Files
charts/bitnami/thanos/templates/receive/grpc-server-tls-secrets.yaml
2021-12-09 11:52:51 +01:00

31 lines
1.4 KiB
YAML

{{- if and .Values.receive.enabled .Values.receive.grpc.server.tls.enabled (not .Values.receive.grpc.server.tls.existingSecret) }}
apiVersion: v1
kind: Secret
metadata:
name: {{ printf "%s-receive-grpc-server" (include "common.names.fullname" .) }}
namespace: {{ .Release.Namespace | quote }}
labels: {{- include "common.labels.standard" . | nindent 4 }}
app.kubernetes.io/component: receive
{{- if .Values.commonLabels }}
{{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
{{- end }}
{{- if .Values.commonAnnotations }}
annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
{{- end }}
type: Opaque
data:
{{- if .Values.receive.grpc.server.tls.autoGenerated }}
{{- $ca := genCA "thanos-receive-grpc-server-ca" 365 }}
{{- $hostname := printf "%s-receive-grpc-server" (include "common.names.fullname" .) }}
{{- $cert := genSignedCert $hostname nil (list $hostname) 365 $ca }}
tls-crt: {{ $cert.Cert | b64enc | quote }}
tls-key: {{ $cert.Key | b64enc | quote }}
ca-cert: {{ $ca.Cert | b64enc | quote }}
{{- else }}
tls-cert: {{ .Values.receive.grpc.server.tls.cert | b64enc | quote }}
tls-key: {{ .Values.receive.grpc.server.tls.key | b64enc | quote }}
ca-cert : {{ .Values.receive.grpc.server.tls.ca | b64enc | quote }}
{{- end }}
{{ end }}