However, there is no guarantee that the hook will execute before the container ENTRYPOINT. See: https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks
crowd.readinessProbe.customProbe object {} Custom readinessProbe to override the default /status httpGet
crowd.readinessProbe.enabled bool true Whether to apply the readinessProbe check to pod.
crowd.readinessProbe.failureThreshold int 10 The number of consecutive failures of the Crowd container readiness probe before the pod fails readiness checks.
crowd.readinessProbe.initialDelaySeconds int 10 The initial delay (in seconds) for the Crowd container readiness probe, after which the probe will start running.
crowd.readinessProbe.periodSeconds int 5 How often (in seconds) the Crowd container readiness probe will run
crowd.readinessProbe.timeoutSeconds int 1 Number of seconds after which the probe times out
crowd.resources.container.requests.cpu string "2" Initial CPU request by Crowd pod
crowd.resources.container.requests.memory string "1G" Initial Memory request by Crowd pod
crowd.resources.jvm.maxHeap string "768m" The maximum amount of heap memory that will be used by the Crowd JVM
crowd.resources.jvm.minHeap string "384m" The minimum amount of heap memory that will be used by the Crowd JVM
crowd.securityContext.fsGroup int 2004 The GID used by the Crowd docker image GID will default to 2004 if not supplied and securityContextEnabled is set to true. This is intended to ensure that the shared-home volume is group-writeable by the GID used by the Crowd container. However, this doesn't appear to work for NFS volumes due to a K8s bug: kubernetes/examples#260
crowd.securityContext.fsGroupChangePolicy string "OnRootMismatch" fsGroupChangePolicy defines behavior for changing ownership and permission of the volume before being exposed inside a Pod. This field only applies to volume types that support fsGroup controlled ownership and permissions. https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#configure-volume-permission-and-ownership-change-policy-for-pods
crowd.securityContextEnabled bool true Whether to apply security context to pod.
crowd.service.annotations object {} Additional annotations to apply to the Service
crowd.service.contextPath string "/crowd" The Tomcat context path that Crowd will use. The ATL_TOMCAT_CONTEXTPATH will be set automatically.
crowd.service.loadBalancerIP string nil Use specific loadBalancerIP. Only applies to service type LoadBalancer.
crowd.service.nodePort string nil Only applicable if service.type is NodePort. NodePort for Crowd service
crowd.service.port int 80 The port on which the Crowd K8s Service will listen
crowd.service.sessionAffinity string "None" Session affinity type. If you want to make sure that connections from a particular client are passed to the same pod each time, set sessionAffinity to ClientIP. See: https://kubernetes.io/docs/reference/networking/virtual-ips/#session-affinity
crowd.service.sessionAffinityConfig object {"clientIP":{"timeoutSeconds":null}} Session affinity configuration
crowd.service.sessionAffinityConfig.clientIP.timeoutSeconds string nil Specifies the seconds of ClientIP type session sticky time. The value must be > 0 && <= 86400(for 1 day) if ServiceAffinity == "ClientIP". Default value is 10800 (for 3 hours).
crowd.service.type string "ClusterIP" The type of K8s service to use for Crowd. For loadBalancer type, deselect the consistent client IP address in Crowd Session configuration. Read more: https://atlassian.github.io/data-center-helm-charts/troubleshooting/LIMITATIONS/#loadbalancer-service-type
crowd.setPermissions bool true Boolean to define whether to set local home directory permissions on startup of Crowd container. Set to 'false' to disable this behaviour.
crowd.shutdown.command string "/shutdown-wait.sh" By default pods will be stopped via a preStop hook, using a script supplied by the Docker image. If any other shutdown behaviour is needed it can be achieved by overriding this value. Note that the shutdown command needs to wait for the application shutdown completely before exiting; see the default command for details.
crowd.shutdown.terminationGracePeriodSeconds int 30 The termination grace period for pods during shutdown. This should be set to the internal grace period, plus a small buffer to allow the JVM to fully terminate.
crowd.startupProbe.enabled bool false Whether to apply the startupProbe check to pod.
