+ auth:
+ username: kong
+ database: kong
+ image:
+ # use postgres < 14 until is https://github.com/Kong/kong/issues/8533 resolved and released
+ # enterprise (kong-gateway) supports postgres 14
+ tag: 13.11.0-debian-11-r20
+ service:
+ ports:
+ postgresql: "5432"
+
+# -----------------------------------------------------------------------------
+# Configure cert-manager integration
+# -----------------------------------------------------------------------------
+
+certificates:
+ enabled: false
+
+ # Set either `issuer` or `clusterIssuer` to the name of the desired cert manager issuer
+ # If left blank a built in self-signed issuer will be created and utilized
+ issuer: ""
+ clusterIssuer: ""
+
+ # Set proxy.enabled to true to issue default kong-proxy certificate with cert-manager
+ proxy:
+ enabled: true
+ # Set `issuer` or `clusterIssuer` to name of alternate cert-manager clusterIssuer to override default
+ # self-signed issuer.
+ issuer: ""
+ clusterIssuer: ""
+ # Use commonName and dnsNames to set the common name and dns alt names which this
+ # certificate is valid for. Wildcard records are supported by the included self-signed issuer.
+ commonName: "app.example"
+ # Remove the "[]" and uncomment/change the examples to add SANs
+ dnsNames: []
+ # - "app.example"
+ # - "*.apps.example"
+ # - "*.kong.example"
+
+ # Set admin.enabled true to issue kong admin api and manager certificate with cert-manager
+ admin:
+ enabled: true
+ # Set `issuer` or `clusterIssuer` to name of alternate cert-manager clusterIssuer to override default
+ # self-signed issuer.
+ issuer: ""
+ clusterIssuer: ""
+ # Use commonName and dnsNames to set the common name and dns alt names which this
+ # certificate is valid for. Wildcard records are supported by the included self-signed issuer.
+ commonName: "kong.example"
+ # Remove the "[]" and uncomment/change the examples to add SANs
+ dnsNames: []
+ # - "manager.kong.example"
+
+ # Set portal.enabled to true to issue a developer portal certificate with cert-manager
+ portal:
+ enabled: true
+ # Set `issuer` or `clusterIssuer` to name of alternate cert-manager clusterIssuer to override default
+ # self-signed issuer.
+ issuer: ""
+ clusterIssuer: ""
+ # Use commonName and dnsNames to set the common name and dns alt names which this
+ # certificate is valid for. Wildcard records are supported by the included self-signed issuer.
+ commonName: "developer.example"
+ # Remove the "{}" and uncomment/change the examples to add SANs
+ dnsNames: []
+ # - "manager.kong.example"
+
+ # Set cluster.enabled true to issue kong hybrid mtls certificate with cert-manager
+ cluster:
+ enabled: true
+ # Issuers used by the control and data plane releases must match for this certificate.
+ issuer: ""
+ clusterIssuer: ""
+ commonName: "kong_clustering"
+ dnsNames: []