diff --git a/charts/default/README.md b/charts/default/README.md index 373f6889..f629a8c4 100644 --- a/charts/default/README.md +++ b/charts/default/README.md @@ -86,3 +86,5 @@ concerns. |-----|---------|-------------| | `service.type` | `ClusterIP` | Service type. | | `service.port` | `80` | Service port (also the default `HTTPRoute` backend port). | +| `serviceAccount.name` | `''` | Existing ServiceAccount the pod runs as, e.g. one bound to an Azure Workload Identity. Empty renders no `serviceAccountName`. The chart does not create it. | +| `podLabels` | `{}` | Extra labels on the pod template only, never the selector. Values render as strings, e.g. `--set 'podLabels.azure\.workload\.identity/use=true'`. `app`, `draft` and `release` are set by the chart and can't be overridden. | diff --git a/charts/default/templates/deployment.yaml b/charts/default/templates/deployment.yaml index 361c0fc1..e60749b5 100644 --- a/charts/default/templates/deployment.yaml +++ b/charts/default/templates/deployment.yaml @@ -20,9 +20,18 @@ spec: app: {{ template "project.name" . }} draft: {{ .Values.draft | default "draft-app" }} release: {{ .Release.Name }} + {{- range $key, $value := .Values.podLabels }} + {{- if has $key (list "app" "draft" "release") }} + {{- fail (printf "podLabels.%s is set by the chart and can't be overridden" $key) }} + {{- end }} + {{ $key }}: {{ $value | quote }} + {{- end }} annotations: buildID: {{ .Values.buildID | default "" | quote }} spec: + {{- with .Values.serviceAccount.name }} + serviceAccountName: {{ . | quote }} + {{- end }} {{- if .Values.hostAliases }} hostAliases: {{- range .Values.hostAliases }} diff --git a/charts/default/values.yaml b/charts/default/values.yaml index 511a0e30..955d5b46 100644 --- a/charts/default/values.yaml +++ b/charts/default/values.yaml @@ -103,6 +103,17 @@ tolerations: [] affinity: {} +# Existing ServiceAccount for the pod to run as, e.g. one bound to an Azure Workload Identity. +# Empty (default) renders no serviceAccountName, so the namespace's default ServiceAccount is used. +# The chart does not create the ServiceAccount. +serviceAccount: + name: '' + +# Extra labels on the pod template only, never the selector. Values always render as strings. +# app, draft and release are set by the chart and can't be overridden. +# e.g. --set 'podLabels.azure\.workload\.identity/use=true' +podLabels: {} + # db is the connection string for the database db: ""