Helm Reference
General Configuration
Section titled “General Configuration”trustDomain
Section titled “trustDomain”(string, default qhx.dev, required)
The trustDomain value specifies a DNS domain name which should be a unique
identifier for the cluster.
clusterName
Section titled “clusterName”(string, default qhx-cluster, required)
The clusterName value specifies a unique identifier for the cluster which
should meet the rules of a single DNS label (i.e., formed of alphanumeric
characters and hyphens).
Kubernetes Environment Configuration
Section titled “Kubernetes Environment Configuration”kubernetesVariant
Section titled “kubernetesVariant”(string, no default value, required)
This must be set to one of the following supported values, and indicates the Kubernetes variant into which QHx is deployed.
| Value | Description |
|---|---|
| eks | The target cluster is an AWS EKS cluster. |
| kind | The target cluster is a cluster created with kind. |
| microk8s | The target cluster is a cluster created with microk8s installed via snap. |
| unknown | The target cluster is a generic Kubernetes cluster not corresponding to any of the above values. |
The kubernetesVariant setting is used to set the other Kubernetes values
defined in the QHx Helm chart to appropriate default values for the given
Kubernetes variant. Each such value may still be overriden with a
cluster-specific value if desired.
The value unknown uses reasonable defaults for most production Kubernetes
environments and can be used to deploy QHx into unsupported Kubernetes
environments. In some cases, it may be necessary to manually adjust other
Kubernetes-related Helm values defined in the QHx helm chart.
kubeletStateDir
Section titled “kubeletStateDir”(string, default: see below, required)
Specifies the path to the kubelet state directory on each of the cluster nodes.
This is usually /var/lib/kubelet, but may vary according to the
kubernetesVariant unless manually overriden. It defaults to
/var/snap/microk8s/common/var/lib/kubelet for the microk8s variant.
spiffeCSIPluginName
Section titled “spiffeCSIPluginName”(string, default “csi.spiffe.io”, required)
This configures the CSI plugin name used for the SPIFFE CSI integration. It is rarely necessary to change it unless it is needed to shorten UNIX domain socket paths.
OCI Image References
Section titled “OCI Image References”The following images express OCI image references for the OCI images that comprise a QHx cluster. They can be customized if needed, for example to allow for installation against a private OCI registry.
| Setting | Type | Default Value |
|---|---|---|
| managerImage | string (OCI Image Ref) | "oci.messier42.com/qhx/manager:{VERSION}" |
| proxyImage | string (OCI Image Ref) | "oci.messier42.com/qhx/proxy:{VERSION}" |
| agentImage | string (OCI Image Ref) | "oci.messier42.com/qhx/agent:{VERSION}" |
| pkiServerImage | string (OCI Image Ref) | "oci.messier42.com/qhx/pki-server:{VERSION}" |
| pkiAgentImage | string (OCI Image Ref) | "oci.messier42.com/qhx/pki-agent:{VERSION}" |
| pkiControllerManagerImage | string (OCI Image Ref) | "oci.messier42.com/qhx/pki-controller-manager:{VERSION}" |
OCI Authentication
Section titled “OCI Authentication”The following values configure OCI registry authentication credentials which are used to retrieve OCI images from the configured paths.
OCI credentials can be provided as a username and password, or as a base64-encoded Docker-style JSON object containing OCI credentials.
If ociSecretBase64 is specified as a non-empty value, it is used; otherwise,
ociUsername and ociPassword are used to generate the required credentials
file.
| Setting | Type | Default Value |
|---|---|---|
| ociUsername | string (required) | "" |
| ociPassword | string (required) | "" |
| ociSecretBase64 | string (OCI Image Ref) | "" |