Helm Reference
General Configuration
Section titled “General Configuration”trustDomain
Section titled “trustDomain”(string, default qhx.dev, required)
The trustDomain value specifies a DNS domain name which should be a unique
identifier for the cluster.
clusterName
Section titled “clusterName”(string, default qhx-cluster, required)
The clusterName value specifies a unique identifier for the cluster which
should meet the rules of a single DNS label (i.e., formed of alphanumeric
characters and hyphens).
clusterDomain
Section titled “clusterDomain”(string, default cluster.local, required)
The clusterDomain value specifies the Kubernetes cluster domain name to be
used. This needs to match the cluster domain name configured for the Kubernetes
cluster. In testing environments, it is often set to cluster.local, which is
the default setting.
Kubernetes Environment Configuration
Section titled “Kubernetes Environment Configuration”kubernetesVariant
Section titled “kubernetesVariant”(string, no default value, required)
This must be set to one of the following supported values, and indicates the Kubernetes variant into which QHx is deployed.
| Value | Description |
|---|---|
| openshift | The target cluster is a Red Hat OpenShift cluster. |
| eks | The target cluster is an AWS EKS cluster. |
| kind | The target cluster is a cluster created with kind. |
| microk8s | The target cluster is a cluster created with microk8s installed via snap. |
| unknown | The target cluster is a generic Kubernetes cluster not corresponding to any of the above values. |
The kubernetesVariant setting is used to set the other Kubernetes values
defined in the QHx Helm chart to appropriate default values for the given
Kubernetes variant. Each such value may still be overriden with a
cluster-specific value if desired.
The value unknown uses reasonable defaults for most production Kubernetes
environments and can be used to deploy QHx into unsupported Kubernetes
environments. In some cases, it may be necessary to manually adjust other
Kubernetes-related Helm values defined in the QHx helm chart.
kubeletStateDir
Section titled “kubeletStateDir”(string, default: see below, required)
Specifies the path to the kubelet state directory on each of the cluster nodes.
This is usually /var/lib/kubelet, but may vary according to the
kubernetesVariant unless manually overriden. It defaults to
/var/snap/microk8s/common/var/lib/kubelet for the microk8s variant.
spiffeCSIPluginName
Section titled “spiffeCSIPluginName”(string, default “csi.spiffe.io”, required)
This configures the CSI plugin name used for the SPIFFE CSI integration. It is rarely necessary to change it unless it is needed to shorten UNIX domain socket paths.
imagePullPolicy
Section titled “imagePullPolicy”(string, default “IfNotPresent”, required to be “IfNotPresent” or “Always”)
This sets the Kubernetes imagePullPolicy for QHx system images such as QHx
Manager. The default value, IfNotPresent, is appropriate for most production
environments.
OCI Image References
Section titled “OCI Image References”The following images express OCI image references for the OCI images that comprise a QHx cluster. They can be customized if needed, for example to allow for installation against a private OCI registry.
| Setting | Type | Default Value |
|---|---|---|
| managerImage | string (OCI Image Ref) | "oci.messier42.com/qhx/manager:{VERSION}" |
| proxyImage | string (OCI Image Ref) | "oci.messier42.com/qhx/proxy:{VERSION}" |
| agentImage | string (OCI Image Ref) | "oci.messier42.com/qhx/agent:{VERSION}" |
| pkiServerImage | string (OCI Image Ref) | "oci.messier42.com/qhx/pki-server:{VERSION}" |
| pkiAgentImage | string (OCI Image Ref) | "oci.messier42.com/qhx/pki-agent:{VERSION}" |
| pkiControllerManagerImage | string (OCI Image Ref) | "oci.messier42.com/qhx/pki-controller-manager:{VERSION}" |
| spiffeCSIDriverImage | string (OCI Image Ref) | "oci.messier42.com/qhx/spiffe-csi-driver:{VERSION}" |
| nodeDriverRegistrarImage | string (OCI Image Ref) | "oci.messier42.com/qhx/csi-node-driver-registrar:v2.12.0" |
| tpmDevicePluginImage | string (OCI Image Ref) | "oci.messier42.com/qhx/k8s-tpm-device:master" |
| khaled.image | string (OCI Image Ref) | "oci.messier42.com/qhx/khaled:{VERSION}" |
| initImage | string (OCI Image Ref) | "cgr.dev/chainguard/wait-for-it:{VERSION}" |
OCI Authentication
Section titled “OCI Authentication”The following values configure OCI registry authentication credentials which are used to retrieve OCI images from the configured paths.
OCI credentials can be provided as a username and password, or as a base64-encoded Docker-style JSON object containing OCI credentials.
If ociSecretBase64 is specified as a non-empty value, it is used; otherwise,
ociUsername and ociPassword are used to generate the required credentials
file.
| Setting | Type | Default Value |
|---|---|---|
| ociUsername | string (required) | "" |
| ociPassword | string (required) | "" |
| ociSecretBase64 | string (OCI Image Ref) | "" |
Internal Tuning Parameters
Section titled “Internal Tuning Parameters”These values can be used to tune the QHx installation, but are not expected to need to be changed in most testing production use cases.
webhookCertTTL
Section titled “webhookCertTTL”(string (duration), default “2h”, required)
The lifetime of the certificate generated by QHx to enable communication from the Kubernetes control plane to the QHx admission controller.
webhookCertRotationInterval
Section titled “webhookCertRotationInterval”(string (duration), default “30m”, required)
How frequently to rotate the certificate generated by QHx to enable
communication from the Kubernetes control plane to the QHx admission
controller. This must be less than the value of webhookCertTTL.
tpm.enable
Section titled “tpm.enable”(boolean, default false)
Setting this to true enables TPM support in the QHx installation. This must be enabled at install time if enabling TPM functionality in policy resources is desired.
Setting this to true will provision a TPM device plugin to provide access to TPM devices on each Kubernetes node and enable TPM device support in QHx.
You must have a TPM device available on each Kubernetes node before installing QHx with this value set to true.
Khaled
Section titled “Khaled”The Khaled key server is integrated into the QHx suite. These values allow the Khaled installation to be configured or disabled.
khaled.enable
Section titled “khaled.enable”(boolean, default true)
Enables the Khaled key server. Note that the Khaled key server requires a valid storage class be available on the cluster for persistent storage.
khaled.image
Section titled “khaled.image”(string)
See “OCI Image References” above.
khaled.storageSize
Section titled “khaled.storageSize”(string, duration value, default “1Gi”)
This specifies the amount of storage requested for the persistent key storage volume provisioned for Khaled.
khaled.storageClassName
Section titled “khaled.storageClassName”(string, default "")
This specifies the storage class name to use when requesting the persistent key storage volume used by Khaled to store data. If left empty, the cluster’s default storage class is used.
License Tracking
Section titled “License Tracking”QHx can ingest signed offline license files at Helm install time for installation at installation time. tracking.
license.inlineFiles
Section titled “license.inlineFiles”(array, default [])
List of licenses to import as part of the Helm install. Each entry must include:
| Field | Type | Description |
|---|---|---|
name | string | Secret name to create |
dataBase64 | string | Base64-encoded contents of the signed license file |
Example:
license: inlineFiles: - name: qhx-license-1 coseBase64: "<base64 of license.qhxlicense>"