crowd.startupProbe.failureThreshold int 120 The number of consecutive failures of the Crowd container startup probe before the pod fails startup checks.
crowd.startupProbe.initialDelaySeconds int 60 Time to wait before starting the first probe
crowd.startupProbe.periodSeconds int 5 How often (in seconds) the Crowd container startup probe will run
crowd.tomcatConfig.acceptCount string "100"
crowd.tomcatConfig.accessLogsMaxDays string "-1"
crowd.tomcatConfig.connectionTimeout string "20000"
crowd.tomcatConfig.enableLookups string "false"
crowd.tomcatConfig.generateByHelm bool false Mount server.xml as a ConfigMap. Override configuration elements if necessary
crowd.tomcatConfig.maxHttpHeaderSize string "8192"
crowd.tomcatConfig.maxThreads string "150"
crowd.tomcatConfig.mgmtPort string "8020"
crowd.tomcatConfig.minSpareThreads string "25"
crowd.tomcatConfig.port string "8095"
crowd.tomcatConfig.protocol string "HTTP/1.1"
crowd.tomcatConfig.proxyInternalIps string nil
crowd.tomcatConfig.proxyName string nil
crowd.tomcatConfig.proxyPort string nil
crowd.tomcatConfig.redirectPort string "8443"
crowd.tomcatConfig.requestAttributesEnabled string "false"
crowd.tomcatConfig.scheme string nil
crowd.tomcatConfig.secure string nil
crowd.topologySpreadConstraints list [] Defines topology spread constraints for Crowd pods. See details: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
crowd.umask string "0022" The umask used by the Crowd process when it creates new files. The default is 0022. This gives the new files: - read/write permissions for the Crowd user - read permissions for everyone else.
crowd.useHelmReleaseNameAsContainerName bool false Whether the main container should acquire helm release name. By default the container name is crowd which corresponds to the name of the Helm Chart.
fluentd.command string nil The command used to start Fluentd. If not supplied the default command will be used: "fluentd -c /fluentd/etc/fluent.conf -v" Note: The custom command can be free-form, however pay particular attention to the process that should ultimately be left running in the container. This process should be invoked with 'exec' so that signals are appropriately propagated to it, for instance SIGTERM. An example of how such a command may look is: "<command 1> && <command 2> && exec "
fluentd.customConfigFile bool false Set to 'true' if a custom config (see 'configmap-fluentd.yaml' for default) should be used for Fluentd. If enabled this config must be supplied via the 'fluentdCustomConfig' property below. If your custom config forces fluentd to run in a server mode, add -Datlassian.logging.cloud.enabled=true to crowd.AdditionalJvmArgs stanza in values file
fluentd.elasticsearch.enabled bool true Set to 'true' if Fluentd should send all log events to an Elasticsearch service.
fluentd.elasticsearch.hostname string "elasticsearch" The hostname of the Elasticsearch service that Fluentd should send logs to.
fluentd.elasticsearch.indexNamePrefix string "crowd" The prefix of the Elasticsearch index name that will be used
fluentd.enabled bool false Set to 'true' if the Fluentd sidecar (DaemonSet) should be added to each pod
fluentd.extraVolumes list [] Specify custom volumes to be added to Fluentd container (e.g. more log sources)
fluentd.fluentdCustomConfig object {} Custom fluent.conf file
fluentd.httpPort int 9880 The port on which the Fluentd sidecar will listen
fluentd.imageRepo string "fluent/fluentd-kubernetes-daemonset" The Fluentd sidecar image repository
fluentd.imageTag string "v1.11.5-debian-elasticsearch7-1.2" The Fluentd sidecar image tag
fluentd.resources object {} Resources requests and limits for fluentd sidecar container See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
gateway.additionalRules list [] Advanced routing rules. Use this for complex routing scenarios like header-based routing, traffic splitting, or multiple backends. See: https://gateway-api.sigs.k8s.io/reference/spec/#gateway.networking.k8s.io/v1.HTTPRouteRule
gateway.annotations object {} Annotations to add to the HTTPRoute resource.
