DirectorySecurity AdvisoriesPricing
Sign in
Directory
apisix logoHELM

apisix

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:
Compare:

1
#
2
# Licensed to the Apache Software Foundation (ASF) under one or more
3
# contributor license agreements. See the NOTICE file distributed with
4
# this work for additional information regarding copyright ownership.
5
# The ASF licenses this file to You under the Apache License, Version 2.0
6
# (the "License"); you may not use this file except in compliance with
7
# the License. You may obtain a copy of the License at
8
#
9
# http://www.apache.org/licenses/LICENSE-2.0
10
#
11
# Unless required by applicable law or agreed to in writing, software
12
# distributed under the License is distributed on an "AS IS" BASIS,
13
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14
# See the License for the specific language governing permissions and
15
# limitations under the License.
16
17
global:
18
# e.g.
19
# imagePullSecrets:
20
# - my-registry-secrets
21
# - other-registry-secrets
22
# -- Global Docker registry secret names as an array
23
imagePullSecrets: []
24
image:
25
# -- Apache APISIX image repository
26
repository: chainreg.biz/chainguard-private/apache-apisix
27
# -- Apache APISIX image pull policy
28
pullPolicy: IfNotPresent
29
# -- Apache APISIX image tag
30
# Overrides the image tag whose default is the chart appVersion.
31
tag: 3.19.0-r1@sha256:4ffc3c314e15e13c1e6cfe5f30cf6e4b9ea118460af9d65294c16599bf87cccd
32
# -- set false to use `Deployment`, set true to use `DaemonSet`
33
useDaemonSet: false
34
# -- if useDaemonSet is true or autoscaling.enabled is true, replicaCount not become effective
35
replicaCount: 1
36
# -- Set [priorityClassName](https://kubernetes.io/docs/concepts/scheduling-eviction/pod-priority-preemption/#pod-priority) for Apache APISIX pods
37
priorityClassName: ""
38
# -- Annotations to add to each pod
39
podAnnotations: {}
40
# -- Labels to add to each pod
41
podLabels: {}
42
# -- Set the securityContext for Apache APISIX pods
43
podSecurityContext: {}
44
# fsGroup: 2000
45
# -- Number of seconds Kubernetes waits for Apache APISIX to terminate gracefully
46
terminationGracePeriodSeconds: 30
47
# -- Set the securityContext for Apache APISIX container
48
securityContext: {}
49
# capabilities:
50
# drop:
51
# - ALL
52
# readOnlyRootFilesystem: true
53
# runAsNonRoot: true
54
# runAsUser: 1000
55
56
# -- Lifecycle hooks for the Apache APISIX container
57
lifecycle:
58
preStop:
59
exec:
60
command:
61
- /bin/sh
62
- -c
63
- "sleep 30"
64
# -- See https://kubernetes.io/docs/tasks/run-application/configure-pdb/ for more details
65
podDisruptionBudget:
66
# -- Enable or disable podDisruptionBudget
67
enabled: false
68
# -- Set the `minAvailable` of podDisruptionBudget. You can specify only one of `maxUnavailable` and `minAvailable` in a single PodDisruptionBudget.
69
# See [Specifying a Disruption Budget for your Application](https://kubernetes.io/docs/tasks/run-application/configure-pdb/#specifying-a-poddisruptionbudget)
70
# for more details
71
minAvailable: 90%
72
# -- Set the maxUnavailable of podDisruptionBudget
73
maxUnavailable: 1
74
# -- Set pod resource requests & limits
75
resources: {}
76
# We usually recommend not to specify default resources and to leave this as a conscious
77
# choice for the user. This also increases chances charts run on environments with little
78
# resources, such as Minikube. If you do want to specify resources, uncomment the following
79
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
80
# limits:
81
# cpu: 100m
82
# memory: 128Mi
83
# requests:
84
# cpu: 100m
85
# memory: 128Mi
86
87
# -- Use the host's network namespace
88
hostNetwork: false
89
# -- Node labels for Apache APISIX pod assignment
90
nodeSelector: {}
91
# -- List of node taints to tolerate
92
tolerations: []
93
# -- Set affinity for Apache APISIX deploy
94
affinity: {}
95
# -- Topology Spread Constraints for pod assignment spread across your cluster among failure-domains
96
# ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/#spread-constraints-for-pods
97
topologySpreadConstraints: []
98
# -- timezone is the timezone where apisix uses.
99
# For example: "UTC" or "Asia/Shanghai"
100
# This value will be set on apisix container's environment variable TZ.
101
# You may need to set the timezone to be consistent with your local time zone,
102
# otherwise the apisix's logs may used to retrieve event maybe in wrong timezone.
103
timezone: ""
104
# -- extraEnvVars An array to add extra env vars
105
# e.g:
106
# extraEnvVars:
107
# - name: FOO
108
# value: "bar"
109
# - name: FOO2
110
# valueFrom:
111
# secretKeyRef:
112
# name: SECRET_NAME
113
# key: KEY
114
extraEnvVars: []
115
# -- Update strategy of the workload (Deployment or DaemonSet), e.g. `type: RollingUpdate`
116
updateStrategy: {}
117
# type: RollingUpdate
118
119
# -- Additional Kubernetes resources to deploy with the release.
120
extraDeploy: []
121
# -- Additional `volume`, See [Kubernetes Volumes](https://kubernetes.io/docs/concepts/storage/volumes/) for the detail.
122
extraVolumes: []
123
# - name: extras
124
# emptyDir: {}
125
126
# -- Additional `volumeMounts` for the APISIX container, See [Kubernetes Volumes](https://kubernetes.io/docs/concepts/storage/volumes/) for the detail.
