DirectorySecurity AdvisoriesPricing
Sign in
Directory
alloy logoHELM

alloy

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:
Compare:

1
# -- Overrides the chart's name. Used to change the infix in the resource names.
2
nameOverride: null
3
# -- Overrides the chart's namespace.
4
namespaceOverride: null
5
# -- Overrides the chart's computed fullname. Used to change the full prefix of
6
# resource names.
7
fullnameOverride: null
8
## Global properties for image pulling override the values defined under `image.registry` and `configReloader.image.registry`.
9
## If you want to override only one image registry, use the specific fields but if you want to override them all, use `global.image.registry`
10
global:
11
image:
12
# -- Global image registry to use if it needs to be overridden for some specific use cases (e.g local registries, custom images, ...)
13
registry: ""
14
# -- Optional set of global image pull secrets.
15
pullSecrets: []
16
# -- Global image pull policy to apply to all containers. Overrides `image.pullPolicy` and `configReloader.image.pullPolicy`.
17
pullPolicy: ""
18
# -- Security context to apply to the Grafana Alloy pod.
19
podSecurityContext: {}
20
crds:
21
# -- Whether to install CRDs for monitoring.
22
create: true
23
## Various Alloy settings. For backwards compatibility with the grafana-agent
24
## chart, this field may also be called "agent". Naming this field "agent" is
25
## deprecated and will be removed in a future release.
26
alloy:
27
configMap:
28
# -- Create a new ConfigMap for the config file.
29
create: true
30
# -- Content to assign to the new ConfigMap. This is passed into `tpl` allowing for templating from values.
31
content: ''
32
# -- Name of existing ConfigMap to use. Used when create is false.
33
name: null
34
# -- Key in ConfigMap to get config from.
35
key: null
36
clustering:
37
# -- Deploy Alloy in a cluster to allow for load distribution.
38
enabled: false
39
# -- Name for the Alloy cluster. Used for differentiating between clusters.
40
name: ""
41
# -- Name for the port used for clustering, useful if running inside an Istio Mesh
42
portName: http
43
# -- Minimum stability level of components and behavior to enable. Must be
44
# one of "experimental", "public-preview", or "generally-available".
45
stabilityLevel: "generally-available"
46
# -- Path to where Grafana Alloy stores data (for example, the Write-Ahead Log).
47
# By default, data is lost between reboots.
48
storagePath: /tmp/alloy
49
# -- Enables Grafana Alloy container's http server port.
50
enableHttpServerPort: true
51
# -- Address to listen for traffic on. 0.0.0.0 exposes the UI to other
52
# containers.
53
listenAddr: 0.0.0.0
54
# -- Port to listen for traffic on.
55
listenPort: 12345
56
# -- Scheme is needed for readiness probes. If enabling tls in your configs, set to "HTTPS"
57
listenScheme: HTTP
58
# -- Initial delay for readiness probe.
59
initialDelaySeconds: 10
60
# -- Timeout for readiness probe.
61
timeoutSeconds: 1
62
# -- Base path where the UI is exposed.
63
uiPathPrefix: /
64
# -- Enables sending Grafana Labs anonymous usage stats to help improve Grafana
65
# Alloy.
66
enableReporting: true
67
# -- Extra environment variables to pass to the Alloy container.
68
extraEnv: []
69
# -- Maps all the keys on a ConfigMap or Secret as environment variables. https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.24/#envfromsource-v1-core
70
envFrom: []
71
# -- Override the entrypoint command for the Alloy container. When set, this
72
# replaces the image's default entrypoint (the chart-provided `args` are still
73
# passed). Useful on Windows where the binary lives at a different path, for
74
# example `["C:\\Program Files\\GrafanaLabs\\Alloy\\alloy.exe"]`. Leave empty
75
# to use the image's default entrypoint.
76
command: []
77
# -- Extra args to pass to `alloy run`: https://grafana.com/docs/alloy/latest/reference/cli/run/
78
extraArgs: []
