Skip to content

Helm Reference

(string, default qhx.dev, required)

The trustDomain value specifies a DNS domain name which should be a unique identifier for the cluster.

(string, default qhx-cluster, required)

The clusterName value specifies a unique identifier for the cluster which should meet the rules of a single DNS label (i.e., formed of alphanumeric characters and hyphens).

(string, default cluster.local, required)

The clusterDomain value specifies the Kubernetes cluster domain name to be used. This needs to match the cluster domain name configured for the Kubernetes cluster. In testing environments, it is often set to cluster.local, which is the default setting.

(string, no default value, required)

This must be set to one of the following supported values, and indicates the Kubernetes variant into which QHx is deployed.

ValueDescription
eksThe target cluster is an AWS EKS cluster.
kindThe target cluster is a cluster created with kind.
microk8sThe target cluster is a cluster created with microk8s installed via snap.
unknownThe target cluster is a generic Kubernetes cluster not corresponding to any of the above values.

The kubernetesVariant setting is used to set the other Kubernetes values defined in the QHx Helm chart to appropriate default values for the given Kubernetes variant. Each such value may still be overriden with a cluster-specific value if desired.

The value unknown uses reasonable defaults for most production Kubernetes environments and can be used to deploy QHx into unsupported Kubernetes environments. In some cases, it may be necessary to manually adjust other Kubernetes-related Helm values defined in the QHx helm chart.

(string, default: see below, required)

Specifies the path to the kubelet state directory on each of the cluster nodes. This is usually /var/lib/kubelet, but may vary according to the kubernetesVariant unless manually overriden. It defaults to /var/snap/microk8s/common/var/lib/kubelet for the microk8s variant.

(string, default “csi.spiffe.io”, required)

This configures the CSI plugin name used for the SPIFFE CSI integration. It is rarely necessary to change it unless it is needed to shorten UNIX domain socket paths.

(string, default “IfNotPresent”, required to be “IfNotPresent” or “Always”)

This sets the Kubernetes imagePullPolicy for QHx system images such as QHx Manager. The default value, IfNotPresent, is appropriate for most production environments.

The following images express OCI image references for the OCI images that comprise a QHx cluster. They can be customized if needed, for example to allow for installation against a private OCI registry.

SettingTypeDefault Value
managerImagestring (OCI Image Ref)"oci.messier42.com/qhx/manager:{VERSION}"
proxyImagestring (OCI Image Ref)"oci.messier42.com/qhx/proxy:{VERSION}"
agentImagestring (OCI Image Ref)"oci.messier42.com/qhx/agent:{VERSION}"
pkiServerImagestring (OCI Image Ref)"oci.messier42.com/qhx/pki-server:{VERSION}"
pkiAgentImagestring (OCI Image Ref)"oci.messier42.com/qhx/pki-agent:{VERSION}"
pkiControllerManagerImagestring (OCI Image Ref)"oci.messier42.com/qhx/pki-controller-manager:{VERSION}"

The following values configure OCI registry authentication credentials which are used to retrieve OCI images from the configured paths.

OCI credentials can be provided as a username and password, or as a base64-encoded Docker-style JSON object containing OCI credentials.

If ociSecretBase64 is specified as a non-empty value, it is used; otherwise, ociUsername and ociPassword are used to generate the required credentials file.

SettingTypeDefault Value
ociUsernamestring (required)""
ociPasswordstring (required)""
ociSecretBase64string (OCI Image Ref)""

These values can be used to tune the QHx installation, but are not expected to need to be changed in most testing production use cases.

(string (duration), default “2h”, required)

The lifetime of the certificate generated by QHx to enable communication from the Kubernetes control plane to the QHx admission controller.

(string (duration), default “30m”, required)

How frequently to rotate the certificate generated by QHx to enable communication from the Kubernetes control plane to the QHx admission controller. This must be less than the value of webhookCertTTL.