127
extraVolumeMounts: []
128
# - name: extras
129
# mountPath: /usr/share/extras
130
# readOnly: true
131
132
# -- Additional `initContainers`, See [Kubernetes initContainers](https://kubernetes.io/docs/concepts/workloads/pods/init-containers/) for the detail.
133
extraInitContainers: []
134
# - name: init-myservice
135
# image: busybox:1.28
136
# command: ['sh', '-c', "until nslookup myservice.$(cat /var/run/secrets/kubernetes.io/serviceaccount/namespace).svc.cluster.local; do echo waiting for myservice; sleep 2; done"]
137
138
# -- Additional `containers`, See [Kubernetes containers](https://kubernetes.io/docs/concepts/containers/) for the detail.
139
extraContainers: []
140
initContainer:
141
# -- Init container image
142
image: chainreg.biz/chainguard-private/netcat
143
# -- Init container tag
144
tag: 1.238-r1@sha256:b961470bd7a9a1ece5f8bf51b2accd244cebc7a83767ab08da80821e403eb140
145
autoscaling:
146
# -- Enable HorizontalPodAutoscaler for APISIX (only when useDaemonSet is false)
147
enabled: false
148
# -- HPA version, the value is "v2" or "v2beta1", default "v2"
149
version: v2
150
# -- Minimum number of APISIX replicas
151
minReplicas: 1
152
# -- Maximum number of APISIX replicas
153
maxReplicas: 100
154
# -- Target average CPU utilization percentage that triggers scaling
155
targetCPUUtilizationPercentage: 80
156
# -- Target average memory utilization percentage that triggers scaling
157
targetMemoryUtilizationPercentage: 80
158
# -- String to partially override the chart fullname
159
nameOverride: ""
160
# -- String to fully override the chart fullname
161
fullnameOverride: ""
162
serviceAccount:
163
# -- Whether a ServiceAccount should be created for the APISIX pods
164
create: false
165
# -- Annotations to add to the ServiceAccount
166
annotations: {}
167
# -- Name of the ServiceAccount to use. If not set and create is true, a name is generated from the chart fullname
168
name: ""
169
rbac:
170
# -- Whether RBAC resources (ClusterRole and ClusterRoleBinding) should be created
171
create: false
172
service:
173
# -- Apache APISIX service type for user access itself
174
type: NodePort
175
# -- Setting how the Service route external traffic.
176
# If you want to keep the client source IP, you can set this to Local,
177
# ref: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip
178
externalTrafficPolicy: Cluster
179
# type: LoadBalancer
180
# annotations:
181
# service.beta.kubernetes.io/aws-load-balancer-type: nlb
182
# -- IPs for which nodes in the cluster will also accept traffic for the service
183
externalIPs: []
184
# -- Apache APISIX service settings for http
185
http:
186
# -- Enable plain HTTP listeners
187
enabled: true
188
# -- Kubernetes service port for HTTP traffic
189
servicePort: 80
190
# -- Container port APISIX listens on for HTTP traffic
191
containerPort: 9080
192
# -- (number) Bind the APISIX HTTP container port to a host port.
193
hostPort:
194
# -- Support multiple http ports, See [Configuration](https://github.com/apache/apisix/blob/0bc65ea9acd726f79f80ae0abd8f50b7eb172e3d/conf/config-default.yaml#L24)
195
additionalContainerPorts: []
196
# - port: 9081
197
# enable_http2: true # If not set, the default value is `false`.
198
# - ip: 127.0.0.2 # Specific IP, If not set, the default value is `0.0.0.0`.
199
# port: 9082
200
# enable_http2: true
201
# -- Apache APISIX service settings for tls
202
tls:
203
# -- Kubernetes service port for HTTPS traffic
204
servicePort: 443
205
# nodePort: 4443
206
# -- Apache APISIX service settings for stream. L4 proxy (TCP/UDP)
207
stream:
208
# -- Enable the stream (L4 proxy) subsystem
209
enabled: false
210
# -- TCP proxy port list, element format: port number, or a map with `addr` and optional `tls` / `tls_passthrough`
211
tcp: []
212
# -- UDP proxy port list
213
udp: []
214
# - secretName: apisix-tls
215
# hosts:
216
# - chart-example.local
217
# -- Override default labels assigned to Apache APISIX gateway resources
218
labelsOverride: {}
219
# labelsOverride:
220
# app.kubernetes.io/name: "{{ .Release.Name }}"
221
# app.kubernetes.io/instance: '{{ include "apisix.name" . }}'
222
# -- Using ingress access Apache APISIX service
223
ingress:
224
# -- Enable an Ingress resource in front of the APISIX service
225
enabled: false
226
# -- (number) Service port to send traffic. Defaults to `service.http.servicePort`.
227
servicePort:
228
# -- Ingress annotations
229
annotations: {}
230
# kubernetes.io/ingress.class: nginx
231
# kubernetes.io/tls-acme: "true"
232
# -- Ingress host and path rules
233
hosts:
234
- host: apisix.local
235
paths: []
236
# -- Ingress TLS settings
237
tls: []
238
control:
239
# -- Enable Control API
240
enabled: true
241
service:
242
# -- Control annotations
243
annotations: {}
244
# -- Control service type
245
type: ClusterIP
246
# loadBalancerIP: a.b.c.d
247
# loadBalancerSourceRanges:
248
# - "143.231.0.0/16"
249
# -- IPs for which nodes in the cluster will also accept traffic for the servic
250
externalIPs: []
251
# -- NodePort (only if control.service.type is NodePort)
252
# nodePort: 32000
253
254
# -- which ip to listen on for Apache APISIX Control API
255
ip: "127.0.0.1"
256
# -- which port to use for Apache APISIX Control API
257
port: 9090
258
# -- Service port to use for Apache APISIX Control API
259
servicePort: 9090
260
# -- Using ingress access Apache APISIX Control service
261
ingress:
262
# -- Enable an Ingress resource in front of the Control API service
263
enabled: false
264
# -- Ingress annotations
265
annotations: {}
266
# kubernetes.io/ingress.class: nginx
267
# kubernetes.io/tls-acme: "true"
268
# -- Ingress Class Name
269
# className: "nginx"
270
# -- Ingress host and path rules
271
hosts:
272
- host: apisix-control.local
273
paths:
274
- "/*"
275
# -- Ingress TLS settings
276
tls: []
277
# - secretName: apisix-tls
278
# hosts:
279
# - chart-example.local
280
# -- Observability configuration.
281
metrics:
282
serviceMonitor:
283
# -- Enable or disable Apache APISIX serviceMonitor
284
enabled: false
285
# -- namespace where the serviceMonitor is deployed, by default, it is the same as the namespace of the apisix
286
namespace: ""
287
# -- name of the serviceMonitor, by default, it is the same as the apisix fullname
288
name: ""
289
# -- interval at which metrics should be scraped
290
interval: 15s
291
# -- @param serviceMonitor.labels ServiceMonitor extra labels
292
labels: {}
293
# -- @param serviceMonitor.annotations ServiceMonitor annotations
294
annotations: {}
295
apisix:
296
# -- Enable nginx IPv6 resolver
297
enableIPv6: true
298
# -- Enable HTTP/2 on the HTTP listeners
299
enableHTTP2: true
300
# -- Whether the APISIX version number should be shown in Server header
301
enableServerTokens: true
302
# -- When true, the upstream status is always written to the `X-APISIX-Upstream-Status` response header; when false, it is written only for 5xx responses
303
showUpstreamStatusInResponseHeader: false
304
# -- PROXY Protocol configuration.
305
proxyProtocol:
306
# -- (int) The HTTP port that accepts the PROXY Protocol. It differs from `service.http` ports and `apisix.admin` port:
307
# this port only accepts HTTP requests carrying the PROXY Protocol, while the other ports only accept plain HTTP
308
# requests. If you enable the PROXY Protocol, you must use this port to receive HTTP requests with it.
309
# When set, the port is also exposed on the gateway Service.
310
listenHttpPort:
311
# -- (int) The nodePort of the PROXY Protocol HTTP port, only used if service.type is NodePort.
312
# If not set, a random port will be assigned by Kubernetes.
313
listenHttpNodePort:
314
# -- (int) The HTTPS port that accepts the PROXY Protocol.
315
# When set, the port is also exposed on the gateway Service.
316
listenHttpsPort:
317
# -- (int) The nodePort of the PROXY Protocol HTTPS port, only used if service.type is NodePort.
318
# If not set, a random port will be assigned by Kubernetes.
319
listenHttpsNodePort:
320
# -- Accept the PROXY Protocol on every service.stream.tcp port.
321
enableTcpPP: false
322
# -- Send the PROXY Protocol to the upstream server on every service.stream.tcp port.
323
enableTcpPPToUpstream: false
324
# -- Proxy caching configuration used by the proxy-cache plugin.
325
proxyCache:
326
# -- The default caching time in disk if the upstream does not specify the cache time
327
cacheTtl: 10s
328
# -- The parameters of a cache. The `memory_size` field stores the cache index for the
329
# disk strategy and the cache content for the memory strategy; `disk_size`, `disk_path`
330
# and `cache_levels` only apply to the disk strategy.
331
zones:
332
- name: disk_cache_one
333
memory_size: 50m
334
disk_size: 1G
335
disk_path: "/tmp/disk_cache_one"
336
cache_levels: "1:2"
337
- name: memory_cache
338
memory_size: 50m
339
graphql:
340
# -- The maximum size in bytes of GraphQL queries APISIX parses when matching routes by GraphQL attributes (default 1MiB)
341
maxSize: 1048576
342
# -- Delete the '/' at the end of the URI
343
deleteURITailSlash: false
344
# -- The URI normalization in servlet is a little different from the RFC's.
345
# See https://github.com/jakartaee/servlet/blob/master/spec/src/main/asciidoc/servlet-spec-body.adoc#352-uri-path-canonicalization,
346
# which is used under Tomcat.
347
# Turn this option on if you want to be compatible with servlet when matching URI path.
348
normalizeURILikeServlet: false
349
# -- fine tune the parameters of LRU cache for some features like secret
350
lru:
351
secret:
352
# -- TTL in seconds for cached secret values
353
ttl: 300
354
# -- Maximum number of cached secret values
355
count: 512
356
# -- TTL in seconds for cached negative (failed lookup) results
357
neg_ttl: 60
358
# -- Maximum number of cached negative (failed lookup) results
359
neg_count: 512
360
# -- Enable comprehensive request lifecycle tracing (SSL/SNI, rewrite, access, header_filter, body_filter, and log).
361
# When disabled, OpenTelemetry collects only a single span per request.
362
tracing: false
363
# -- Use Pod metadata.uid as the APISIX id.
364
setIDFromPodUID: false
365
# -- Whether to add a custom lua module
366
luaModuleHook:
367
# -- Enable loading a custom lua module hook
368
enabled: false
369
# -- extend lua_package_path to load third party code
370
luaPath: ""
371
# -- the hook module which will be used to inject third party code into APISIX
372
# use the lua require style like: "module.say_hello"
373
hookPoint: ""
374
# -- configmap that stores the codes
375
configMapRef:
376
# -- Name of the ConfigMap where the lua module codes store
377
name: ""
378
# mounts decides how to mount the codes to the container.
379
mounts:
380
# -- Name of the ConfigMap key, for setting the mapping relationship between ConfigMap key and the lua module code path.
381
- key: ""
382
# -- Filepath of the plugin code, for setting the mapping relationship between ConfigMap key and the lua module code path.
383
path: ""
384
ssl:
385
# -- Enable HTTPS listeners
386
enabled: false
387
# -- Container port APISIX listens on for HTTPS traffic
388
containerPort: 9443
389
# -- (number) Bind the APISIX HTTPS container port to a host port.
390
hostPort:
391
# -- Support multiple https ports, See [Configuration](https://github.com/apache/apisix/blob/0bc65ea9acd726f79f80ae0abd8f50b7eb172e3d/conf/config-default.yaml#L99)
392
additionalContainerPorts: []
393
# - ip: 127.0.0.3 # Specific IP, If not set, the default value is `0.0.0.0`.
394
# port: 9445
395
# enable_http3: true
396
# -- Specifies the name of Secret contains trusted CA certificates in the PEM format used to verify the certificate when APISIX needs to do SSL/TLS handshaking with external services (e.g. etcd)
397
existingCASecret: ""
398
# -- Filename be used in the apisix.ssl.existingCASecret
399
certCAFilename: ""
400
# -- Enable HTTP/3 (QUIC) on the HTTPS listeners
401
enableHTTP3: false
402
# -- TLS protocols allowed to use.
403
sslProtocols: "TLSv1.2 TLSv1.3"
404
# -- TLS ciphers allowed to use.
405
sslCiphers: "ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-SHA256:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA"
406
# -- Enable or disable TLS session tickets. Disabled by default because session tickets
407
# defeat Perfect Forward Secrecy (see https://github.com/mozilla/server-side-tls/issues/135)
408
sslSessionTickets: false
409
# -- Define SNI to fallback if none is presented by client
410
fallbackSNI: ""
411
router:
412
# -- Defines how apisix handles routing:
413
# - radixtree_uri: match route by uri(base on radixtree)
414
# - radixtree_host_uri: match route by host + uri(base on radixtree)
415
# - radixtree_uri_with_parameter: match route by uri with parameters
416
http: radixtree_host_uri
417
fullCustomConfig:
418
# -- Enable full customized config.yaml
419
enabled: false
420
# -- If apisix.fullCustomConfig.enabled is true, full customized config.yaml.
421
# Please note that other settings about APISIX config will be ignored
422
config: {}
423
deployment:
424
# -- Apache APISIX deployment mode
425
# Optional: traditional, decoupled, standalone
426
#
427
# ref: https://apisix.apache.org/docs/apisix/deployment-modes/
428
mode: traditional
429
# -- Deployment role
430
# Optional: traditional, data_plane, control_plane
431
#
432
# ref: https://apisix.apache.org/docs/apisix/deployment-modes/
433
role: "traditional"
434
role_traditional:
435
# -- Config provider for the traditional role. enum: etcd, yaml
436
config_provider: "etcd"
437
# -- Standalone rules configuration
438
#
439
# ref: https://apisix.apache.org/docs/apisix/deployment-modes/#standalone
440
standalone:
441
# -- Rules which are set to the default apisix.yaml configmap.
442
# If apisix.delpoyment.standalone.existingConfigMap is empty, these are used.
443
config: |
444
routes:
445
-
446
uri: /hi
447
upstream:
448
nodes:
449
"127.0.0.1:1980": 1
450
type: roundrobin
451
# -- Specifies the name of the ConfigMap that contains the rule configurations.
452
# The configuration must be set to the key named `apisix.yaml` in the configmap.
453
existingConfigMap: ""
454
admin:
455
# -- Enable Admin API
456
enabled: true
457
# -- Enable Embedded Admin UI
458
enable_admin_ui: true
459
# -- admin service type
460
type: ClusterIP
461
# loadBalancerIP: a.b.c.d
462
# loadBalancerSourceRanges:
463
# - "143.231.0.0/16"
464
# -- IPs for which nodes in the cluster will also accept traffic for the servic
465
externalIPs: []
466
# -- which ip to listen on for Apache APISIX admin API. Set to `"[::]"` when on IPv6 single stack
467
ip: 0.0.0.0
468
# -- which port to use for Apache APISIX admin API
469
port: 9180
470
# -- Service port to use for Apache APISIX admin API
471
servicePort: 9180
472
# -- Admin API support CORS response headers
473
cors: true
474
# -- Admin API credentials
475
credentials:
476
# -- Apache APISIX admin API admin role credentials
477
admin: edd1c9f034335f136f87ad84b625c8f1
478
# -- Apache APISIX admin API viewer role credentials
479
viewer: 4054f7cf07e344346cd3f287985e76a2
480
# -- The APISIX Helm chart supports storing user credentials in a secret.
481
# The secret needs to contain two keys, admin and viewer, with their respective values set.
482
secretName: ""
483
# -- Name of the admin role key in the secret, overrides the default key name "admin"
484
secretAdminKey: ""
485
# -- Name of the viewer role key in the secret, overrides the default key name "viewer"
486
secretViewerKey: ""
487
allow:
488
# -- The client IP CIDR allowed to access Apache APISIX Admin API service.
489
ipList:
490
- 127.0.0.1/24
491
# -- Using ingress access Apache APISIX admin service
492
ingress:
493
# -- Enable an Ingress resource in front of the Admin API service
494
enabled: false
495
# -- Ingress annotations
496
annotations: {}
497
# kubernetes.io/ingress.class: nginx
498
# kubernetes.io/tls-acme: "true"
499
# -- Ingress host and path rules
500
hosts:
501
- host: apisix-admin.local
502
paths:
503
- "/apisix"
504
# -- Ingress TLS settings
505
tls: []
506
# - secretName: apisix-tls
507
# hosts:
508
# - chart-example.local
509
nginx:
510
# -- The number of files a worker process can open, should be larger than apisix.nginx.workerConnections
511
workerRlimitNofile: "20480"
512
# -- The maximum number of connections that each worker process can open
513
workerConnections: "10620"
514
# -- The number of nginx worker processes. `auto` means the number of CPU cores
515
workerProcesses: auto
516
# -- Bind nginx worker processes to CPUs
517
enableCPUAffinity: true
518
# -- Timeout for a graceful shutdown of worker processes
519
workerShutdownTimeout: "240s"
520
# -- Maximum number of pending timers. Increase it if you see "too many pending timers" error
521
maxPendingTimers: 16384
522
# -- Maximum number of running timers. Increase it if you see "lua_max_running_timers are not enough" error
523
maxRunningTimers: 4096
524
# -- Timeout during which a keep-alive client connection will stay open on the server side.
525
keepaliveTimeout: 60s
526
# -- List of environment variable names allowed to be accessed within nginx (rendered as nginx `env` directives)
527
envs: []
528
# -- Nginx HTTP subsystem configurations
529
http:
530
# -- timeout for reading client request header, then 408 (Request Time-out) error is returned to the client
531
clientHeaderTimeout: "60s"
532
# -- timeout for reading client request body, then 408 (Request Time-out) error is returned to the client
533
clientBodyTimeout: "60s"
534
# -- timeout for transmitting a response to the client, then the connection is closed
535
sendTimeout: "10s"
536
# -- The maximum allowed size of the client request body.
537
# If exceeded, the 413 (Request Entity Too Large) error is returned to the client.
538
# Note that unlike Nginx, we don't limit the body size by default (0 means no limit).
539
clientMaxBodySize: 0
540
# -- Enable the use of underscores in client request header fields
541
underscoresInHeaders: "on"
542
# -- The request header used to determine the client's real IP address,
543
# see [real_ip_header](http://nginx.org/en/docs/http/ngx_http_realip_module.html#real_ip_header)
544
realIpHeader: "X-Real-IP"
545
# -- Whether to search for the real IP recursively when the header set in apisix.nginx.http.realIpHeader contains multiple addresses,
546
# see [real_ip_recursive](http://nginx.org/en/docs/http/ngx_http_realip_module.html#real_ip_recursive)
547
realIpRecursive: "off"
548
# -- Trusted addresses from which the real IP header is honored,
549
# see [set_real_ip_from](http://nginx.org/en/docs/http/ngx_http_realip_module.html#set_real_ip_from)
550
realIpFrom:
551
- 127.0.0.1
552
- "unix:"
553
# -- Enables or disables passing of the server name through TLS Server Name Indication extension (SNI, RFC 6066)
554
# when establishing a connection with the proxied HTTPS server
555
proxySslServerName: true
556
# -- Keepalive settings for connections from APISIX to upstream servers
557
upstream:
558
# -- Maximum number of idle keepalive connections to upstream servers that are preserved in the cache of each worker process.
