iac/clusters/yc-infra-prod/infrastructure/patches/vault.yaml

31 lines
687 B
YAML

apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: vault
namespace: vault
spec:
interval: 5m
timeout: 15m
values:
global:
namespace: vault
autounseal:
transit:
address: "https://vault-unseal.infra.sarex.io"
keyName: "vault-infra-prod"
mountPath: "transit/"
tlsSkipVerify: false
secret:
name: "vault-transit-autounseal"
backup:
schedule: "0 * * * *"
secret:
name: "vault-backup-s3"
endpoint: "https://storage.yandexcloud.net"
prefix: "vault/yc-infra-prod/raft-snapshots"
server:
dataStorage:
size: 20Gi
ha:
replicas: 3