Configure and Install Components Using Values Files
Every installation in this guide can also be performed with a YAML values file instead of a chain of --set flags. This is the recommended approach for production, because the file can be version-controlled, reviewed, and reused for upgrades.
Long multi-line commands are error-prone: if a space remains after a trailing backslash when the command is pasted into a terminal, the command breaks and Helm reports errors such as “helm upgrade requires 2 arguments”. Using a values file avoids this class of error entirely.
Agent — `agent-values.yaml`:
secrets:
installToken: "<KRON_PAM_AAPM_AGENT_INSTALLATION_TOKEN>"
address: "<KRON_PAM_SERVER_ADDRESS>"
config:
singleconnect:
agentName: "<AGENT_NAME>"
sslIgnored: false
hostnameIgnored: falseThen execute the following commands
helm install kron-aapm-agent kron-pam/kron-aapm-agent \
--namespace ns-agent --create-namespace \
-f agent-values.yamlaapm-service — `service-values.yaml`:
agent:
service: "kron-aapm-agent.ns-agent.svc.cluster.local"
port: "8080"
ignoreCertificate: true
interceptor:
ignoreCertificate: false
pam:
url: "https://<KRON_PAM_SERVER_ADDRESS>"
vault:
allowedAccounts:
- accountName: "<ACCOUNT_NAME>"
accountPath: "<ACCOUNT_PATH>"Then execute the following commands:
helm install aapm-service kron-pam/aapm-service \
--namespace kron-pam-aapm --create-namespace \
-f service-values.yamlInjector — `sidecar-values.yaml`:
namespace:
name: ns-sidecar
aapmConnection:
agentService: "kron-aapm-agent.ns-agent.svc.cluster.local"
agentPort: "8080"
directAccessUrl: "https://<KRON_PAM_SERVER_ADDRESS>"
ignoreCertificate: true
ignoreInterceptorCertificate: false
sidecarImage:
tag: "<VERIFIED_IMAGE_TAG>"Then execute the following commands:
helm install kron-aapm-sidecar kron-pam/kron-aapm-sidecar \
--namespace ns-sidecar --create-namespace \
-f sidecar-values.yamlValues files contain installation tokens and Kron PAM access tokens. Store them with restricted permissions (chmod 600) and never commit them to a shared repository in plain text.
To review the values a release was actually installed with at any later point:
helm get values <release-name> -n <namespace>
helm get values <release-name> -n <namespace> --all