gateway.create bool false Set to 'true' if an HTTPRoute Resource should be created. This depends on a pre-provisioned Gateway API controller being available and a Gateway resource. Cannot be enabled if ingress.create is true.
gateway.filters list [] HTTP filters to apply to requests. Can be used to add/remove headers, perform redirects, or rewrite URLs. See: https://gateway-api.sigs.k8s.io/reference/spec/#gateway.networking.k8s.io/v1.HTTPRouteFilter
gateway.hostnames list [] The hostnames that should be routed to Crowd. At least one hostname is required when gateway.create is true. Setting hostnames activates gateway mode for product configuration even when gateway.create is false, allowing use with a pre-existing Gateway or external proxy. The first entry is used as the canonical hostname for base URL, proxy settings, and NOTES output — list the primary/public hostname first.
gateway.https bool true Whether users access the application over HTTPS. This does not configure TLS on the Gateway or load balancer — it must match how traffic is actually routed to the application.
gateway.labels object {} Labels to add to the HTTPRoute resource.
gateway.parentRefs list [] Reference to the parent Gateway resource. Supports any standard parentRef fields (name, namespace, sectionName, etc.). See: https://gateway-api.sigs.k8s.io/reference/spec/#gateway.networking.k8s.io/v1.ParentReference
gateway.path string "/" The base path for routing. When empty, falls back to the product's service.contextPath (same behavior as ingress). Set explicitly to override, e.g. "/crowd".
gateway.pathType string "PathPrefix" Path matching type. Can be "PathPrefix", "Exact", or "RegularExpression". PathPrefix is recommended for most use cases.
gateway.timeouts object {"backendRequest":"60s","request":"60s"} Timeout configuration for HTTPRoute rules. Note: when migrating from Ingress, these replace proxyReadTimeout and proxySendTimeout. There is no Gateway API equivalent for proxyConnectTimeout or maxBodySize — those require controller-specific policies (e.g. Envoy Gateway BackendTrafficPolicy). See: https://gateway-api.sigs.k8s.io/reference/spec/#gateway.networking.k8s.io/v1.HTTPRouteTimeouts
hostNamespaces object {} Share host namespaces which may include hostNetwork, hostIPC, and hostPID
image object {"pullPolicy":"IfNotPresent","repository":"atlassian/crowd","tag":""} Image configuration
image.pullPolicy string "IfNotPresent" Image pull policy
image.repository string "atlassian/crowd" The Docker Crowd Docker image to use https://hub.docker.com/r/atlassian/crowd
image.tag string "" The docker image tag to be used. Defaults to appVersion in Chart.yaml
ingress.additionalPaths list [] Additional paths to be added to the Ingress resource to point to different backend services
ingress.annotations object {} The custom annotations that should be applied to the Ingress Resource. If using an ingress-nginx controller be sure that the annotations you add here are compatible with those already defined in the 'ingess.yaml' template
ingress.className string "nginx" The class name used by the ingress controller if it's being used. Please follow documentation of your ingress controller. If the cluster contains multiple ingress controllers, this setting allows you to control which of them is used for Atlassian application traffic.
ingress.create bool false Set to 'true' if an Ingress Resource should be created. This depends on a pre-provisioned Ingress Controller being available.
ingress.host string nil The fully-qualified hostname (FQDN) of the Crowd instance. This value is used to configure the product's proxy settings and, when ingress.create is true, the Ingress resource routing rules.
ingress.https bool true Whether users access the application over HTTPS. Set to 'false' if not using TLS, e.g. when reaching the service via localhost port-forwarding.
ingress.maxBodySize string "250m" The max body size to allow. Requests exceeding this size will result in an HTTP 413 error being returned to the client.
ingress.nginx bool true Set to 'true' if the Ingress Resource is to use the K8s 'ingress-nginx' controller. https://kubernetes.github.io/ingress-nginx/ This will populate the Ingress Resource with annotations that are specific to the K8s ingress-nginx controller. Set to 'false' if a different controller is to be used, in which case the appropriate annotations for that controller must be specified below under 'ingress.annotations'.
