2# Licensed to the Apache Software Foundation (ASF) under one or more
3# contributor license agreements. See the NOTICE file distributed with
4# this work for additional information regarding copyright ownership.
5# The ASF licenses this file to You under the Apache License, Version 2.0
6# (the "License"); you may not use this file except in compliance with
7# the License. You may obtain a copy of the License at
9# http://www.apache.org/licenses/LICENSE-2.0
11# Unless required by applicable law or agreed to in writing, software
12# distributed under the License is distributed on an "AS IS" BASIS,
13# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14# See the License for the specific language governing permissions and
15# limitations under the License.
20 # - my-registry-secrets
21 # - other-registry-secrets
22 # -- Global Docker registry secret names as an array
25 # -- Apache APISIX image repository
26 repository: chainreg.biz/chainguard-private/apache-apisix
27 # -- Apache APISIX image pull policy
28 pullPolicy: IfNotPresent
29 # -- Apache APISIX image tag
30 # Overrides the image tag whose default is the chart appVersion.
31 tag: 3.19.0-r1@sha256:4ffc3c314e15e13c1e6cfe5f30cf6e4b9ea118460af9d65294c16599bf87cccd
32# -- set false to use `Deployment`, set true to use `DaemonSet`
34# -- if useDaemonSet is true or autoscaling.enabled is true, replicaCount not become effective
36# -- Set [priorityClassName](https://kubernetes.io/docs/concepts/scheduling-eviction/pod-priority-preemption/#pod-priority) for Apache APISIX pods
38# -- Annotations to add to each pod
40# -- Labels to add to each pod
42# -- Set the securityContext for Apache APISIX pods
45# -- Number of seconds Kubernetes waits for Apache APISIX to terminate gracefully
46terminationGracePeriodSeconds: 30
47# -- Set the securityContext for Apache APISIX container
52# readOnlyRootFilesystem: true
56# -- Lifecycle hooks for the Apache APISIX container
64# -- See https://kubernetes.io/docs/tasks/run-application/configure-pdb/ for more details
66 # -- Enable or disable podDisruptionBudget
68 # -- Set the `minAvailable` of podDisruptionBudget. You can specify only one of `maxUnavailable` and `minAvailable` in a single PodDisruptionBudget.
69 # See [Specifying a Disruption Budget for your Application](https://kubernetes.io/docs/tasks/run-application/configure-pdb/#specifying-a-poddisruptionbudget)
72 # -- Set the maxUnavailable of podDisruptionBudget
74# -- Set pod resource requests & limits
76# We usually recommend not to specify default resources and to leave this as a conscious
77# choice for the user. This also increases chances charts run on environments with little
78# resources, such as Minikube. If you do want to specify resources, uncomment the following
79# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
87# -- Use the host's network namespace
89# -- Node labels for Apache APISIX pod assignment
91# -- List of node taints to tolerate
93# -- Set affinity for Apache APISIX deploy
95# -- Topology Spread Constraints for pod assignment spread across your cluster among failure-domains
96# ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/#spread-constraints-for-pods
97topologySpreadConstraints: []
98# -- timezone is the timezone where apisix uses.
99# For example: "UTC" or "Asia/Shanghai"
100# This value will be set on apisix container's environment variable TZ.
101# You may need to set the timezone to be consistent with your local time zone,
102# otherwise the apisix's logs may used to retrieve event maybe in wrong timezone.
104# -- extraEnvVars An array to add extra env vars
115# -- Update strategy of the workload (Deployment or DaemonSet), e.g. `type: RollingUpdate`
119# -- Additional Kubernetes resources to deploy with the release.
121# -- Additional `volume`, See [Kubernetes Volumes](https://kubernetes.io/docs/concepts/storage/volumes/) for the detail.
126# -- Additional `volumeMounts` for the APISIX container, See [Kubernetes Volumes](https://kubernetes.io/docs/concepts/storage/volumes/) for the detail.
129# mountPath: /usr/share/extras
132# -- Additional `initContainers`, See [Kubernetes initContainers](https://kubernetes.io/docs/concepts/workloads/pods/init-containers/) for the detail.
