From a7f9d2d30ed2650de473c887c29bf5043c8334d9 Mon Sep 17 00:00:00 2001 From: Firas Medini Date: Thu, 12 Feb 2026 02:52:17 +0100 Subject: [PATCH] charts/apisix: Add support for setting encryption configs Signed-off-by: Firas Medini --- charts/apisix/templates/configmap.yaml | 10 ++++++++++ charts/apisix/values.yaml | 7 +++++++ 2 files changed, 17 insertions(+) diff --git a/charts/apisix/templates/configmap.yaml b/charts/apisix/templates/configmap.yaml index b8ecb4da..e4eb6d41 100644 --- a/charts/apisix/templates/configmap.yaml +++ b/charts/apisix/templates/configmap.yaml @@ -44,6 +44,16 @@ data: {{- end }} {{- else }} apisix: # universal configurations + {{- if .Values.apisix.encryption }} + data_encryption: # Data encryption settings + enable_encrypt_fields: {{ .Values.apisix.encryption.enabled }} + {{- if and .Values.apisix.encryption.keyring (gt (len .Values.apisix.encryption.keyring) 0) }} + keyring: + {{- range $key := .Values.apisix.encryption.keyring }} + - {{ $key | quote }} + {{- end }} + {{- end }} + {{- end }} {{- if not (eq .Values.apisix.deployment.role "control_plane") }} node_listen: # APISIX listening port - {{ .Values.service.http.containerPort }} diff --git a/charts/apisix/values.yaml b/charts/apisix/values.yaml index 520f4d0d..5e75469e 100644 --- a/charts/apisix/values.yaml +++ b/charts/apisix/values.yaml @@ -603,6 +603,13 @@ apisix: ip: "0.0.0.0" port: 7085 + # -- Data encryption settings. + encryption: + # -- Enable or disable the encryption feature. + enabled: true + # -- The keyring used for encryption and decryption of sensitive data, e.g. "0123456789abcdef" or "${{MY_ENV_VAR}}". Leave empty to use the default keyring. + keyring: [] + # -- When configured, APISIX will trust the `X-Forwarded-*` Headers passed in requests from the IP/CIDR in the list. trustedAddresses: - 127.0.0.1