ingress.openShiftRoute bool false Set to true if you want to create an OpenShift Route instead of an Ingress
ingress.path string "/" The base path for the application, e.g. '/crowd'.
ingress.proxyConnectTimeout int 60 Defines a timeout for establishing a connection with a proxied server. It should be noted that this timeout cannot usually exceed 75 seconds.
ingress.proxyReadTimeout int 60 Defines a timeout for reading a response from the proxied server. The timeout is set only between two successive read operations, not for the transmission of the whole response. If the proxied server does not transmit anything within this time, the connection is closed.
ingress.proxySendTimeout int 60 Sets a timeout for transmitting a request to the proxied server. The timeout is set only between two successive write operations, not for the transmission of the whole request. If the proxied server does not receive anything within this time, the connection is closed.
ingress.routeHttpHeaders object {} routeHttpHeaders defines policy for HTTP headers. Applicable to OpenShift Routes only
ingress.tlsSecretName string nil The name of the K8s Secret that contains the TLS private key and corresponding certificate. When utilised, TLS termination occurs at the ingress point where traffic to the Service, and it's Pods is in plaintext. Usage is optional and depends on your use case. The Ingress Controller itself can also be configured with a TLS secret for all Ingress Resources. https://kubernetes.io/docs/concepts/configuration/secret/#tls-secrets https://kubernetes.io/docs/concepts/services-networking/ingress/#tls
monitoring.exposeJmxMetrics bool false Expose JMX metrics with jmx_exporter https://github.com/prometheus/jmx_exporter
monitoring.fetchJmxExporterJar bool true Fetch jmx_exporter jar from the image. If set to false make sure to manually copy the jar to shared home and provide an absolute path in jmxExporterCustomJarLocation
monitoring.grafana.createDashboards bool false Create ConfigMaps with Grafana dashboards
monitoring.grafana.dashboardAnnotations object {} Annotations added to Grafana dashboards ConfigMaps. See: https://github.com/kiwigrid/k8s-sidecar#usage
monitoring.grafana.dashboardLabels object {} Label selector for Grafana dashboard importer sidecar
monitoring.jmxExporterCustomConfig object {} Custom JMX config with the rules
monitoring.jmxExporterCustomJarLocation string nil Location of jmx_exporter jar file if mounted from a secret or manually copied to shared home
monitoring.jmxExporterImageRepo string "bitnamilegacy/jmx-exporter" Image repository with jmx_exporter jar
monitoring.jmxExporterImageTag string "0.18.0"
monitoring.jmxExporterInitContainer object {"customSecurityContext":{},"jmxJarLocation":null,"resources":{},"runAsRoot":true} JMX exporter init container configuration
monitoring.jmxExporterInitContainer.customSecurityContext object {} Custom SecurityContext for the jmx exporter init container
monitoring.jmxExporterInitContainer.jmxJarLocation string nil The location of the JMX exporter jarfile in the JMX exporter image Leave blank for default bitnami image
monitoring.jmxExporterInitContainer.resources object {} Resources requests and limits for the JMX exporter init container See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
monitoring.jmxExporterInitContainer.runAsRoot bool true Whether to run JMX exporter init container as root to copy JMX exporter binary to shared home volume. Set to false if running containers as root is not allowed in the cluster.
monitoring.jmxExporterPort int 9999 Port number on which metrics will be available
monitoring.jmxExporterPortType string "ClusterIP" JMX exporter port type
monitoring.jmxServiceAnnotations object {} Annotations added to the jmx service
monitoring.serviceMonitor.create bool false Create ServiceMonitor to start scraping metrics. ServiceMonitor CRD needs to be created in advance.
monitoring.serviceMonitor.prometheusLabelSelector object {} ServiceMonitorSelector of the prometheus instance.
monitoring.serviceMonitor.scrapeIntervalSeconds int 30 Scrape interval for the JMX service.
nodeSelector object {} Standard K8s node-selectors that will be applied to all Crowd pods
openshift.runWithRestrictedSCC bool false When set to true, the containers will run with a restricted Security Context Constraint (SCC). See: https://docs.openshift.com/container-platform/4.14/authentication/managing-security-context-constraints.html This configuration property unsets pod's SecurityContext, nfs-fixer init container (which runs as root), and mounts server configuration files as ConfigMaps.