559
# When this number is exceeded, the least recently used connections are closed
560
keepalive: 320
561
# -- Maximum number of requests that can be served through one keepalive connection.
562
# After the maximum number of requests is made, the connection is closed
563
keepaliveRequests: 1000
564
# -- Timeout during which an idle keepalive connection to an upstream server will stay open
565
keepaliveTimeout: 60s
566
# -- The charset added to the "Content-Type" response header field,
567
# see [charset](http://nginx.org/en/docs/http/ngx_http_charset_module.html#charset)
568
charset: utf-8
569
# -- The maximum size of the nginx variables hash table
570
variablesHashMaxSize: 2048
571
# access log and error log configuration
572
logs:
573
# -- Enable access log or not, default true
574
enableAccessLog: true
575
# -- Access log path
576
accessLog: "/dev/stdout"
577
# -- Access log format
578
accessLogFormat: '$remote_addr - $remote_user [$time_local] $http_host \"$request\" $status $body_bytes_sent $request_time \"$http_referer\" \"$http_user_agent\" $upstream_addr $upstream_status $upstream_response_time \"$upstream_scheme://$upstream_host$upstream_uri\"'
579
# -- Allows setting json or default characters escaping in variables
580
accessLogFormatEscape: default
581
# -- Error log path
582
errorLog: "/dev/stderr"
583
# -- Error log level
584
errorLogLevel: "warn"
585
# -- Stream (L4 proxy) access log configuration
586
stream:
587
# -- Enable stream access log or not, default false
588
enableAccessLog: false
589
# -- Stream access log path
590
accessLog: "logs/access_stream.log"
591
# -- Stream access log format
592
accessLogFormat: '$remote_addr [$time_local] $protocol $status $bytes_sent $bytes_received $session_time'
593
# -- Allows setting json or default characters escaping in variables for stream
594
accessLogFormatEscape: default
595
# -- Custom nginx configuration snippets injected into the generated nginx.conf.
596
# As arbitrary configuration can be added here, it is your responsibility to make sure
597
# the snippets don't conflict with the configuration generated by APISIX.
598
configurationSnippet:
599
# -- Snippet added to the nginx `main` (top-level) block
600
main: ""
601
# -- Snippet added to the beginning of the nginx `http` block
602
httpStart: ""
603
# -- Snippet added to the end of the nginx `http` block
604
httpEnd: ""
605
# -- Snippet added to the nginx `server` block that proxies regular traffic
606
httpSrv: ""
607
# -- Snippet added to the nginx `server` block that serves the Admin API
608
httpAdmin: ""
609
# -- Snippet added to the nginx `stream` block
610
stream: ""
611
# -- Add custom [lua_shared_dict](https://github.com/openresty/lua-nginx-module?tab=readme-ov-file#lua_shared_dict) settings,
612
# click [here](https://github.com/apache/apisix-helm-chart/blob/master/charts/apisix/values.yaml#L27-L30) to learn the format of a shared dict
613
customLuaSharedDicts: []
614
# - name: foo
615
# size: 10k
616
# - name: bar
617
# size: 1m
618
619
# -- Override default [lua_shared_dict](https://github.com/apache/apisix/blob/master/conf/config.yaml.example#L250-L276) settings,
620
# click [here](https://github.com/apache/apisix-helm-chart/blob/master/charts/apisix/values.yaml#L27-L30) to learn the format of a shared dict
621
luaSharedDicts: []
622
# - name: prometheus-metrics
623
# size: 20m
624
625
# -- Override default meta-level [lua_shared_dict](https://github.com/apache/apisix/blob/master/conf/config.yaml.example) settings,
626
# meta-level shared dicts are shared across both HTTP and stream subsystems.
627
# Since APISIX 3.16.0, `upstream-healthcheck` is a meta-level shared dict.
628
# click [here](https://github.com/apache/apisix-helm-chart/blob/master/charts/apisix/values.yaml#L27-L30) to learn the format of a shared dict
629
metaLuaSharedDicts: []
630
# - name: upstream-healthcheck
631
# size: 10m
632
discovery:
633
# -- Enable or disable Apache APISIX integration service discovery
634
enabled: false
635
# -- Service discovery registry. Refer to [configuration under discovery](https://github.com/apache/apisix/blob/master/conf/config.yaml.example#L307) for example.
636
# Also see [example of using external service discovery](https://apisix.apache.org/docs/ingress-controller/1.8.0/tutorials/external-service-discovery/).
