Skip to content

QHx Proxy Central Notary Configuration

This guide shows an example configuration of a central QHx Proxy notary instance. This configuration supports notarization of HTTP requests using the OpenAI inference API in conjunction with client and server mode proxy sidecars.

---
apiVersion: v1
kind: Namespace
metadata:
name: qhx-notary
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: notary
namespace: qhx-notary
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: pod-reader
rules:
- apiGroups: [""]
resources: ["pods"]
verbs: ["get", "list", "watch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: notary-pod-reader
subjects:
- kind: ServiceAccount
name: notary
namespace: qhx-notary
roleRef:
kind: ClusterRole
name: pod-reader
apiGroup: rbac.authorization.k8s.io
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: notary
namespace: qhx-notary
labels:
app: notary
spec:
replicas: 1
selector:
matchLabels:
app: notary
template:
metadata:
labels:
app: central-proxy
spec:
serviceAccountName: notary
containers:
- name: qhx-proxy
image: "oci.messier42.com/qhx/proxy:v${RELEASE_VERSION}"
imagePullPolicy: Always
ports:
- containerPort: 8081
name: http
env:
- name: QHX_PROXY_CONFIG
value: |
spiffe:
workload_socket_path: unix:///spiffe-workload-api/agent.sock
notary:
enable: true
database:
path: /database/notary.db
listeners:
- name: notary
address: "0.0.0.0:8081"
protocol: http
mode: central
target:
url: "https://app-server.example.svc.cluster.local:8081"
spiffe_ids:
- "^spiffe://qhx.dev/ns/example/sa/app-server/.*$"
middlewares:
- type: notary-query
- type: openai
timeouts:
read: 600s
write: 600s
idle: 600s
volumeMounts:
- name: database
mountPath: /database
- name: spiffe-workload-api
mountPath: /spiffe-workload-api
readOnly: true
resources:
requests:
memory: "64Mi"
cpu: "100m"
limits:
memory: "256Mi"
cpu: "500m"
volumes:
- name: database
emptyDir: {}
- name: spiffe-workload-api
csi:
driver: csi.spiffe.io
readOnly: true
---
apiVersion: v1
kind: Service
metadata:
name: notary
namespace: qhx-notary
spec:
selector:
app: notary
type: ClusterIP
ports:
- protocol: TCP
port: 8081
targetPort: 8081