ordinals object {"enabled":false,"start":0} Set a custom start ordinal number for the K8s stateful set. Note that this depends on the StatefulSetStartOrdinal K8s feature gate, which has entered beta state with K8s version 1.27.
ordinals.enabled bool false Enable only if StatefulSetStartOrdinal K8s feature gate is available.
ordinals.start int 0 Set start ordinal to a positive integer, defaulting to 0.
podAnnotations object {} Custom annotations that will be applied to all Crowd pods
podDisruptionBudget object {"annotations":{},"enabled":false,"labels":{},"maxUnavailable":null,"minAvailable":null} PodDisruptionBudget: https://kubernetes.io/docs/tasks/run-application/configure-pdb/ You can specify only one of maxUnavailable and minAvailable in a single PodDisruptionBudget. When both minAvailable and maxUnavailable are set, maxUnavailable takes precedence.
podLabels object {} Custom labels that will be applied to all Crowd pods
priorityClassName string nil Priority class for the application pods. The PriorityClass with this name needs to be available in the cluster. For details see https://kubernetes.io/docs/concepts/scheduling-eviction/pod-priority-preemption/#priorityclass
replicaCount int 1 The initial number of Crowd pods that should be started at deployment time. Note that Crowd requires manual configuration via the browser post deployment after the first pod is deployed. This configuration must be completed before scaling up additional pods. As such this value should always be kept as 1, but can be altered once manual configuration is complete.
schedulerName string nil Standard K8s schedulerName that will be applied to all Crowd pods. Check Kubernetes documentation on how to configure multiple schedulers: https://kubernetes.io/docs/tasks/extend-kubernetes/configure-multiple-schedulers/#specify-schedulers-for-pods
serviceAccount.annotations object {} Annotations to add to the ServiceAccount (if created)
serviceAccount.create bool true Set to 'true' if a ServiceAccount should be created, or 'false' if it already exists.
serviceAccount.imagePullSecrets list [] For Docker images hosted in private registries, define the list of image pull secrets that should be utilized by the created ServiceAccount https://kubernetes.io/docs/concepts/containers/images/#specifying-imagepullsecrets-on-a-pod
serviceAccount.name string nil The name of the ServiceAccount to be used by the pods. If not specified, but the "serviceAccount.create" flag is set to 'true', then the ServiceAccount name will be auto-generated, otherwise the 'default' ServiceAccount will be used. https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/#use-the-default-service-account-to-access-the-api-server
terminationGracePeriodSeconds int 30 Kubernetes default, but can be overridden here.
testPods object {"affinity":{},"annotations":{},"image":{"permissionsTestContainer":"debian:stable-slim","statusTestContainer":"alpine:latest"},"labels":{},"nodeSelector":{},"resources":{},"schedulerName":null,"tolerations":[]} Metadata and pod spec for pods started in Helm tests
tolerations list [] Standard K8s tolerations that will be applied to all Crowd pods
updateStrategy object {} StatefulSet update strategy. When unset defaults to Rolling update. See: https://kubernetes.io/docs/tutorials/stateful-application/basic-stateful-set/#updating-statefulsets
volumes.additional list [] Defines additional volumes that should be applied to all Crowd pods. Note that this will not create any corresponding volume mounts; those needs to be defined in crowd.additionalVolumeMounts
volumes.localHome.customVolume object {} Static provisioning of local-home using K8s PVs and PVCs NOTE: Due to the ephemeral nature of pods this approach to provisioning volumes for pods is not recommended. Dynamic provisioning described above is the prescribed approach. When 'persistentVolumeClaim.create' is 'false', then this value can be used to define a standard K8s volume that will be used for the local-home volume(s). If not defined, then an 'emptyDir' volume is utilised. Having provisioned a 'PersistentVolume', specify the bound 'persistentVolumeClaim.claimName' for the 'customVolume' object. https://kubernetes.io/docs/concepts/storage/persistent-volumes/#static
volumes.localHome.mountPath string "/var/atlassian/application-data/crowd" Specifies the path in the Crowd container to which the local-home volume will be mounted.
