8 secret: tsa-server-secret
12 # Credentials file read by kms/tink if set. Unset by default
13 GOOGLE_APPLICATION_CREDENTIALS: ""
16 repository: chainguard-private/timestamp-authority-server
17 pullPolicy: IfNotPresent
18 # crane digest ghcr.io/sigstore/timestamp-server:v2.0.5
19 version: latest@sha256:bb470564b133cbbe4c0cf492ca07b71020442e6fa4fc1664157b9c463ac1b1bb
22 # Valid values: tink, kms, file
24 # PEM encoded cert chain here. Order from active intermedate first to root last
26 tink_enc_keyset: keyset
27 tink_key_resource: resource
28 tink_hcvault_token: token
29 kms_key_resource: resource
39 port: 80 # must match .Values.server.svcPort
53 host: "timestamp.localhost"
65# Force namespace of namespaced resources