mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-04 16:39:35 +08:00
* fix(kubernetes): scope resource admission RBAC Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(helm): gate PVC admission reads Signed-off-by: Drew Newberry <anewberry@nvidia.com> --------- Signed-off-by: Drew Newberry <anewberry@nvidia.com>
35 lines
1.2 KiB
YAML
35 lines
1.2 KiB
YAML
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
# SPDX-License-Identifier: Apache-2.0
|
|
|
|
# -- Override the chart name used in generated resource names.
|
|
nameOverride: ""
|
|
# -- Override the full generated resource name.
|
|
fullnameOverride: ""
|
|
|
|
gateway:
|
|
# -- Grant PVC metadata reads required when the gateway enables caller driver config.
|
|
# Keep this aligned with server.drivers.kubernetes.allowDriverConfig in the gateway chart.
|
|
allowDriverConfig: false
|
|
serviceAccount:
|
|
# -- Name of the shared gateway ServiceAccount.
|
|
name: openshell
|
|
# -- Namespace containing the shared gateway ServiceAccount.
|
|
namespace: openshell
|
|
networkPolicy:
|
|
# -- Labels selecting gateway pods allowed to reach sandbox SSH.
|
|
podSelector:
|
|
app.kubernetes.io/name: openshell
|
|
app.kubernetes.io/instance: openshell
|
|
|
|
sandboxServiceAccount:
|
|
# -- Create the ServiceAccount assigned to sandbox pods.
|
|
create: true
|
|
# -- Sandbox ServiceAccount name.
|
|
name: openshell-sandbox
|
|
# -- Annotations added to the generated sandbox ServiceAccount.
|
|
annotations: {}
|
|
|
|
networkPolicy:
|
|
# -- Restrict sandbox SSH ingress to the shared gateway pods.
|
|
enabled: true
|