133extraInitContainers: []
134# - name: init-myservice
136# command: ['sh', '-c', "until nslookup myservice.$(cat /var/run/secrets/kubernetes.io/serviceaccount/namespace).svc.cluster.local; do echo waiting for myservice; sleep 2; done"]
138# -- Additional `containers`, See [Kubernetes containers](https://kubernetes.io/docs/concepts/containers/) for the detail.
141 # -- Init container image
142 image: chainreg.biz/chainguard-private/netcat
143 # -- Init container tag
144 tag: 1.238-r1@sha256:b961470bd7a9a1ece5f8bf51b2accd244cebc7a83767ab08da80821e403eb140
146 # -- Enable HorizontalPodAutoscaler for APISIX (only when useDaemonSet is false)
148 # -- HPA version, the value is "v2" or "v2beta1", default "v2"
150 # -- Minimum number of APISIX replicas
152 # -- Maximum number of APISIX replicas
154 # -- Target average CPU utilization percentage that triggers scaling
155 targetCPUUtilizationPercentage: 80
156 # -- Target average memory utilization percentage that triggers scaling
157 targetMemoryUtilizationPercentage: 80
158# -- String to partially override the chart fullname
160# -- String to fully override the chart fullname
163 # -- Whether a ServiceAccount should be created for the APISIX pods
165 # -- Annotations to add to the ServiceAccount
167 # -- Name of the ServiceAccount to use. If not set and create is true, a name is generated from the chart fullname
170 # -- Whether RBAC resources (ClusterRole and ClusterRoleBinding) should be created
173 # -- Apache APISIX service type for user access itself
175 # -- Setting how the Service route external traffic.
176 # If you want to keep the client source IP, you can set this to Local,
177 # ref: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip
178 externalTrafficPolicy: Cluster
181 # service.beta.kubernetes.io/aws-load-balancer-type: nlb
182 # -- IPs for which nodes in the cluster will also accept traffic for the service
184 # -- Apache APISIX service settings for http
186 # -- Enable plain HTTP listeners
188 # -- Kubernetes service port for HTTP traffic
190 # -- Container port APISIX listens on for HTTP traffic
192 # -- (number) Bind the APISIX HTTP container port to a host port.
194 # -- Support multiple http ports, See [Configuration](https://github.com/apache/apisix/blob/0bc65ea9acd726f79f80ae0abd8f50b7eb172e3d/conf/config-default.yaml#L24)
195 additionalContainerPorts: []
197 # enable_http2: true # If not set, the default value is `false`.
198 # - ip: 127.0.0.2 # Specific IP, If not set, the default value is `0.0.0.0`.
201 # -- Apache APISIX service settings for tls
203 # -- Kubernetes service port for HTTPS traffic
206 # -- Apache APISIX service settings for stream. L4 proxy (TCP/UDP)
208 # -- Enable the stream (L4 proxy) subsystem
210 # -- TCP proxy port list, element format: port number, or a map with `addr` and optional `tls` / `tls_passthrough`
212 # -- UDP proxy port list
214 # - secretName: apisix-tls
216 # - chart-example.local
217 # -- Override default labels assigned to Apache APISIX gateway resources
220 # app.kubernetes.io/name: "{{ .Release.Name }}"
221 # app.kubernetes.io/instance: '{{ include "apisix.name" . }}'
222# -- Using ingress access Apache APISIX service
224 # -- Enable an Ingress resource in front of the APISIX service
226 # -- (number) Service port to send traffic. Defaults to `service.http.servicePort`.
