Created
January 15, 2021 03:50
-
-
Save fai555/d6791428ab805f40f2fc9314cbfb4729 to your computer and use it in GitHub Desktop.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| apiVersion: install.istio.io/v1alpha1 | |
| kind: IstioOperator | |
| spec: | |
| addonComponents: | |
| istiocoredns: | |
| enabled: false | |
| components: | |
| base: | |
| enabled: true | |
| cni: | |
| enabled: false | |
| egressGateways: | |
| - enabled: false | |
| k8s: | |
| env: | |
| - name: ISTIO_META_ROUTER_MODE | |
| value: standard | |
| hpaSpec: | |
| maxReplicas: 5 | |
| metrics: | |
| - resource: | |
| name: cpu | |
| targetAverageUtilization: 80 | |
| type: Resource | |
| minReplicas: 1 | |
| scaleTargetRef: | |
| apiVersion: apps/v1 | |
| kind: Deployment | |
| name: istio-egressgateway | |
| resources: | |
| limits: | |
| cpu: 2000m | |
| memory: 1024Mi | |
| requests: | |
| cpu: 100m | |
| memory: 128Mi | |
| service: | |
| ports: | |
| - name: http2 | |
| port: 80 | |
| protocol: TCP | |
| targetPort: 8080 | |
| - name: https | |
| port: 443 | |
| protocol: TCP | |
| targetPort: 8443 | |
| - name: tls | |
| port: 15443 | |
| protocol: TCP | |
| targetPort: 15443 | |
| strategy: | |
| rollingUpdate: | |
| maxSurge: 100% | |
| maxUnavailable: 25% | |
| name: istio-egressgateway | |
| ingressGateways: | |
| - enabled: true | |
| k8s: | |
| env: | |
| - name: ISTIO_META_ROUTER_MODE | |
| value: standard | |
| hpaSpec: | |
| maxReplicas: 5 | |
| metrics: | |
| - resource: | |
| name: cpu | |
| targetAverageUtilization: 80 | |
| type: Resource | |
| minReplicas: 1 | |
| scaleTargetRef: | |
| apiVersion: apps/v1 | |
| kind: Deployment | |
| name: istio-ingressgateway | |
| resources: | |
| limits: | |
| cpu: 2000m | |
| memory: 1024Mi | |
| requests: | |
| cpu: 100m | |
| memory: 128Mi | |
| service: | |
| ports: | |
| - name: status-port | |
| port: 15021 | |
| protocol: TCP | |
| targetPort: 15021 | |
| - name: http2 | |
| port: 80 | |
| protocol: TCP | |
| targetPort: 8080 | |
| - name: https | |
| port: 443 | |
| protocol: TCP | |
| targetPort: 8443 | |
| - name: tcp-istiod | |
| port: 15012 | |
| protocol: TCP | |
| targetPort: 15012 | |
| - name: tls | |
| port: 15443 | |
| protocol: TCP | |
| targetPort: 15443 | |
| strategy: | |
| rollingUpdate: | |
| maxSurge: 100% | |
| maxUnavailable: 25% | |
| name: istio-ingressgateway | |
| istiodRemote: | |
| enabled: false | |
| pilot: | |
| enabled: true | |
| k8s: | |
| env: | |
| - name: POD_NAME | |
| valueFrom: | |
| fieldRef: | |
| apiVersion: v1 | |
| fieldPath: metadata.name | |
| - name: POD_NAMESPACE | |
| valueFrom: | |
| fieldRef: | |
| apiVersion: v1 | |
| fieldPath: metadata.namespace | |
| readinessProbe: | |
| httpGet: | |
| path: /ready | |
| port: 8080 | |
| initialDelaySeconds: 1 | |
| periodSeconds: 3 | |
| timeoutSeconds: 5 | |
| strategy: | |
| rollingUpdate: | |
| maxSurge: 100% | |
| maxUnavailable: 25% | |
| hub: docker.io/istio | |
| meshConfig: | |
| defaultConfig: | |
| proxyMetadata: {} | |
| enablePrometheusMerge: true | |
| profile: default | |
| tag: 1.8.1 | |
| values: | |
| base: | |
| enableCRDTemplates: false | |
| validationURL: "" | |
| clusterResources: true | |
| gateways: | |
| istio-egressgateway: | |
| autoscaleEnabled: true | |
| env: {} | |
| name: istio-egressgateway | |
| secretVolumes: | |
| - mountPath: /etc/istio/egressgateway-certs | |
| name: egressgateway-certs | |
| secretName: istio-egressgateway-certs | |
