mirror of https://github.com/linkerd/linkerd2.git
* Introduce support for authenticated docker registries using imagePullSecrets Problem: Private Docker Registries are not supported for the moment as detailed in issue #4413 Solution: Every Service Account of linkerd subcomponents are Attached with imagePullSecrets, which in turn can then pulls the docker images from authenticated private registries using them. The imagePullSecret is configured in global.imagePullSecret parameter of values.yaml like imagePullSecret: - name: <name-of-private-registry-secret-resource> Fixes #4413 Signed-off-by: Nilakhya <nilakhya@hotmail.com> |
||
---|---|---|
.. | ||
templates | ||
.helmignore | ||
Chart.yaml | ||
OWNERS | ||
README.md | ||
requirements.lock | ||
requirements.yaml | ||
values.yaml |
README.md
Linkerd2-cni Helm Chart
Linkerd is a service mesh, designed to give platform-wide observability, reliability, and security without requiring configuration or code changes. The Linkerd CNI plugin takes care of setting up your pod's network so incoming and outgoing traffic is proxied through the data plane.
Configuration
The following table lists the configurable parameters of the Linkerd2-cni chart and their default values.
Parameter | Description | Default |
---|---|---|
cniPluginImage |
Docker image for the CNI plugin | ghcr.io/linkerd/cni-plugin |
cniPluginVersion |
Tag for the CNI container Docker image | latest version |
cniResourceAnnotation |
CNI resource annotation. Do not edit | linkerd.io/cni-resource |
controllerNamespaceLabel |
Control plane label. Do not edit | linkerd.io/control-plane-ns |
createdByAnnotation |
Annotation label for the proxy create. Do not edit. | linkerd.io/created-by |
destCNIBinDir |
Directory on the host where the CNI plugin binaries reside | /opt/cni/bin |
destCNINetDir |
Directory on the host where the CNI configuration will be placed | /etc/cni/net.d |
ignoreInboundPorts |
Inbound ports the proxy should ignore | |
ignoreOutboundPorts |
Outbound ports the proxy should ignore | |
inboundProxyPort |
Inbound port for the proxy container | 4143 |
logLevel |
Log level for the CNI plugin | info |
namespace |
CNI plugin plane namespace | linkerd-cni |
outboundProxyPort |
Outbound port for the proxy container | 4140 |
portsToRedirect |
Ports to redirect to proxy | |
proxyUID |
User id under which the proxy shall be ran | 2102 |
useWaitFlag |
Configures the CNI plugin to use the -w flag for the iptables command | false |
installNamespace |
Whether to create the CNI plugin plane namespace or not | true |
priorityClassName |
Kubernetes priorityClassName for the CNI plugin's Pods |