volumes.localHome.persistentVolumeClaim.create bool false If 'true', then a 'PersistentVolume' and 'PersistentVolumeClaim' will be dynamically created for each pod based on the 'StorageClassName' supplied below.
volumes.localHome.persistentVolumeClaim.resources object {"requests":{"storage":"1Gi"}} Specifies the standard K8s resource requests and/or limits for the local-home volume claims.
volumes.localHome.persistentVolumeClaim.storageClassName string nil Specify the name of the 'StorageClass' that should be used for the local-home volume claim.
volumes.localHome.persistentVolumeClaimRetentionPolicy.whenDeleted string nil Configures the volume retention behavior that applies when the StatefulSet is deleted.
volumes.localHome.persistentVolumeClaimRetentionPolicy.whenScaled string nil Configures the volume retention behavior that applies when the replica count of the StatefulSet is reduced.
volumes.localHome.subPath string nil Specifies the sub-directory of the local-home volume that will be mounted in to the Crowd container.
volumes.sharedHome.customVolume object {} Static provisioning of shared-home using K8s PVs and PVCs When 'persistentVolumeClaim.create' is 'false', then this value can be used to define a standard K8s volume that will be used for the shared-home volume. If not defined, then an 'emptyDir' volume is utilised. Having provisioned a 'PersistentVolume', specify the bound 'persistentVolumeClaim.claimName' for the 'customVolume' object. https://kubernetes.io/docs/concepts/storage/persistent-volumes/#static https://atlassian.github.io/data-center-helm-charts/examples/storage/aws/SHARED_STORAGE/
volumes.sharedHome.mountPath string "/var/atlassian/application-data/crowd/shared" Specifies the path in the Crowd container to which the shared-home volume will be mounted.
volumes.sharedHome.nfsPermissionFixer.command string nil By default, the fixer will change the group ownership of the volume's root directory to match the Crowd container's GID (2002), and then ensures the directory is group-writeable. If this is not the desired behaviour, command used can be specified here.
volumes.sharedHome.nfsPermissionFixer.enabled bool true If 'true', this will alter the shared-home volume's root directory so that Crowd can write to it. This is a workaround for a K8s bug affecting NFS volumes: kubernetes/examples#260
volumes.sharedHome.nfsPermissionFixer.imageRepo string "alpine" Image repository for the permission fixer init container. Defaults to alpine
volumes.sharedHome.nfsPermissionFixer.imageTag string "latest" Image tag for the permission fixer init container. Defaults to latest
volumes.sharedHome.nfsPermissionFixer.mountPath string "/shared-home" The path in the K8s initContainer where the shared-home volume will be mounted
volumes.sharedHome.nfsPermissionFixer.resources object {} Resources requests and limits for nfsPermissionFixer init container See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
volumes.sharedHome.persistentVolumeClaim.accessModes list ["ReadWriteMany"] Specify the access modes that should be used for the 'shared-home' volume claim. Note: 'ReadWriteOnce' (RWO) is suitable only for single-node installations. Be aware that changing the access mode of an existing PVC might be impossible, as the PVC spec is immutable. https://kubernetes.io/docs/concepts/storage/persistent-volumes/#access-modes
volumes.sharedHome.persistentVolumeClaim.create bool false If 'true', then a 'PersistentVolumeClaim' and 'PersistentVolume' will be dynamically created for shared-home based on the 'StorageClassName' supplied below.
volumes.sharedHome.persistentVolumeClaim.resources object {"requests":{"storage":"1Gi"}} Specifies the standard K8s resource requests and/or limits for the shared-home volume claims.
volumes.sharedHome.persistentVolumeClaim.storageClassName string nil Specify the name of the 'StorageClass' that should be used for the 'shared-home' volume claim.
volumes.sharedHome.subPath string nil Specifies the sub-directory of the shared-home volume that will be mounted in to the Crowd container.

Autogenerated from chart metadata using helm-docs v1.12.0