228 # -- Ingress annotations
230 # kubernetes.io/ingress.class: nginx
231 # kubernetes.io/tls-acme: "true"
232 # -- Ingress host and path rules
236 # -- Ingress TLS settings
239 # -- Enable Control API
242 # -- Control annotations
244 # -- Control service type
246 # loadBalancerIP: a.b.c.d
247 # loadBalancerSourceRanges:
249 # -- IPs for which nodes in the cluster will also accept traffic for the servic
251 # -- NodePort (only if control.service.type is NodePort)
254 # -- which ip to listen on for Apache APISIX Control API
256 # -- which port to use for Apache APISIX Control API
258 # -- Service port to use for Apache APISIX Control API
260 # -- Using ingress access Apache APISIX Control service
262 # -- Enable an Ingress resource in front of the Control API service
264 # -- Ingress annotations
266 # kubernetes.io/ingress.class: nginx
267 # kubernetes.io/tls-acme: "true"
268 # -- Ingress Class Name
270 # -- Ingress host and path rules
272 - host: apisix-control.local
275 # -- Ingress TLS settings
277 # - secretName: apisix-tls
279 # - chart-example.local
280# -- Observability configuration.
283 # -- Enable or disable Apache APISIX serviceMonitor
285 # -- namespace where the serviceMonitor is deployed, by default, it is the same as the namespace of the apisix
287 # -- name of the serviceMonitor, by default, it is the same as the apisix fullname
289 # -- interval at which metrics should be scraped
291 # -- @param serviceMonitor.labels ServiceMonitor extra labels
293 # -- @param serviceMonitor.annotations ServiceMonitor annotations
296 # -- Enable nginx IPv6 resolver
298 # -- Enable HTTP/2 on the HTTP listeners
300 # -- Whether the APISIX version number should be shown in Server header
301 enableServerTokens: true
302 # -- When true, the upstream status is always written to the `X-APISIX-Upstream-Status` response header; when false, it is written only for 5xx responses
303 showUpstreamStatusInResponseHeader: false
304 # -- PROXY Protocol configuration.
306 # -- (int) The HTTP port that accepts the PROXY Protocol. It differs from `service.http` ports and `apisix.admin` port:
307 # this port only accepts HTTP requests carrying the PROXY Protocol, while the other ports only accept plain HTTP
308 # requests. If you enable the PROXY Protocol, you must use this port to receive HTTP requests with it.
309 # When set, the port is also exposed on the gateway Service.
311 # -- (int) The nodePort of the PROXY Protocol HTTP port, only used if service.type is NodePort.
312 # If not set, a random port will be assigned by Kubernetes.
314 # -- (int) The HTTPS port that accepts the PROXY Protocol.
315 # When set, the port is also exposed on the gateway Service.
317 # -- (int) The nodePort of the PROXY Protocol HTTPS port, only used if service.type is NodePort.
318 # If not set, a random port will be assigned by Kubernetes.
320 # -- Accept the PROXY Protocol on every service.stream.tcp port.
322 # -- Send the PROXY Protocol to the upstream server on every service.stream.tcp port.
323 enableTcpPPToUpstream: false
324 # -- Proxy caching configuration used by the proxy-cache plugin.
326 # -- The default caching time in disk if the upstream does not specify the cache time
328 # -- The parameters of a cache. The `memory_size` field stores the cache index for the
329 # disk strategy and the cache content for the memory strategy; `disk_size`, `disk_path`
330 # and `cache_levels` only apply to the disk strategy.
332 - name: disk_cache_one
335 disk_path: "/tmp/disk_cache_one"
340 # -- The maximum size in bytes of GraphQL queries APISIX parses when matching routes by GraphQL attributes (default 1MiB)
342 # -- Delete the '/' at the end of the URI
343 deleteURITailSlash: false
344 # -- The URI normalization in servlet is a little different from the RFC's.
345 # See https://github.com/jakartaee/servlet/blob/master/spec/src/main/asciidoc/servlet-spec-body.adoc#352-uri-path-canonicalization,
346 # which is used under Tomcat.
347 # Turn this option on if you want to be compatible with servlet when matching URI path.
348 normalizeURILikeServlet: false
349 # -- fine tune the parameters of LRU cache for some features like secret
352 # -- TTL in seconds for cached secret values
354 # -- Maximum number of cached secret values
356 # -- TTL in seconds for cached negative (failed lookup) results
358 # -- Maximum number of cached negative (failed lookup) results
360 # -- Enable comprehensive request lifecycle tracing (SSL/SNI, rewrite, access, header_filter, body_filter, and log).
