## Aurva Data Plane ## Ref: https://github.com/aurva-io/aurva-charts.git postgresql: enabled: true fullnameOverride: "aurva-dataplane-database" global: postgresql: auth: postgresPassword: "aurva" database: "controller" # Add toleration to make sure where this postgres db pod should reside (Applicable for production workloads): For more detail ref: https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/ primary: extendedConfiguration: | max_connections = 300 tolerations: # - key: "dedicated" # operator: "Equal" # value: "app" # effect: "NoSchedule" # -- Provide a name in place of `aurva` # namespaceOverride: aurva-dataplane ########################################################## # Global Configs ########################################################## global: aurva_controller: enabled: true aurva_pii_analyzer: enabled: true aurva_ocr: enabled: true aurva_collector: enabled: true aurva_proxy: enabled: false deploymentAnnotations: {} priorityClassName: "" ########################################################## # Aurva Controller ########################################################## aurva_controller: # -- Additional labels for aurva-controller additionalLabels: {} # -- Annotations on aurva-controller annotations: {} # "key": "value" revisionHistoryLimit: 3 # -- no of replicas for aurva controller replicas: 4 # -- Additional label added on pod which is used in Service's Label Selector podLabels: {} # -- Additional Pod Annotations added on pod created by this Deployment additionalPodAnnotations: {} # "key": "value" # -- Secrets used to pull image imagePullSecrets: "" # Image of the app container image: repository: 119191042565.dkr.ecr.ap-south-1.amazonaws.com/aurva-controller tag: "v1.5.8-pre2" pullPolicy: IfNotPresent # Environment variables to be passed to the app container env: - name: NODE_NAME valueFrom: fieldRef: apiVersion: v1 fieldPath: spec.nodeName - name: NODE_IP valueFrom: fieldRef: apiVersion: v1 fieldPath: status.hostIP # -- If want to mount Envs from configmap or secret envFrom: aurva-controller: type: secret name: aurva-controller-secrets # -- Resources to be defined for pod resources: limits: memory: 512Mi cpu: 1 requests: memory: 256Mi cpu: 0.5 # -- Select nodes to deploy which matches the following labels nodeSelector: # cloud.google.com/gke-nodepool: default-pool # schedule-on: app-workload # -- Taint tolerations for nodes tolerations: # - key: "dedicated" # operator: "Equal" # value: "app" # effect: "NoSchedule" # -- Pod affinity and pod anti-affinity allow you to specify rules about how pods should be placed relative to other pods. affinity: # nodeAffinity: # requiredDuringSchedulingIgnoredDuringExecution: # nodeSelectorTerms: # - matchExpressions: # - key: disktype # operator: In # values: # - ssd # -- [DNS configuration] dnsConfig: {} # -- Alternative DNS policy for application controller pods dnsPolicy: "ClusterFirst" secret: name: "aurva-controller-secrets" # -- Additional Labels on secrets additionalLabels: # key: value # -- Annotations on secrets annotations: # key: value config: COMPANY_ID: "47c5ed30-c23e-48c3-a510-9c9378867737" PG_USERNAME: "postgres" PG_PASSWORD: "aurva" PG_DBNAME: "controller" AWS_REGION: "ap-south-1" COMMAND_URL: "command.uat.aurva.io:443" # Please update this with ingress URL of command ENVIRONMENT: "uat" PROVIDER_ACCOUNT_ID: "918749230" LOG_ENV: "production" RDS_SCANNER_AVAILABILITY : "true" REDSHIFT_SCANNER_AVAILABILITY : "true" S3_SCANNER_AVAILABILITY : "true" EGRESS_MODE_ONLY: "false" serviceAccount: # -- Create a service account for the aurva controller create: true # -- Service account name name: aurva-controller-sa # -- Annotations applied to created service account annotations: # eks.amazonaws.com/role-arn: arn:aws:iam:::role/ # -- Labels applied to created service account labels: {} ########################################################## # Aurva Collector ########################################################## aurva_collector: # -- Additional labels for aurva-analyzer additionalLabels: {} # "key": "value" # -- Annotations on aurva-analyzer annotations: {} # "key": "value" # -- Additional label added on pod which is used in Service's Label Selector podLabels: {} # -- Additional Pod Annotations added on pod created by this Deployment additionalPodAnnotations: {} # "key": "value" # -- Secrets used to pull image imagePullSecrets: "" # Image of the app container image: repository: 119191042565.dkr.ecr.ap-south-1.amazonaws.com/aurva-collector tag: "v1.5.8-pre2" pullPolicy: IfNotPresent # Environment variables to be passed to the app container env: [] # -- If want to mount Envs from configmap or secret envFrom: aurva-controller: type: secret name: aurva-collector-secrets resources: limits: cpu: 400m memory: 256Mi requests: cpu: 200m memory: 128Mi podSecurityContext: {} securityContext: privileged: false capabilities: add: # For kernel v5.8 and above we don't need SYS_ADMIN or SYS_RESOURCE # we just need CAP_BPF and CAP_PERFMON. This has been tested on our EKS node # which is on kernel v5.10.x # - BPF # - PERFMON - SYS_ADMIN - SYS_RESOURCE # capabilities: # drop: # - ALL # readOnlyRootFilesystem: true # runAsNonRoot: true # runAsUser: 1000 volumes: - name: sys-kernal-debug mountPath: /sys/kernel/debug hostPath: /sys/kernel/debug - name: sys-kernal-btf mountPath: /sys/kernel/btf/vmlinux hostPath: /sys/kernel/btf/vmlinux # -- Select nodes to deploy which matches the following labels nodeSelector: # cloud.google.com/gke-nodepool: default-pool # schedule-on: app-workload # -- Taint tolerations for nodes tolerations: - operator: Exists # -- Pod affinity and pod anti-affinity allow you to specify rules about how pods should be placed relative to other pods. affinity: # nodeAffinity: # requiredDuringSchedulingIgnoredDuringExecution: # nodeSelectorTerms: # - matchExpressions: # - key: disktype # operator: In # values: # - ssd dnsPolicy: "ClusterFirst" secret: name: "aurva-collector-secrets" # -- Additional Labels on secrets additionalLabels: # key: value # -- Annotations on secrets annotations: # key: value config: COMPANY_ID: "" DEPLOYMENT_TYPE: kubernetes LOG_ENV: production TRACE_EGRESS: "true" TRACE_PSQL: "false" SKIP_NAMESPACES: "aurva-dataplane,kube-system,default" serviceAccount: # -- Create a service account for the aurva controller create: true # -- Service account name name: aurva-controller-sa # -- Annotations applied to created service account annotations: # eks.amazonaws.com/role-arn: arn:aws:iam:::role/ # -- Labels applied to created service account labels: {} ########################################################## # Aurva PII Analyzer ########################################################## aurva_pii_analyzer: # -- Additional labels for aurva-controller additionalLabels: {} # -- Annotations on aurva-controller annotations: {} # "key": "value" revisionHistoryLimit: 3 # -- no of replicas for aurva controller replicas: 1 # -- Additional label added on pod which is used in Service's Label Selector podLabels: {} # -- Additional Pod Annotations added on pod created by this Deployment additionalPodAnnotations: {} # "key": "value" # -- Secrets used to pull image imagePullSecrets: "" # Image of the app container image: repository: 119191042565.dkr.ecr.ap-south-1.amazonaws.com/aurva-piianalyzer tag: "v1.2.8" pullPolicy: IfNotPresent # Environment variables to be passed to the app container env: [] # -- If want to mount Envs from configmap or secret envFrom: aurva-pii-analyzer: type: secret name: aurva-pii-analyzer-secrets # -- Resources to be defined for pod resources: limits: memory: 4Gi cpu: 2 requests: memory: 2Gi cpu: 1 # -- Select nodes to deploy which matches the following labels nodeSelector: # cloud.google.com/gke-nodepool: default-pool # schedule-on: app-workload # -- Taint tolerations for nodes tolerations: # - key: "dedicated" # operator: "Equal" # value: "app" # effect: "NoSchedule" # -- Pod affinity and pod anti-affinity allow you to specify rules about how pods should be placed relative to other pods. affinity: # nodeAffinity: # requiredDuringSchedulingIgnoredDuringExecution: # nodeSelectorTerms: # - matchExpressions: # - key: disktype # operator: In # values: # - ssd # -- [DNS configuration] dnsConfig: {} # -- Alternative DNS policy for application controller pods dnsPolicy: "ClusterFirst" secret: name: "aurva-pii-analyzer-secrets" # -- Additional Labels on secrets additionalLabels: # key: value # -- Annotations on secrets annotations: # key: value config: PG_USERNAME: "postgres" PG_PASSWORD: "aurva" PG_DBNAME: "controller" SCHEDULER_TIME: "1" SUPPORTED_REGION: "US" serviceAccount: # -- Create a service account for the aurva controller create: true # -- Service account name name: aurva-pii-analyzer-sa # -- Annotations applied to created service account annotations: # eks.amazonaws.com/role-arn: arn:aws:iam:::role/ # -- Labels applied to created service account labels: {} ########################################################## # Aurva OCR ########################################################## aurva_ocr: # -- Additional labels for aurva-controller additionalLabels: {} # -- Annotations on aurva-controller annotations: {} # "key": "value" revisionHistoryLimit: 3 # -- no of replicas for aurva controller replicas: 1 # -- Additional label added on pod which is used in