iac/clusters/yc-infra-prod/infrastructure/patches/vault-unseal.yaml

29 lines
611 B
YAML

apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: vault-unseal
namespace: vault-unseal
spec:
interval: 5m
timeout: 15m
values:
global:
namespace: vault-unseal
autounseal:
enabled: false
backup:
enabled: true
schedule: "0 19 * * *"
timeZone: "Europe/Moscow"
secret:
name: "vault-unseal-backup-s3"
endpoint: "https://storage.yandexcloud.net"
prefix: "vault/yc-infra-prod/unseal-raft-snapshots"
injector:
enabled: false
server:
ha:
replicas: 3
dataStorage:
size: 10Gi