79
# -- Extra ports to expose on the Alloy container.
80
# If `service.type` is `NodePort`, each item may set `nodePort` to choose the Service NodePort for that port.
81
extraPorts: []
82
# - name: "faro"
83
# nodePort: 31129
84
# port: 12347
85
# targetPort: 12347
86
# protocol: "TCP"
87
# appProtocol: "h2c"
88
89
# -- Host aliases to add to the Alloy container.
90
hostAliases: []
91
# - ip: "20.21.22.23"
92
# hostnames:
93
# - "company.grafana.net"
94
95
mounts:
96
# -- Mount /var/log from the host into the container for log collection.
97
varlog: false
98
# -- Mount /var/lib/docker/containers from the host into the container for log
99
# collection.
100
dockercontainers: false
101
# -- Extra volume mounts to add into the Grafana Alloy container. Does not
102
# affect the watch container.
103
extra: []
104
# -- Security context to apply to the Grafana Alloy container.
105
securityContext: {}
106
# -- Resource requests and limits to apply to the Grafana Alloy container.
107
resources: {}
108
# -- Set lifecycle hooks for the Grafana Alloy container.
109
lifecycle: {}
110
# preStop:
111
# exec:
112
# command:
113
# - /bin/sleep
114
# - "10"
115
116
# -- Set livenessProbe for the Grafana Alloy container.
117
livenessProbe: {}
118
image:
119
# -- Grafana Alloy image registry (defaults to docker.io)
120
registry: chainreg.biz
121
# -- Grafana Alloy image repository.
122
repository: chainguard-private/grafana-alloy
123
# -- (string) Grafana Alloy image tag. When empty, the Chart's appVersion is
124
# used.
125
tag: 1.20.1-r0
126
# -- Grafana Alloy image's SHA256 digest (either in format "sha256:XYZ" or "XYZ"). When set, will override `image.tag`.
127
digest: sha256:ae63498d44d329df962fc8c83d833fc72e9ea7b56a0200cbf7af454c42492ec4
128
# -- Grafana Alloy image pull policy.
129
pullPolicy: IfNotPresent
130
# -- Optional set of image pull secrets.
131
pullSecrets: []
132
rbac:
133
# -- Whether to create RBAC resources for Alloy.
134
create: true
135
# -- If set, only create Roles and RoleBindings in the given list of namespaces, rather than ClusterRoles and
136
# ClusterRoleBindings. If not using ClusterRoles, bear in mind that Alloy will not be able to discover cluster-scoped
137
# resources such as Nodes.
138
namespaces: []
139
# -- The rules to create for the ClusterRole or Role objects.
140
rules:
141
# -- Rules required for the `discovery.kubernetes` component.
142
- apiGroups: ["", "discovery.k8s.io", "networking.k8s.io"]
143
resources: ["endpoints", "endpointslices", "ingresses", "pods", "services"]
144
verbs: ["get", "list", "watch"]
145
# -- Rules required for the `loki.source.kubernetes` component.
146
- apiGroups: [""]
147
resources: ["pods", "pods/log", "namespaces"]
148
verbs: ["get", "list", "watch"]
149
# -- Rules required for the `loki.source.podlogs` component.
150
- apiGroups: ["monitoring.grafana.com"]
151
resources: ["podlogs"]
152
verbs: ["get", "list", "watch"]
153
# -- Rules required for the `mimir.rules.kubernetes` component.
154
- apiGroups: ["monitoring.coreos.com"]
155
resources: ["prometheusrules"]
156
verbs: ["get", "list", "watch"]
157
# -- Rules required for the `mimir.alerts.kubernetes` component.
158
- apiGroups: ["monitoring.coreos.com"]
159
resources: ["alertmanagerconfigs"]
160
verbs: ["get", "list", "watch"]
161
# -- Rules required for the `prometheus.operator.*` components.
162
- apiGroups: ["monitoring.coreos.com"]
163
resources: ["podmonitors", "servicemonitors", "probes", "scrapeconfigs"]
164
verbs: ["get", "list", "watch"]
165
# -- Rules required for the `loki.source.kubernetes_events` component.
166
- apiGroups: [""]
167
resources: ["events"]
168
verbs: ["get", "list", "watch"]
169
# -- Rules required for the `remote.kubernetes.*` components.
170
- apiGroups: [""]
171
resources: ["configmaps", "secrets"]
172
verbs: ["get", "list", "watch"]
173
# -- Rules required for the `otelcol.processor.k8sattributes` component.
174
- apiGroups: ["apps", "extensions"]
175
resources: ["replicasets"]
176
verbs: ["get", "list", "watch"]
177
# -- The rules to create for the ClusterRole objects.
178
clusterRules:
179
# -- Rules required for the Nodes role in the `discovery.kubernetes` component.
180
- apiGroups: [""]
181
resources: ["nodes"]
182
verbs: ["get", "list", "watch"]
183
# -- Rules required for the `discovery.kubelet` component.
184
- apiGroups: [""]
185
resources: ["nodes/pods"]
186
verbs: ["get", "list", "watch"]
187
# -- Rules required accessing metric endpoints on the Node (e.g. Kubelet, cAdvisor, etc...).
188
- apiGroups: [""]
189
resources: ["nodes/metrics"]
190
verbs: ["get", "list", "watch"]
191
# -- Rules required for accessing metrics endpoint.
192
- nonResourceURLs: ["/metrics"]
193
verbs: ["get"]
194
serviceAccount:
195
# -- Whether to create a service account for the Grafana Alloy deployment.
196
create: true
197
# -- Additional labels to add to the created service account.
198
additionalLabels: {}
199
# -- Annotations to add to the created service account.
200
annotations: {}
201
# -- The name of the existing service account to use when
202
# serviceAccount.create is false.
203
name: null
204
# Whether the Alloy pod should automatically mount the service account token.
205
automountServiceAccountToken: true
206
# Options for the extra controller used for config reloading.
207
configReloader:
208
# -- Enables automatically reloading when the Alloy config changes.
209
enabled: true
210
image:
211
# -- Config reloader image registry (defaults to docker.io)
212
registry: chainreg.biz
213
# -- Repository to get config reloader image from.
214
repository: chainguard-private/prometheus-config-reloader
215
# -- Tag of image to use for config reloading.
216
tag: 0.94.1-r0
217
# -- SHA256 digest of image to use for config reloading (either in format "sha256:XYZ" or "XYZ"). When set, will override `configReloader.image.tag`
218
digest: sha256:823019601dd011210745aa354c954e0ec31fb3a08f2fff55710f0f622383d8aa
219
# -- Config reloader image pull policy.
220
pullPolicy: IfNotPresent
221
# -- Override the args passed to the container.
222
customArgs: []
223
# -- Resource requests and limits to apply to the config reloader container.
224
resources:
225
requests:
226
cpu: "10m"
227
memory: "50Mi"
228
# -- Security context to apply to the Grafana configReloader container.
229
securityContext:
230
allowPrivilegeEscalation: false
231
readOnlyRootFilesystem: true
232
capabilities:
233
drop:
234
- ALL
235
runAsNonRoot: true
236
runAsUser: 65534
237
runAsGroup: 65534
238
seccompProfile:
239
type: RuntimeDefault
240
controller:
241
# -- Type of controller to use for deploying Grafana Alloy in the cluster.
242
# Must be one of 'daemonset', 'deployment', or 'statefulset'.
243
type: 'daemonset'
244
# -- Number of pods to deploy. Ignored when controller.type is 'daemonset'.
245
replicas: 1
246
# -- Extra labels to add to the controller.
247
extraLabels: {}
248
# -- Annotations to add to controller.
249
extraAnnotations: {}
250
# -- Whether to deploy pods in parallel. Only used when controller.type is
251
# 'statefulset'.
252
parallelRollout: true
253
# -- How many additional seconds to wait before considering a pod ready.
254
minReadySeconds: 10
255
# -- Configures Pods to use the host network. When set to true, the ports that will be used must be specified.
256
hostNetwork: false
257
# -- Configures Pods to use the host PID namespace.
258
hostPID: false
259
# -- Configures the DNS policy for the pod. https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-s-dns-policy
260
dnsPolicy: ClusterFirst
261
# -- Configures the DNS config for the pod. https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config
262
dnsConfig: {}
263
# -- Termination grace period in seconds for the Grafana Alloy pods.
264
# The default value used by Kubernetes if unspecifed is 30 seconds.
265
terminationGracePeriodSeconds: null
266
# -- The maximum number of revisions that will be maintained in the Controllers's revision history. The history consists of all revisions not represented by a currently applied reversion.
267
revisionHistoryLimit: 10
268
# -- Update strategy for updating deployed Pods.
269
updateStrategy: {}
270
# -- nodeSelector to apply to Grafana Alloy pods.
271
nodeSelector: {}
272
# -- Tolerations to apply to Grafana Alloy pods.
273
tolerations: []
274
# -- Topology Spread Constraints to apply to Grafana Alloy pods.
275
topologySpreadConstraints: []
276
# -- priorityClassName to apply to Grafana Alloy pods.
277
priorityClassName: ''
278
# -- Extra pod annotations to add.
279
podAnnotations: {}
280
# -- Extra pod labels to add.
281
podLabels: {}
282
# -- PodDisruptionBudget configuration.
283
podDisruptionBudget:
284
# -- Whether to create a PodDisruptionBudget for the controller.
285
enabled: false
286
# -- Minimum number of pods that must be available during a disruption.
287
# Note: Only one of minAvailable or maxUnavailable should be set.
288
minAvailable: null
289
# -- Maximum number of pods that can be unavailable during a disruption.
290
# Note: Only one of minAvailable or maxUnavailable should be set.
291
maxUnavailable: null
292
# -- Whether to enable automatic deletion of stale PVCs due to a scale down operation, when controller.type is 'statefulset'.
293
enableStatefulSetAutoDeletePVC: false
294
autoscaling:
295
# -- Creates a HorizontalPodAutoscaler for controller type deployment.
296
# Deprecated: Please use controller.autoscaling.horizontal instead
297
enabled: false
298
# -- The lower limit for the number of replicas to which the autoscaler can scale down.
299
minReplicas: 1
300
# -- The upper limit for the number of replicas to which the autoscaler can scale up.
301
maxReplicas: 5
302
# -- Average CPU utilization across all relevant pods, a percentage of the requested value of the resource for the pods. Setting `targetCPUUtilizationPercentage` to 0 will disable CPU scaling.
303
targetCPUUtilizationPercentage: 0
304
# -- Average Memory utilization across all relevant pods, a percentage of the requested value of the resource for the pods. Setting `targetMemoryUtilizationPercentage` to 0 will disable Memory scaling.
305
targetMemoryUtilizationPercentage: 80
306
scaleDown:
307
# -- List of policies to determine the scale-down behavior.
308
policies: []
309
# - type: Pods
310
# value: 4
311
# periodSeconds: 60
312
# -- Determines which of the provided scaling-down policies to apply if multiple are specified.
313
selectPolicy: Max
314
# -- The duration that the autoscaling mechanism should look back on to make decisions about scaling down.
315
stabilizationWindowSeconds: 300
316
scaleUp:
317
# -- List of policies to determine the scale-up behavior.
318
policies: []
319
# - type: Pods
320
# value: 4
321
# periodSeconds: 60
322
# -- Determines which of the provided scaling-up policies to apply if multiple are specified.
323
selectPolicy: Max
324
# -- The duration that the autoscaling mechanism should look back on to make decisions about scaling up.
325
stabilizationWindowSeconds: 0
326
# -- Configures the Horizontal Pod Autoscaler for the controller.
327
horizontal:
328
# -- Enables the Horizontal Pod Autoscaler for the controller.
329
enabled: false
330
# -- When true, the chart omits `spec.replicas` from the workload AND does NOT
331
# render its own HorizontalPodAutoscaler. Use this when an external controller
332
# (e.g. KEDA, a hand-written HPA, or another scaler) owns replicas for the Alloy
333
# workload. Mutually exclusive with `horizontal.enabled`. When set, all other
334
# `controller.autoscaling.horizontal.*` fields are ignored.
335
#
336
# Upgrade note: switching this from `false` to `true` on an existing release
337
# triggers a one-time single-cycle dip to 1 replica on the next `helm upgrade`
338
# (Helm removes the `replicas` field via `{"spec":{"replicas":null}}`, which
339
# Kubernetes interprets as "reset to default"). The external HPA corrects this
340
# within its next polling interval; users with `minReplicaCount > 1` are
341
# restored within ~30s under KEDA defaults. Plan upgrades accordingly.
342
externalHPA: false
343
# -- The lower limit for the number of replicas to which the autoscaler can scale down.
344
minReplicas: 1
345
# -- The upper limit for the number of replicas to which the autoscaler can scale up.
346
maxReplicas: 5
347
# -- Average CPU utilization across all relevant pods, a percentage of the requested value of the resource for the pods. Setting `targetCPUUtilizationPercentage` to 0 will disable CPU scaling.
348
targetCPUUtilizationPercentage: 0
349
# -- Average Memory utilization across all relevant pods, a percentage of the requested value of the resource for the pods. Setting `targetMemoryUtilizationPercentage` to 0 will disable Memory scaling.
350
targetMemoryUtilizationPercentage: 80
351
scaleDown:
352
# -- List of policies to determine the scale-down behavior.
353
policies: []
354
# - type: Pods
355
# value: 4
356
# periodSeconds: 60
357
# -- Determines which of the provided scaling-down policies to apply if multiple are specified.
358
selectPolicy: Max
359
# -- The duration that the autoscaling mechanism should look back on to make decisions about scaling down.
360
stabilizationWindowSeconds: 300
361
scaleUp:
362
# -- List of policies to determine the scale-up behavior.
363
policies: []
364
# - type: Pods
365
# value: 4
366
# periodSeconds: 60
367
# -- Determines which of the provided scaling-up policies to apply if multiple are specified.
368
selectPolicy: Max
369
# -- The duration that the autoscaling mechanism should look back on to make decisions about scaling up.
370
stabilizationWindowSeconds: 0
371
# -- Configures the Vertical Pod Autoscaler for the controller.
372
vertical:
373
# -- Enables the Vertical Pod Autoscaler for the controller.
374
enabled: false
375
# -- List of recommenders to use for the Vertical Pod Autoscaler.
376
# Recommenders are responsible for generating recommendation for the object.
377
# List should be empty (then the default recommender will generate the recommendation)
378
# or contain exactly one recommender.
379
recommenders: []
380
# recommenders:
381
# - name: custom-recommender-performance
382
383
# -- Configures the resource policy for the Vertical Pod Autoscaler.
384
resourcePolicy:
385
# -- Configures the container policies for the Vertical Pod Autoscaler.
386
containerPolicies:
387
- containerName: alloy
388
# -- The controlled resources for the Vertical Pod Autoscaler.
389
controlledResources:
390
- cpu
391
- memory
392
# -- The controlled values for the Vertical Pod Autoscaler. Needs to be either RequestsOnly or RequestsAndLimits.
393
controlledValues: "RequestsAndLimits"
394
# -- The maximum allowed values for the pods.
395
maxAllowed: {}
396
# cpu: 200m
397
# memory: 100Mi
398
# -- Defines the min allowed resources for the pod
399
minAllowed: {}
400
# cpu: 200m
401
# memory: 100Mi
402
# -- Configures the update policy for the Vertical Pod Autoscaler.
403
updatePolicy:
404
# -- Specifies minimal number of replicas which need to be alive for VPA Updater to attempt pod eviction
405
# minReplicas: 1
406
# -- Specifies whether recommended updates are applied when a Pod is started and whether recommended updates
407
# are applied during the life of a Pod. Possible values are "Off", "Initial", "Recreate", and "Auto".
408
# updateMode: Auto
409
# -- Affinity configuration for pods.
410
affinity: {}
411
volumes:
412
# -- Extra volumes to add to the Grafana Alloy pod.
413
extra: []
414
# -- volumeClaimTemplates to add when controller.type is 'statefulset'.
415
volumeClaimTemplates: []
416
## -- Additional init containers to run.
417
## ref: https://kubernetes.io/docs/concepts/workloads/pods/init-containers/
418
##
419
initContainers: []
420
# -- Additional containers to run alongside the Alloy container and initContainers.
421
extraContainers: []
422
networkPolicy:
423
enabled: false
424
flavor: kubernetes
425
policyTypes:
426
- Ingress
427
- Egress
428
# Default allow all traffic because Alloy is so configurable
429
# It is recommended to change this before deploying to production
430
# To disable each policyType, set value to `null`
431
ingress:
432
- {}
433
egress:
434
- {}
435
service:
436
# -- Creates a Service for the controller's pods.
437
enabled: true
438
# -- Service type
439
type: ClusterIP
440
# -- NodePort port. Only takes effect when `service.type: NodePort`
441
nodePort: 31128
442
# -- Cluster IP, can be set to None, empty "" or an IP address
443
clusterIP: ''
444
# -- Value for internal traffic policy. 'Cluster' or 'Local'
445
internalTrafficPolicy: Cluster
446
# -- Value for external traffic policy. 'Cluster' or 'Local'
447
externalTrafficPolicy: Cluster
448
# -- Value for traffic distribution. 'PreferSameNode' or 'PreferSameZone' (k8s >= 1.34)
449
trafficDistribution: ""
450
annotations: {}
451
# cloud.google.com/load-balancer-type: Internal
452
serviceMonitor:
453
enabled: false
454
# -- Additional labels for the service monitor.
455
additionalLabels: {}
456
# -- Scrape interval. If not set, the Prometheus default scrape interval is used.
457
interval: ""
458
# -- MetricRelabelConfigs to apply to samples after scraping, but before ingestion.
459
# ref: https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#relabelconfig
460
metricRelabelings: []
461
# - action: keep
462
# regex: 'kube_(daemonset|deployment|pod|namespace|node|statefulset).+'
463
# sourceLabels: [__name__]
464
465
# -- Customize tls parameters for the service monitor
466
tlsConfig: {}
467
# -- RelabelConfigs to apply to samples before scraping
468
# ref: https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#relabelconfig
469
relabelings: []
470
# - sourceLabels: [__meta_kubernetes_pod_node_name]
471
# separator: ;
472
# regex: ^(.*)$
473
# targetLabel: nodename
474
# replacement: $1
475
# action: replace
476
ingress:
477
# -- Enables ingress for Alloy (Faro port)
478
enabled: false
479
# For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName
480
# See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress
481
# ingressClassName: nginx
482
# Values can be templated
483
annotations: {}
484
# kubernetes.io/ingress.class: nginx
485
# kubernetes.io/tls-acme: "true"
486
labels: {}
487
path: /
488
faroPort: 12347
489
# pathType is only for k8s >= 1.1=
490
pathType: Prefix
491
hosts:
492
- chart-example.local
493
## Extra paths to prepend to every host configuration. This is useful when working with annotation based services.
494
extraPaths: []
495
# - path: /*
496
# backend:
497
# serviceName: ssl-redirect
498
# servicePort: use-annotation
499
## Or for k8s > 1.19
500
# - path: /*
501
# pathType: Prefix
502
# backend:
503
# service:
504
# name: ssl-redirect
505
# port:
506
# name: use-annotation
507
508
tls: []
509
# - secretName: chart-example-tls
510
# hosts:
511
# - chart-example.local
512
# -- Extra k8s manifests to deploy
513
extraObjects: []
514
# - apiVersion: v1
515
# kind: Secret
516
# metadata:
517
# name: grafana-cloud
518
# stringData:
519
# PROMETHEUS_HOST: 'https://prometheus-us-central1.grafana.net/api/prom/push'
520
# PROMETHEUS_USERNAME: '123456'
521

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.