| - mountPath: /etc/istio/egressgateway-ca-certs | |
| name: egressgateway-ca-certs | |
| secretName: istio-egressgateway-ca-certs | |
| type: ClusterIP | |
| zvpn: {} | |
| istio-ingressgateway: | |
| autoscaleEnabled: true | |
| env: {} | |
| name: istio-ingressgateway | |
| secretVolumes: | |
| - mountPath: /etc/istio/ingressgateway-certs | |
| name: ingressgateway-certs | |
| secretName: istio-ingressgateway-certs | |
| - mountPath: /etc/istio/ingressgateway-ca-certs | |
| name: ingressgateway-ca-certs | |
| secretName: istio-ingressgateway-ca-certs | |
| type: LoadBalancer | |
| zvpn: {} | |
| global: | |
| arch: | |
| amd64: 2 | |
| ppc64le: 2 | |
| s390x: 2 | |
| configValidation: true | |
| defaultNodeSelector: {} | |
| defaultPodDisruptionBudget: | |
| enabled: true | |
| defaultResources: | |
| requests: | |
| cpu: 10m | |
| imagePullPolicy: "" | |
| imagePullSecrets: [] | |
| istioNamespace: istio-system | |
| istiod: | |
| enableAnalysis: false | |
| jwtPolicy: third-party-jwt | |
| logAsJson: false | |
| logging: | |
| level: default:info | |
| meshExpansion: | |
| enabled: false | |
| useILB: false | |
| meshNetworks: {} | |
| mountMtlsCerts: false | |
| multiCluster: | |
| clusterName: "" | |
| enabled: false | |
| network: "" | |
| omitSidecarInjectorConfigMap: false | |
| oneNamespace: false | |
| operatorManageWebhooks: false | |
| pilotCertProvider: istiod | |
| priorityClassName: "" | |
| proxy: | |
| autoInject: enabled | |
| clusterDomain: cluster.local | |
| componentLogLevel: misc:error | |
| enableCoreDump: false | |
| excludeIPRanges: "" | |
| excludeInboundPorts: "" | |
| excludeOutboundPorts: "" | |
| image: proxyv2 | |
| includeIPRanges: '*' | |
| logLevel: warning | |
| privileged: false | |
| readinessFailureThreshold: 30 | |
| readinessInitialDelaySeconds: 1 | |
| readinessPeriodSeconds: 2 | |
| resources: | |
| limits: | |
| cpu: 2000m | |
| memory: 1024Mi | |
| requests: | |
| cpu: 100m | |
| memory: 128Mi | |
| statusPort: 15020 | |
| tracer: zipkin | |
| proxy_init: | |
| image: proxyv2 | |
| resources: | |
| limits: | |
| cpu: 2000m | |
| memory: 1024Mi | |
| requests: | |
| cpu: 10m | |
| memory: 10Mi | |
| sds: | |
| token: | |
| aud: istio-ca | |
| sts: | |
| servicePort: 0 | |
| tracer: | |
| datadog: {} | |
| lightstep: {} | |
| stackdriver: {} | |
| zipkin: {} | |
| useMCP: false | |
| istiocoredns: | |
| coreDNSImage: coredns/coredns | |
| coreDNSPluginImage: istio/coredns-plugin:0.2-istio-1.1 | |
| coreDNSTag: 1.6.2 | |
| istiodRemote: | |
| injectionURL: "" | |
| pilot: | |
| autoscaleEnabled: true | |
| autoscaleMax: 5 | |
| autoscaleMin: 1 | |
| configMap: true | |
| cpu: | |
| targetAverageUtilization: 80 | |
| enableProtocolSniffingForInbound: true | |
| enableProtocolSniffingForOutbound: true | |
| env: {} | |
| image: pilot | |
| keepaliveMaxServerConnectionAge: 30m | |
| nodeSelector: {} | |
| replicaCount: 1 | |
| traceSampling: 1 | |
| sidecarInjectorWebhook: | |
| enableNamespacesByDefault: false | |
| objectSelector: | |
| autoInject: true | |
| enabled: false | |
| rewriteAppHTTPProbe: true | |
| telemetry: | |
| enabled: true | |
| v2: | |
| enabled: true | |
| metadataExchange: | |
| wasmEnabled: false | |
| prometheus: | |
| enabled: true | |
| wasmEnabled: false | |
| stackdriver: | |
| configOverride: {} | |
| enabled: false | |
| logging: false | |
| monitoring: false | |
| topology: false |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment