QHx Proxy Central Notary Configuration
This guide shows an example configuration of a central QHx Proxy notary instance. This configuration supports notarization of HTTP requests using the OpenAI inference API in conjunction with client and server mode proxy sidecars.
---apiVersion: v1kind: Namespacemetadata: name: qhx-notary---apiVersion: v1kind: ServiceAccountmetadata: name: notary namespace: qhx-notary---apiVersion: rbac.authorization.k8s.io/v1kind: ClusterRolemetadata: name: pod-readerrules: - apiGroups: [""] resources: ["pods"] verbs: ["get", "list", "watch"]---apiVersion: rbac.authorization.k8s.io/v1kind: ClusterRoleBindingmetadata: name: notary-pod-readersubjects: - kind: ServiceAccount name: notary namespace: qhx-notaryroleRef: kind: ClusterRole name: pod-reader apiGroup: rbac.authorization.k8s.io---apiVersion: apps/v1kind: Deploymentmetadata: name: notary namespace: qhx-notary labels: app: notaryspec: replicas: 1 selector: matchLabels: app: notary template: metadata: labels: app: central-proxy spec: serviceAccountName: notary containers: - name: qhx-proxy image: "oci.messier42.com/qhx/proxy:v${RELEASE_VERSION}" imagePullPolicy: Always ports: - containerPort: 8081 name: http env: - name: QHX_PROXY_CONFIG value: | spiffe: workload_socket_path: unix:///spiffe-workload-api/agent.sock notary: enable: true database: path: /database/notary.db listeners: - name: notary address: "0.0.0.0:8081" protocol: http mode: central target: url: "https://app-server.example.svc.cluster.local:8081" spiffe_ids: - "^spiffe://qhx.dev/ns/example/sa/app-server/.*$" middlewares: - type: notary-query - type: openai timeouts: read: 600s write: 600s idle: 600s volumeMounts: - name: database mountPath: /database - name: spiffe-workload-api mountPath: /spiffe-workload-api readOnly: true resources: requests: memory: "64Mi" cpu: "100m" limits: memory: "256Mi" cpu: "500m" volumes: - name: database emptyDir: {} - name: spiffe-workload-api csi: driver: csi.spiffe.io readOnly: true---apiVersion: v1kind: Servicemetadata: name: notary namespace: qhx-notaryspec: selector: app: notary type: ClusterIP ports: - protocol: TCP port: 8081 targetPort: 8081