Service's Label Selector podLabels: {} # -- Additional Pod Annotations added on pod created by this Deployment additionalPodAnnotations: {} # "key": "value" # -- Secrets used to pull image imagePullSecrets: "" # Image of the app container image: repository: 119191042565.dkr.ecr.ap-south-1.amazonaws.com/aurva-ocr tag: "v1.2.8" pullPolicy: IfNotPresent # Environment variables to be passed to the app container env: [] # -- If want to mount Envs from configmap or secret envFrom: aurva-ocr: type: secret name: aurva-ocr-secrets # -- Resources to be defined for pod resources: limits: memory: 2Gi cpu: 1 requests: memory: 2Gi cpu: 1 # -- Select nodes to deploy which matches the following labels nodeSelector: # cloud.google.com/gke-nodepool: default-pool # schedule-on: app-workload # -- Taint tolerations for nodes tolerations: # - key: "dedicated" # operator: "Equal" # value: "app" # effect: "NoSchedule" # -- Pod affinity and pod anti-affinity allow you to specify rules about how pods should be placed relative to other pods. affinity: # nodeAffinity: # requiredDuringSchedulingIgnoredDuringExecution: # nodeSelectorTerms: # - matchExpressions: # - key: disktype # operator: In # values: # - ssd # -- [DNS configuration] dnsConfig: {} # -- Alternative DNS policy for application controller pods dnsPolicy: "ClusterFirst" secret: name: "aurva-ocr-secrets" # -- Additional Labels on secrets additionalLabels: # key: value # -- Annotations on secrets annotations: # key: value config: PG_USERNAME: "postgres" PG_PASSWORD: "aurva" PG_DBNAME: "controller" OCR_TIME_LIMIT: "1" serviceAccount: # -- Create a service account for the aurva controller create: true # -- Service account name name: aurva-ocr-sa # -- Annotations applied to created service account annotations: # eks.amazonaws.com/role-arn: arn:aws:iam:::role/ # -- Labels applied to created service account labels: {} ########################################################## # Aurva Proxy ########################################################## aurva_proxy: # -- Additional labels for aurva-proxy additionalLabels: {} # -- Annotations on aurva-proxy annotations: {} # "key": "value" revisionHistoryLimit: 3 # -- no of replicas for aurva proxy replicas: 4 # -- Additional label added on pod which is used in Service's Label Selector podLabels: {} # -- Additional Pod Annotations added on pod created by this Deployment additionalPodAnnotations: {} # "key": "value" # -- Secrets used to pull image imagePullSecrets: "" # Image of the app container image: repository: 119191042565.dkr.ecr.ap-south-1.amazonaws.com/aurva-proxy tag: "v1.2.6" pullPolicy: IfNotPresent # Environment variables to be passed to the app container env: [] # -- If want to mount Envs from configmap or secret envFrom: aurva-controller: type: secret name: aurva-proxy-secrets # -- Resources to be defined for pod resources: limits: memory: 512Mi cpu: 1 requests: memory: 256Mi cpu: 0.5 # -- Select nodes to deploy which matches the following labels nodeSelector: # cloud.google.com/gke-nodepool: default-pool # schedule-on: app-workload # -- Taint tolerations for nodes tolerations: # - key: "dedicated" # operator: "Equal" # value: "app" # effect: "NoSchedule" # -- Pod affinity and pod anti-affinity allow you to specify rules about how pods should be placed relative to other pods. affinity: # nodeAffinity: # requiredDuringSchedulingIgnoredDuringExecution: # nodeSelectorTerms: # - matchExpressions: # - key: disktype # operator: In # values: # - ssd # -- [DNS configuration] dnsConfig: {} # -- Alternative DNS policy for application controller pods dnsPolicy: "ClusterFirst" secret: name: "aurva-proxy-secrets" # -- Additional Labels on secrets additionalLabels: # key: value # -- Annotations on secrets annotations: # key: value config: # PG_HOST: "aurva-dataplane-database.aurva-dataplane.svc.cluster.local" PG_USERNAME: "postgres" PG_PASSWORD: "aurva" PG_DBNAME: "controller" # CONTROLLER_HOST: "aurva-controller.aurva-dataplane" CONTROLLER_PORT: "9090" COMPANY_ID: "47c5ed30-c23e-48c3-a510-9c9378867737" # TODO: update this with your relevant COMPANY_ID JWT_PUBLIC_KEY: "-----BEGIN PUBLIC KEY-----\nMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEfS6iQUtuHtloso4mZeSg0663/a4F\n61UIvWTs5XtI3fE7/7LbQpPD5u5l7xDQpqRjD0wfIT32Y3WgjqyDQTadag==\n-----END PUBLIC KEY-----" PROXY_HOST: "proxy.aurva.io" PROXY_PORT: "8090" serviceAccount: # -- Create a service account for the aurva controller create: true # -- Service account name name: aurva-proxy-sa # -- Annotations applied to created service account annotations: # eks.amazonaws.com/role-arn: arn:aws:iam:::role/ # -- Labels applied to created service account labels: {}