diff --git a/charts/sda-svc/templates/re-encrypt-certificate.yaml b/charts/sda-svc/templates/re-encrypt-certificate.yaml index def48d86d..d68e2a6c3 100644 --- a/charts/sda-svc/templates/re-encrypt-certificate.yaml +++ b/charts/sda-svc/templates/re-encrypt-certificate.yaml @@ -18,6 +18,7 @@ spec: algorithm: ECDSA size: 256 usages: + - client auth - server auth # At least one of a DNS Name, URI, or IP address is required. dnsNames: diff --git a/charts/sda-svc/templates/re-encrypt-deploy.yaml b/charts/sda-svc/templates/re-encrypt-deploy.yaml index 74b7c914a..a5d30a185 100644 --- a/charts/sda-svc/templates/re-encrypt-deploy.yaml +++ b/charts/sda-svc/templates/re-encrypt-deploy.yaml @@ -74,10 +74,14 @@ spec: ports: - name: grpc containerPort: {{ ternary 50443 50051 ( .Values.global.tls.enabled ) }} + - name: grpchealth + containerPort: {{add ( ternary 50443 50051 ( .Values.global.tls.enabled ) ) 1 }} readinessProbe: - initialDelaySeconds: 15 - tcpSocket: - port: {{ ternary 50443 50051 ( .Values.global.tls.enabled ) }} + initialDelaySeconds: 5 + timeoutSeconds: 2 + grpc: + port: {{add ( ternary 50443 50051 ( .Values.global.tls.enabled ) ) 1 }} + service: "reencrypt.Reencrypt" resources: {{ toYaml .Values.reencrypt.resources | trim | indent 10 }} volumeMounts: diff --git a/charts/sda-svc/templates/re-encrypt-service.yaml b/charts/sda-svc/templates/re-encrypt-service.yaml index e41464d7d..977708054 100644 --- a/charts/sda-svc/templates/re-encrypt-service.yaml +++ b/charts/sda-svc/templates/re-encrypt-service.yaml @@ -10,6 +10,9 @@ spec: - name: reencrypt port: {{ ternary 50443 50051 ( .Values.global.tls.enabled ) }} targetPort: grpc + - name: healthcheck + port: {{add ( ternary 50443 50051 ( .Values.global.tls.enabled ) ) 1 }} + targetPort: grpchealth selector: app: {{ template "sda.name" . }}-reencrypt {{- end }}