361 # When disabled, OpenTelemetry collects only a single span per request.
363 # -- Use Pod metadata.uid as the APISIX id.
364 setIDFromPodUID: false
365 # -- Whether to add a custom lua module
367 # -- Enable loading a custom lua module hook
369 # -- extend lua_package_path to load third party code
371 # -- the hook module which will be used to inject third party code into APISIX
372 # use the lua require style like: "module.say_hello"
374 # -- configmap that stores the codes
376 # -- Name of the ConfigMap where the lua module codes store
378 # mounts decides how to mount the codes to the container.
380 # -- Name of the ConfigMap key, for setting the mapping relationship between ConfigMap key and the lua module code path.
382 # -- Filepath of the plugin code, for setting the mapping relationship between ConfigMap key and the lua module code path.
385 # -- Enable HTTPS listeners
387 # -- Container port APISIX listens on for HTTPS traffic
389 # -- (number) Bind the APISIX HTTPS container port to a host port.
391 # -- Support multiple https ports, See [Configuration](https://github.com/apache/apisix/blob/0bc65ea9acd726f79f80ae0abd8f50b7eb172e3d/conf/config-default.yaml#L99)
392 additionalContainerPorts: []
393 # - ip: 127.0.0.3 # Specific IP, If not set, the default value is `0.0.0.0`.
396 # -- Specifies the name of Secret contains trusted CA certificates in the PEM format used to verify the certificate when APISIX needs to do SSL/TLS handshaking with external services (e.g. etcd)
398 # -- Filename be used in the apisix.ssl.existingCASecret
400 # -- Enable HTTP/3 (QUIC) on the HTTPS listeners
402 # -- TLS protocols allowed to use.
403 sslProtocols: "TLSv1.2 TLSv1.3"
404 # -- TLS ciphers allowed to use.
405 sslCiphers: "ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-SHA256:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA"
406 # -- Enable or disable TLS session tickets. Disabled by default because session tickets
407 # defeat Perfect Forward Secrecy (see https://github.com/mozilla/server-side-tls/issues/135)
408 sslSessionTickets: false
409 # -- Define SNI to fallback if none is presented by client
412 # -- Defines how apisix handles routing:
413 # - radixtree_uri: match route by uri(base on radixtree)
414 # - radixtree_host_uri: match route by host + uri(base on radixtree)
415 # - radixtree_uri_with_parameter: match route by uri with parameters
416 http: radixtree_host_uri
418 # -- Enable full customized config.yaml
420 # -- If apisix.fullCustomConfig.enabled is true, full customized config.yaml.
421 # Please note that other settings about APISIX config will be ignored
424 # -- Apache APISIX deployment mode
425 # Optional: traditional, decoupled, standalone
427 # ref: https://apisix.apache.org/docs/apisix/deployment-modes/
430 # Optional: traditional, data_plane, control_plane
432 # ref: https://apisix.apache.org/docs/apisix/deployment-modes/
435 # -- Config provider for the traditional role. enum: etcd, yaml
436 config_provider: "etcd"
437 # -- Standalone rules configuration
439 # ref: https://apisix.apache.org/docs/apisix/deployment-modes/#standalone
441 # -- Rules which are set to the default apisix.yaml configmap.
442 # If apisix.delpoyment.standalone.existingConfigMap is empty, these are used.
451 # -- Specifies the name of the ConfigMap that contains the rule configurations.
452 # The configuration must be set to the key named `apisix.yaml` in the configmap.
