80 lines
2.3 KiB
YAML
80 lines
2.3 KiB
YAML
apiVersion: argoproj.io/v1alpha1
|
|
kind: Application
|
|
metadata:
|
|
name: authentik
|
|
namespace: argocd
|
|
spec:
|
|
project: default
|
|
source:
|
|
repoURL: https://charts.goauthentik.io
|
|
chart: authentik
|
|
targetRevision: 2026.5.6
|
|
helm:
|
|
valuesObject:
|
|
authentik:
|
|
existingSecret:
|
|
secretName: authentik
|
|
securityContext:
|
|
allowPrivilegeEscalation: false
|
|
capabilities:
|
|
drop: ["ALL"]
|
|
runAsNonRoot: true
|
|
runAsUser: 1000
|
|
runAsGroup: 1000
|
|
fsGroup: 1000
|
|
seccompProfile:
|
|
type: RuntimeDefault
|
|
server:
|
|
nodeSelector:
|
|
node-role.kubernetes.io/core: "true"
|
|
securityContext:
|
|
runAsNonRoot: true
|
|
runAsUser: 1000
|
|
runAsGroup: 1000
|
|
fsGroup: 1000
|
|
containerSecurityContext:
|
|
runAsNonRoot: true
|
|
allowPrivilegeEscalation: false
|
|
readOnlyRootFilesystem: false # Set to true only if you mount emptyDir for temp paths
|
|
seccompProfile:
|
|
type: RuntimeDefault
|
|
capabilities:
|
|
drop:
|
|
- ALL
|
|
ingress:
|
|
enabled: true
|
|
ingressClassName: traefik
|
|
hosts:
|
|
- auth.panopticons.org
|
|
worker:
|
|
nodeSelector:
|
|
node-role.kubernetes.io/core: "true"
|
|
securityContext:
|
|
runAsNonRoot: true
|
|
runAsUser: 1000
|
|
runAsGroup: 1000
|
|
fsGroup: 1000
|
|
containerSecurityContext:
|
|
runAsNonRoot: true
|
|
allowPrivilegeEscalation: false
|
|
readOnlyRootFilesystem: false # Set to true only if you mount emptyDir for temp paths
|
|
seccompProfile:
|
|
type: RuntimeDefault
|
|
capabilities:
|
|
drop:
|
|
- ALL
|
|
postgresql:
|
|
enabled: true
|
|
auth:
|
|
existingSecret: authentik-postgresql
|
|
primary:
|
|
nodeSelector:
|
|
node-role.kubernetes.io/core: "true"
|
|
containerSecurityContext:
|
|
readOnlyRootFilesystem: true
|
|
destination:
|
|
server: https://kubernetes.default.svc
|
|
namespace: authentik
|
|
syncPolicy:
|
|
syncOptions: [CreateNamespace=True]
|