Skip to content

Commit b6e28c9

Browse files
williamlin-susekakabisht
authored andcommitted
add Cacerts example in configmap
1 parent 1a2373e commit b6e28c9

3 files changed

Lines changed: 51 additions & 3 deletions

File tree

‎docs/02.deploying/01.production/01.configmap/01.configmap.md‎

Lines changed: 17 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ The 'always_reload: true' setting can be added in any ConfigMap yaml to force re
1313

1414
#### Complete Sample NeuVector ConfigMap (initcfg.yaml)
1515

16-
The latest ConfigMap can be found at the following [initcfg.yaml file](https://raw.githubusercontent.com/neuvector/manifests/main/kubernetes/5.4.0/initcfg.yaml).
16+
The latest ConfigMap can be found at the following [initcfg.yaml file](https://raw.githubusercontent.com/neuvector/manifests/main/kubernetes/latest/initcfg.yaml).
1717

1818
The sample is also shown below. This contains all the settings available. Please remove the sections not needed and edit the sections needed. Note: If using configmap in a secret, see section below for formatting changes.
1919

@@ -393,6 +393,22 @@ data:
393393
Auto_Scan: false
394394
# Optional. default value is 24. unit is hour and range is between 0 and 168
395395
Unused_Group_Aging: 24
396+
# Optional. Enable TLS verification for communications to LDAP/OIDC/webhook/registry servers. Enabled by default for new deployment
397+
Enable_Tls_Verification: true
398+
# Optional. TLS self-signed certificate context when TLS verification is enabled
399+
Cacerts:
400+
- |
401+
-----BEGIN CERTIFICATE-----
402+
..................
403+
..................
404+
........
405+
-----END CERTIFICATE-----
406+
- |
407+
-----BEGIN CERTIFICATE-----
408+
..................
409+
..................
410+
........
411+
-----END CERTIFICATE-----
396412
userinitcfg.yaml: |
397413
# Optional. true or false or empty string(false)
398414
always_reload: false

‎versioned_docs/version-5.5/02.deploying/01.production/01.configmap/01.configmap.md‎

Lines changed: 17 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ The 'always_reload: true' setting can be added in any ConfigMap yaml to force re
1313

1414
#### Complete Sample NeuVector ConfigMap (initcfg.yaml)
1515

16-
The latest ConfigMap can be found at the following [initcfg.yaml file](https://raw.githubusercontent.com/neuvector/manifests/main/kubernetes/5.4.0/initcfg.yaml).
16+
The latest ConfigMap can be found at the following [initcfg.yaml file](https://raw.githubusercontent.com/neuvector/manifests/main/kubernetes/5.5.0/initcfg.yaml).
1717

1818
The sample is also shown below. This contains all the settings available. Please remove the sections not needed and edit the sections needed. Note: If using configmap in a secret, see section below for formatting changes.
1919

@@ -393,6 +393,22 @@ data:
393393
Auto_Scan: false
394394
# Optional. default value is 24. unit is hour and range is between 0 and 168
395395
Unused_Group_Aging: 24
396+
# Optional. Enable TLS verification for communications to LDAP/OIDC/webhook/registry servers. Enabled by default for new deployment
397+
Enable_Tls_Verification: true
398+
# Optional. TLS self-signed certificate context when TLS verification is enabled
399+
Cacerts:
400+
- |
401+
-----BEGIN CERTIFICATE-----
402+
..................
403+
..................
404+
........
405+
-----END CERTIFICATE-----
406+
- |
407+
-----BEGIN CERTIFICATE-----
408+
..................
409+
..................
410+
........
411+
-----END CERTIFICATE-----
396412
userinitcfg.yaml: |
397413
# Optional. true or false or empty string(false)
398414
always_reload: false

‎versioned_docs/version-5.6/02.deploying/01.production/01.configmap/01.configmap.md‎

Lines changed: 17 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ The 'always_reload: true' setting can be added in any ConfigMap yaml to force re
1313

1414
#### Complete Sample NeuVector ConfigMap (initcfg.yaml)
1515

16-
The latest ConfigMap can be found at the following [initcfg.yaml file](https://raw.githubusercontent.com/neuvector/manifests/main/kubernetes/5.4.0/initcfg.yaml).
16+
The latest ConfigMap can be found at the following [initcfg.yaml file](https://raw.githubusercontent.com/neuvector/manifests/main/kubernetes/5.6.0/initcfg.yaml).
1717

1818
The sample is also shown below. This contains all the settings available. Please remove the sections not needed and edit the sections needed. Note: If using configmap in a secret, see section below for formatting changes.
1919

@@ -393,6 +393,22 @@ data:
393393
Auto_Scan: false
394394
# Optional. default value is 24. unit is hour and range is between 0 and 168
395395
Unused_Group_Aging: 24
396+
# Optional. Enable TLS verification for communications to LDAP/OIDC/webhook/registry servers. Enabled by default for new deployment
397+
Enable_Tls_Verification: true
398+
# Optional. TLS self-signed certificate context when TLS verification is enabled
399+
Cacerts:
400+
- |
401+
-----BEGIN CERTIFICATE-----
402+
..................
403+
..................
404+
........
405+
-----END CERTIFICATE-----
406+
- |
407+
-----BEGIN CERTIFICATE-----
408+
..................
409+
..................
410+
........
411+
-----END CERTIFICATE-----
396412
userinitcfg.yaml: |
397413
# Optional. true or false or empty string(false)
398414
always_reload: false

0 commit comments

Comments
 (0)