637
registry: {}
638
# Integration service discovery registry. E.g eureka\dns\nacos\consul_kv
639
# reference:
640
# https://apisix.apache.org/docs/apisix/discovery/#configuration-for-eureka
641
# https://apisix.apache.org/docs/apisix/discovery/dns/#service-discovery-via-dns
642
# https://apisix.apache.org/docs/apisix/discovery/consul_kv/#configuration-for-consul-kv
643
# https://apisix.apache.org/docs/apisix/discovery/nacos/#configuration-for-nacos
644
# https://apisix.apache.org/docs/apisix/discovery/kubernetes/#configuration
645
#
646
# an eureka example:
647
# ```
648
# eureka:
649
# host:
650
# - "http://${username}:${password}@${eureka_host1}:${eureka_port1}"
651
# - "http://${username}:${password}@${eureka_host2}:${eureka_port2}"
652
# prefix: "/eureka/"
653
# fetch_interval: 30
654
# weight: 100
655
# timeout:
656
# connect: 2000
657
# send: 2000
658
# read: 5000
659
# ```
660
#
661
# the minimal Kubernetes example:
662
# ```
663
# kubernetes: {}
664
# ```
665
#
666
# The prerequisites for the above minimal Kubernetes example:
667
# 1. [Optional] Set `.serviceAccount.create` to `true` to create a dedicated ServiceAccount.
668
# It is recommended to do so, otherwise the default ServiceAccount "default" will be used.
669
# 2. [Required] Set `.rbac.create` to `true` to create and bind the necessary RBAC resources.
670
# This grants the ServiceAccount in use to List-Watch Kubernetes Endpoints resources.
671
# 3. [Required] Include the following environment variables in `.nginx.envs` to pass them into
672
# nginx worker processes (https://nginx.org/en/docs/ngx_core_module.html#env):
673
# - KUBERNETES_SERVICE_HOST
674
# - KUBERNETES_SERVICE_PORT
675
# This is for allowing the default `host` and `port` of `.discovery.registry.kubernetes.service`.
676
dns:
677
# -- Nameservers used by APISIX to resolve upstream domain names.
678
# When empty (default), nameservers are read from `/etc/resolv.conf`,
679
# which is usually what you want inside Kubernetes
680
resolvers: []
681
# - 127.0.0.1
682
# - 8.8.8.8
683
# -- Override the TTL in seconds of valid DNS records
684
validity: 30
685
# -- DNS resolver timeout in seconds
686
timeout: 5
687
# -- Honor the `search` option in `/etc/resolv.conf` when resolving domain names
688
enableResolvSearchOpt: true
689
vault:
690
# -- Enable or disable the vault integration
691
enabled: false
692
# -- The host address where the vault server is running.
693
host: ""
694
# -- HTTP timeout for each request.
695
timeout: 10
696
# -- The generated token from vault instance that can grant access to read data from the vault.
697
token: ""
698
# -- Prefix allows you to better enforcement of policies.
699
prefix: ""
700
prometheus:
701
# -- Enable Prometheus metrics. ref: https://apisix.apache.org/docs/apisix/plugins/prometheus/
702
enabled: false
703
# -- path of the metrics endpoint
704
path: /apisix/prometheus/metrics
705
# -- prefix of the metrics
706
metricPrefix: apisix_
707
# -- container port where the metrics are exposed
708
containerPort: 9091
709
# -- Customize the list of APISIX plugins to enable. By default, APISIX's [default plugins](https://github.com/apache/apisix/blob/master/apisix/cli/config.lua#L196) are automatically used.
710
plugins: []
711
# -- Customize the list of APISIX stream_plugins to enable. By default, APISIX's [default stream_plugins](https://github.com/apache/apisix/blob/master/apisix/cli/config.lua#L294) are automatically used.
712
stream_plugins: []
713
# -- Set APISIX plugin attributes. By default, APISIX's [plugin_attr](https://github.com/apache/apisix/blob/master/apisix/cli/config.lua#L295) are automatically used.
714
# See [configuration example](https://github.com/apache/apisix/blob/master/conf/config.yaml.example#L591).
715
pluginAttrs: {}
716
extPlugin:
717
# -- Enable External Plugins. See [external plugin](https://apisix.apache.org/docs/apisix/next/external-plugin/)
718
enabled: false
719
# -- the command and its arguements to run as a subprocess
720
cmd: ["/path/to/apisix-plugin-runner/runner", "run"]
721
wasm:
722
# -- Enable Wasm Plugins. See [wasm plugin](https://apisix.apache.org/docs/apisix/next/wasm/)
723
enabled: false
724
# -- List of Wasm plugins, each item with `name`, `priority` and `file` (path or URL of the wasm binary)
725
plugins: []
726
# -- customPlugins allows you to mount your own HTTP plugins.
727
customPlugins:
728
# -- Whether to configure some custom plugins
729
enabled: false
730
# -- the lua_path that tells APISIX where it can find plugins,
731
# note the last ';' is required.
732
luaPath: "/opts/custom_plugins/?.lua"
733
plugins:
