/ abyss / cilium.tf
cilium.tf
 1  resource "helm_release" "cilium" {
 2    name      = "cilium"
 3    version   = "1.15.0"
 4    namespace = "kube-system"
 5  
 6    repository = "https://helm.cilium.io/"
 7    chart      = "cilium"
 8  
 9    values = [<<YAML
10      ipam:
11        mode: kubernetes
12      kubeProxyReplacement: "true"
13      k8sServiceHost: localhost
14      k8sServicePort: 7445
15      securityContext:
16        capabilities:
17          ciliumAgent: [CHOWN,KILL,NET_ADMIN,NET_RAW,IPC_LOCK,SYS_ADMIN,SYS_RESOURCE,DAC_OVERRIDE,FOWNER,SETGID,SETUID]
18          cleanCiliumState: [NET_ADMIN,SYS_ADMIN,SYS_RESOURCE]
19      cgroup:
20        autoMount:
21          enabled: false
22        hostRoot: /sys/fs/cgroup
23    YAML
24    ]
25  }