453 existingConfigMap: ""
455 # -- Enable Admin API
457 # -- Enable Embedded Admin UI
458 enable_admin_ui: true
459 # -- admin service type
461 # loadBalancerIP: a.b.c.d
462 # loadBalancerSourceRanges:
464 # -- IPs for which nodes in the cluster will also accept traffic for the servic
466 # -- which ip to listen on for Apache APISIX admin API. Set to `"[::]"` when on IPv6 single stack
468 # -- which port to use for Apache APISIX admin API
470 # -- Service port to use for Apache APISIX admin API
472 # -- Admin API support CORS response headers
474 # -- Admin API credentials
476 # -- Apache APISIX admin API admin role credentials
477 admin: edd1c9f034335f136f87ad84b625c8f1
478 # -- Apache APISIX admin API viewer role credentials
479 viewer: 4054f7cf07e344346cd3f287985e76a2
480 # -- The APISIX Helm chart supports storing user credentials in a secret.
481 # The secret needs to contain two keys, admin and viewer, with their respective values set.
483 # -- Name of the admin role key in the secret, overrides the default key name "admin"
485 # -- Name of the viewer role key in the secret, overrides the default key name "viewer"
488 # -- The client IP CIDR allowed to access Apache APISIX Admin API service.
491 # -- Using ingress access Apache APISIX admin service
493 # -- Enable an Ingress resource in front of the Admin API service
495 # -- Ingress annotations
497 # kubernetes.io/ingress.class: nginx
498 # kubernetes.io/tls-acme: "true"
499 # -- Ingress host and path rules
501 - host: apisix-admin.local
504 # -- Ingress TLS settings
506 # - secretName: apisix-tls
508 # - chart-example.local
510 # -- The number of files a worker process can open, should be larger than apisix.nginx.workerConnections
511 workerRlimitNofile: "20480"
512 # -- The maximum number of connections that each worker process can open
513 workerConnections: "10620"
514 # -- The number of nginx worker processes. `auto` means the number of CPU cores
515 workerProcesses: auto
516 # -- Bind nginx worker processes to CPUs
517 enableCPUAffinity: true
518 # -- Timeout for a graceful shutdown of worker processes
519 workerShutdownTimeout: "240s"
520 # -- Maximum number of pending timers. Increase it if you see "too many pending timers" error
521 maxPendingTimers: 16384
522 # -- Maximum number of running timers. Increase it if you see "lua_max_running_timers are not enough" error
523 maxRunningTimers: 4096
524 # -- Timeout during which a keep-alive client connection will stay open on the server side.
525 keepaliveTimeout: 60s
526 # -- List of environment variable names allowed to be accessed within nginx (rendered as nginx `env` directives)
528 # -- Nginx HTTP subsystem configurations
530 # -- timeout for reading client request header, then 408 (Request Time-out) error is returned to the client
531 clientHeaderTimeout: "60s"
532 # -- timeout for reading client request body, then 408 (Request Time-out) error is returned to the client
533 clientBodyTimeout: "60s"
534 # -- timeout for transmitting a response to the client, then the connection is closed
536 # -- The maximum allowed size of the client request body.
537 # If exceeded, the 413 (Request Entity Too Large) error is returned to the client.
538 # Note that unlike Nginx, we don't limit the body size by default (0 means no limit).
540 # -- Enable the use of underscores in client request header fields
541 underscoresInHeaders: "on"
542 # -- The request header used to determine the client's real IP address,
543 # see [real_ip_header](http://nginx.org/en/docs/http/ngx_http_realip_module.html#real_ip_header)
544 realIpHeader: "X-Real-IP"
545 # -- Whether to search for the real IP recursively when the header set in apisix.nginx.http.realIpHeader contains multiple addresses,
546 # see [real_ip_recursive](http://nginx.org/en/docs/http/ngx_http_realip_module.html#real_ip_recursive)
547 realIpRecursive: "off"
548 # -- Trusted addresses from which the real IP header is honored,
549 # see [set_real_ip_from](http://nginx.org/en/docs/http/ngx_http_realip_module.html#set_real_ip_from)
553 # -- Enables or disables passing of the server name through TLS Server Name Indication extension (SNI, RFC 6066)
554 # when establishing a connection with the proxied HTTPS server
555 proxySslServerName: true
556 # -- Keepalive settings for connections from APISIX to upstream servers
558 # -- Maximum number of idle keepalive connections to upstream servers that are preserved in the cache of each worker process.
559 # When this number is exceeded, the least recently used connections are closed
561 # -- Maximum number of requests that can be served through one keepalive connection.
562 # After the maximum number of requests is made, the connection is closed
563 keepaliveRequests: 1000
564 # -- Timeout during which an idle keepalive connection to an upstream server will stay open
565 keepaliveTimeout: 60s
566 # -- The charset added to the "Content-Type" response header field,
567 # see [charset](http://nginx.org/en/docs/http/ngx_http_charset_module.html#charset)
569 # -- The maximum size of the nginx variables hash table
570 variablesHashMaxSize: 2048
571 # access log and error log configuration
573 # -- Enable access log or not, default true
574 enableAccessLog: true
576 accessLog: "/dev/stdout"
577 # -- Access log format
578 accessLogFormat: '$remote_addr - $remote_user [$time_local] $http_host \"$request\" $status $body_bytes_sent $request_time \"$http_referer\" \"$http_user_agent\" $upstream_addr $upstream_status $upstream_response_time \"$upstream_scheme://$upstream_host$upstream_uri\"'
579 # -- Allows setting json or default characters escaping in variables
580 accessLogFormatEscape: default
582 errorLog: "/dev/stderr"
584 errorLogLevel: "warn"
585 # -- Stream (L4 proxy) access log configuration
587 # -- Enable stream access log or not, default false
588 enableAccessLog: false
589 # -- Stream access log path
590 accessLog: "logs/access_stream.log"
591 # -- Stream access log format
592 accessLogFormat: '$remote_addr [$time_local] $protocol $status $bytes_sent $bytes_received $session_time'
593 # -- Allows setting json or default characters escaping in variables for stream
594 accessLogFormatEscape: default
595 # -- Custom nginx configuration snippets injected into the generated nginx.conf.
596 # As arbitrary configuration can be added here, it is your responsibility to make sure
597 # the snippets don't conflict with the configuration generated by APISIX.
598 configurationSnippet:
599 # -- Snippet added to the nginx `main` (top-level) block
601 # -- Snippet added to the beginning of the nginx `http` block
603 # -- Snippet added to the end of the nginx `http` block
605 # -- Snippet added to the nginx `server` block that proxies regular traffic
607 # -- Snippet added to the nginx `server` block that serves the Admin API
609 # -- Snippet added to the nginx `stream` block
611 # -- Add custom [lua_shared_dict](https://github.com/openresty/lua-nginx-module?tab=readme-ov-file#lua_shared_dict) settings,
612 # click [here](https://github.com/apache/apisix-helm-chart/blob/master/charts/apisix/values.yaml#L27-L30) to learn the format of a shared dict
613 customLuaSharedDicts: []
619 # -- Override default [lua_shared_dict](https://github.com/apache/apisix/blob/master/conf/config.yaml.example#L250-L276) settings,
620 # click [here](https://github.com/apache/apisix-helm-chart/blob/master/charts/apisix/values.yaml#L27-L30) to learn the format of a shared dict
622 # - name: prometheus-metrics
625 # -- Override default meta-level [lua_shared_dict](https://github.com/apache/apisix/blob/master/conf/config.yaml.example) settings,
626 # meta-level shared dicts are shared across both HTTP and stream subsystems.
627 # Since APISIX 3.16.0, `upstream-healthcheck` is a meta-level shared dict.
628 # click [here](https://github.com/apache/apisix-helm-chart/blob/master/charts/apisix/values.yaml#L27-L30) to learn the format of a shared dict
629 metaLuaSharedDicts: []
630 # - name: upstream-healthcheck
633 # -- Enable or disable Apache APISIX integration service discovery
635 # -- Service discovery registry. Refer to [configuration under discovery](https://github.com/apache/apisix/blob/master/conf/config.yaml.example#L307) for example.
636 # Also see [example of using external service discovery](https://apisix.apache.org/docs/ingress-controller/1.8.0/tutorials/external-service-discovery/).