734
# -- plugin name.
735
- name: "plugin-name"
736
# -- plugin attrs
737
attrs: {}
738
# -- plugin codes can be saved inside configmap object.
739
configMap:
740
# -- name of configmap.
741
name: "configmap-name"
742
# -- since keys in configmap is flat, mountPath allows to define the mount
743
# path, so that plugin codes can be mounted hierarchically.
744
mounts:
745
- key: "the-file-name"
746
path: "mount-path"
747
status:
748
# -- The IP address on which the status endpoint (`/status`, `/status/ready`) listens
749
ip: "0.0.0.0"
750
# -- The port on which the status endpoint listens
751
port: 7085
752
# -- When configured, APISIX will trust the `X-Forwarded-*` Headers passed in requests from the IP/CIDR in the list.
753
trustedAddresses:
754
- 127.0.0.1
755
# -- external etcd configuration. If etcd.enabled is false, these configuration will be used.
756
externalEtcd:
757
# -- if etcd.enabled is false, use external etcd, support multiple address, if your etcd cluster enables TLS, please use https scheme, e.g. https://127.0.0.1:2379.
758
host:
759
# host or ip e.g. http://172.20.128.89:2379
760
- http://etcd.host:2379
761
# -- if etcd.enabled is false, user for external etcd. Set empty to disable authentication
762
user: root
763
# -- if etcd.enabled is true, use etcd.auth.rbac.rootPassword instead.
764
# -- if etcd.enabled is false and externalEtcd.existingSecret is not empty, the password should store in the corresponding secret
765
# -- if etcd.enabled is false and externalEtcd.existingSecret is empty, externalEtcd.password is the passsword for external etcd.
766
password: ""
767
# -- if externalEtcd.existingSecret is the name of secret containing the external etcd password
768
existingSecret: ""
769
# -- externalEtcd.secretPasswordKey Key inside the secret containing the external etcd password
770
secretPasswordKey: "etcd-root-password"
771
# -- etcd configuration
772
# use the FQDN address or the IP of the etcd
773
etcd:
774
# -- install built-in etcd by default, set false if do not want to install built-in etcd together,
775
# this etcd is based on bitnamilegacy/etcd helm chart and latest bitnami docker image, only for development and testing purposes,
776
# if you want to use etcd in production, we recommend you to install etcd by yourself and use `externalEtcd` to connect it.
777
enabled: true
778
# -- docker image for built-in etcd
779
image:
780
registry: docker.io
781
repository: bitnamilegacy/etcd
782
# -- `bitnamilegacy/etcd` only provide `latest` tag now, ref: https://github.com/bitnami/containers/issues/83267,
783
# you can switch `etcd.image.repository` to `bitnamilegacy/etcd` to use old versioned tags.
784
tag: latest
785
# -- apisix configurations prefix
786
prefix: "/apisix"
787
# -- Set the timeout value in seconds for subsequent socket operations from apisix to etcd cluster
788
timeout: 30
789
# -- Set the timeout value in seconds for watching etcd
790
watchTimeout: 50
791
# -- The number of retries to etcd during startup
792
startupRetry: 2
793
# -- if etcd.enabled is true, set more values of bitnamilegacy/etcd helm chart
794
auth:
795
rbac:
796
# -- No authentication by default. Switch to enable RBAC authentication
797
create: false
798
# -- root password for etcd. Requires etcd.auth.rbac.create to be true.
799
rootPassword: ""
800
tls:
801
# -- enable etcd client certificate
802
enabled: false
803
# -- name of the secret contains etcd client cert
804
existingSecret: ""
805
# -- etcd client cert filename using in etcd.auth.tls.existingSecret
806
certFilename: ""
807
# -- etcd client cert key filename using in etcd.auth.tls.existingSecret
808
certKeyFilename: ""
809
# -- whether to verify the etcd endpoint certificate when setup a TLS connection to etcd
810
verify: true
811
# -- specify the TLS Server Name Indication extension, the ETCD endpoint hostname will be used when this setting is unset.
812
sni: ""
813
# -- ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container
814
# -- added for backward compatibility with old kubernetes versions, as seccompProfile is not supported in kubernetes < 1.19
815
containerSecurityContext:
816
enabled: false
817
service:
818
# -- etcd client service port
819
port: 2379
820
# -- Number of etcd replicas, only used when etcd.enabled is true
821
replicaCount: 3
822
# -- Auto compaction retention for mvcc key value store, only used when etcd.enabled is true
823
autoCompactionRetention: "1h"
824
# -- Auto compaction mode (periodic or revision), only used when etcd.enabled is true
825
autoCompactionMode: "periodic"
826
# -- Ingress controller configuration
827
ingress-controller:
828
# -- Enable the apisix-ingress-controller sub-chart
829
enabled: false
830
webhook:
831
# Specifies whether to enable the validation webhook.
832
# Note: This feature relies on the '/apisix/admin/configs/validate' endpoint.
833
# It requires APISIX version 3.17.0 or later to function correctly.
834
# Ensure your cluster's APISIX deployment meets this version requirement before enabling.
835
enabled: false
836

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.