638 # Integration service discovery registry. E.g eureka\dns\nacos\consul_kv
640 # https://apisix.apache.org/docs/apisix/discovery/#configuration-for-eureka
641 # https://apisix.apache.org/docs/apisix/discovery/dns/#service-discovery-via-dns
642 # https://apisix.apache.org/docs/apisix/discovery/consul_kv/#configuration-for-consul-kv
643 # https://apisix.apache.org/docs/apisix/discovery/nacos/#configuration-for-nacos
644 # https://apisix.apache.org/docs/apisix/discovery/kubernetes/#configuration
650 # - "http://${username}:${password}@${eureka_host1}:${eureka_port1}"
651 # - "http://${username}:${password}@${eureka_host2}:${eureka_port2}"
661 # the minimal Kubernetes example:
666 # The prerequisites for the above minimal Kubernetes example:
667 # 1. [Optional] Set `.serviceAccount.create` to `true` to create a dedicated ServiceAccount.
668 # It is recommended to do so, otherwise the default ServiceAccount "default" will be used.
669 # 2. [Required] Set `.rbac.create` to `true` to create and bind the necessary RBAC resources.
670 # This grants the ServiceAccount in use to List-Watch Kubernetes Endpoints resources.
671 # 3. [Required] Include the following environment variables in `.nginx.envs` to pass them into
672 # nginx worker processes (https://nginx.org/en/docs/ngx_core_module.html#env):
673 # - KUBERNETES_SERVICE_HOST
674 # - KUBERNETES_SERVICE_PORT
675 # This is for allowing the default `host` and `port` of `.discovery.registry.kubernetes.service`.
677 # -- Nameservers used by APISIX to resolve upstream domain names.
678 # When empty (default), nameservers are read from `/etc/resolv.conf`,
679 # which is usually what you want inside Kubernetes
683 # -- Override the TTL in seconds of valid DNS records
685 # -- DNS resolver timeout in seconds
687 # -- Honor the `search` option in `/etc/resolv.conf` when resolving domain names
688 enableResolvSearchOpt: true
690 # -- Enable or disable the vault integration
692 # -- The host address where the vault server is running.
694 # -- HTTP timeout for each request.
696 # -- The generated token from vault instance that can grant access to read data from the vault.
698 # -- Prefix allows you to better enforcement of policies.
701 # -- Enable Prometheus metrics. ref: https://apisix.apache.org/docs/apisix/plugins/prometheus/
703 # -- path of the metrics endpoint
704 path: /apisix/prometheus/metrics
705 # -- prefix of the metrics
706 metricPrefix: apisix_
707 # -- container port where the metrics are exposed
709 # -- Customize the list of APISIX plugins to enable. By default, APISIX's [default plugins](https://github.com/apache/apisix/blob/master/apisix/cli/config.lua#L196) are automatically used.
711 # -- Customize the list of APISIX stream_plugins to enable. By default, APISIX's [default stream_plugins](https://github.com/apache/apisix/blob/master/apisix/cli/config.lua#L294) are automatically used.
713 # -- Set APISIX plugin attributes. By default, APISIX's [plugin_attr](https://github.com/apache/apisix/blob/master/apisix/cli/config.lua#L295) are automatically used.
714 # See [configuration example](https://github.com/apache/apisix/blob/master/conf/config.yaml.example#L591).
717 # -- Enable External Plugins. See [external plugin](https://apisix.apache.org/docs/apisix/next/external-plugin/)
719 # -- the command and its arguements to run as a subprocess
720 cmd: ["/path/to/apisix-plugin-runner/runner", "run"]
722 # -- Enable Wasm Plugins. See [wasm plugin](https://apisix.apache.org/docs/apisix/next/wasm/)
724 # -- List of Wasm plugins, each item with `name`, `priority` and `file` (path or URL of the wasm binary)
726 # -- customPlugins allows you to mount your own HTTP plugins.
728 # -- Whether to configure some custom plugins
730 # -- the lua_path that tells APISIX where it can find plugins,
731 # note the last ';' is required.
732 luaPath: "/opts/custom_plugins/?.lua"
735 - name: "plugin-name"
738 # -- plugin codes can be saved inside configmap object.
740 # -- name of configmap.
741 name: "configmap-name"
742 # -- since keys in configmap is flat, mountPath allows to define the mount
743 # path, so that plugin codes can be mounted hierarchically.
745 - key: "the-file-name"
748 # -- The IP address on which the status endpoint (`/status`, `/status/ready`) listens
750 # -- The port on which the status endpoint listens
752 # -- When configured, APISIX will trust the `X-Forwarded-*` Headers passed in requests from the IP/CIDR in the list.
755# -- external etcd configuration. If etcd.enabled is false, these configuration will be used.
757 # -- if etcd.enabled is false, use external etcd, support multiple address, if your etcd cluster enables TLS, please use https scheme, e.g. https://127.0.0.1:2379.
759 # host or ip e.g. http://172.20.128.89:2379
760 - http://etcd.host:2379
761 # -- if etcd.enabled is false, user for external etcd. Set empty to disable authentication
763 # -- if etcd.enabled is true, use etcd.auth.rbac.rootPassword instead.
764 # -- if etcd.enabled is false and externalEtcd.existingSecret is not empty, the password should store in the corresponding secret
765 # -- if etcd.enabled is false and externalEtcd.existingSecret is empty, externalEtcd.password is the passsword for external etcd.
767 # -- if externalEtcd.existingSecret is the name of secret containing the external etcd password
769 # -- externalEtcd.secretPasswordKey Key inside the secret containing the external etcd password
770 secretPasswordKey: "etcd-root-password"
771# -- etcd configuration
772# use the FQDN address or the IP of the etcd
774 # -- install built-in etcd by default, set false if do not want to install built-in etcd together,
775 # this etcd is based on bitnamilegacy/etcd helm chart and latest bitnami docker image, only for development and testing purposes,
776 # if you want to use etcd in production, we recommend you to install etcd by yourself and use `externalEtcd` to connect it.
778 # -- docker image for built-in etcd
781 repository: bitnamilegacy/etcd
782 # -- `bitnamilegacy/etcd` only provide `latest` tag now, ref: https://github.com/bitnami/containers/issues/83267,
783 # you can switch `etcd.image.repository` to `bitnamilegacy/etcd` to use old versioned tags.
785 # -- apisix configurations prefix
787 # -- Set the timeout value in seconds for subsequent socket operations from apisix to etcd cluster
789 # -- Set the timeout value in seconds for watching etcd
791 # -- The number of retries to etcd during startup
793 # -- if etcd.enabled is true, set more values of bitnamilegacy/etcd helm chart
796 # -- No authentication by default. Switch to enable RBAC authentication
798 # -- root password for etcd. Requires etcd.auth.rbac.create to be true.
801 # -- enable etcd client certificate
803 # -- name of the secret contains etcd client cert
805 # -- etcd client cert filename using in etcd.auth.tls.existingSecret
807 # -- etcd client cert key filename using in etcd.auth.tls.existingSecret
809 # -- whether to verify the etcd endpoint certificate when setup a TLS connection to etcd
811 # -- specify the TLS Server Name Indication extension, the ETCD endpoint hostname will be used when this setting is unset.
813 # -- ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container
814 # -- added for backward compatibility with old kubernetes versions, as seccompProfile is not supported in kubernetes < 1.19
815 containerSecurityContext:
818 # -- etcd client service port
820 # -- Number of etcd replicas, only used when etcd.enabled is true
822 # -- Auto compaction retention for mvcc key value store, only used when etcd.enabled is true
823 autoCompactionRetention: "1h"
824 # -- Auto compaction mode (periodic or revision), only used when etcd.enabled is true
825 autoCompactionMode: "periodic"
826# -- Ingress controller configuration
828 # -- Enable the apisix-ingress-controller sub-chart
831 # Specifies whether to enable the validation webhook.
832 # Note: This feature relies on the '/apisix/admin/configs/validate' endpoint.
833 # It requires APISIX version 3.17.0 or later to function correctly.
834 # Ensure your cluster's APISIX deployment meets this version requirement before enabling.