DirectorySecurity AdvisoriesPricing
Sign in
Directory
argo-cd logoHELM

argo-cd

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:
Compare:

1
## Argo CD configuration
2
## Ref: https://github.com/argoproj/argo-cd
3
##
4
5
# -- Provide a name in place of `argocd`
6
nameOverride: argocd
7
# -- String to fully override `"argo-cd.fullname"`
8
fullnameOverride: ""
9
# -- Override the namespace
10
# @default -- `.Release.Namespace`
11
namespaceOverride: ""
12
# -- Override the Kubernetes version, which is used to evaluate certain manifests
13
kubeVersionOverride: ""
14
# Override APIVersions
15
# If you want to template helm charts but cannot access k8s API server
16
# you can set api versions here
17
apiVersionOverrides: {}
18
# -- Create aggregated roles that extend existing cluster roles to interact with argo-cd resources
19
## Ref: https://kubernetes.io/docs/reference/access-authn-authz/rbac/#aggregated-clusterroles
20
createAggregateRoles: false
21
# -- Create cluster roles for cluster-wide installation.
22
## Used when you manage applications in the same cluster where Argo CD runs
23
createClusterRoles: true
24
openshift:
25
# -- enables using arbitrary uid for argo repo server
26
enabled: false
27
## Custom resource configuration
28
crds:
29
# -- Install and upgrade CRDs
30
install: true
31
# -- Keep CRDs on chart uninstall
32
keep: true
33
# -- Annotations to be added to all CRDs
34
annotations:
35
argocd.argoproj.io/sync-options: ServerSideApply=true
36
# -- Additional labels to be added to all CRDs
37
additionalLabels: {}
38
## Globally shared configuration
39
global:
40
# -- Default domain used by all components
41
## Used for ingresses, certificates, SSO, notifications, etc.
42
domain: argocd.example.com
43
# -- Runtime class name for all components
44
runtimeClassName: ""
45
# -- Common labels for the all resources
46
additionalLabels: {}
47
# app: argo-cd
48
49
# -- Number of old deployment ReplicaSets to retain. The rest will be garbage collected.
50
revisionHistoryLimit: 3
51
# Default image used by all components
52
image:
53
# -- If defined, a repository applied to all Argo CD deployments
54
repository: chainreg.biz/chainguard-private/argocd
55
# -- Overrides the global Argo CD image tag whose default is the chart appVersion
56
tag: 3.5.3-r1@sha256:48bc1589241147b042a70a8b992dcc9b7bad3ec9b91271a88d9baef923ead1fb
57
# -- If defined, a imagePullPolicy applied to all Argo CD deployments
58
imagePullPolicy: IfNotPresent
59
# -- Secrets with credentials to pull images from a private registry
60
imagePullSecrets: []
61
# Default logging options used by all components
62
logging:
63
# -- Set the global logging format. Either: `text` or `json`
64
format: text
65
# -- Set the global logging level. One of: `debug`, `info`, `warn` or `error`
66
level: info
67
# -- Annotations for the all deployed Statefulsets
68
statefulsetAnnotations: {}
69
# -- Labels for the all deployed Statefulsets
70
statefulsetLabels: {}
71
# -- Annotations for the all deployed Deployments
72
deploymentAnnotations: {}
73
# -- Labels for the all deployed Deployments
74
deploymentLabels: {}
75
# -- Annotations for the all deployed pods
76
podAnnotations: {}
77
# -- Labels for the all deployed pods
78
podLabels: {}
79
# -- Add Prometheus scrape annotations to all metrics services. This can be used as an alternative to the ServiceMonitors.
80
addPrometheusAnnotations: false
81
# -- Toggle and define pod-level security context.
82
# @default -- `{}` (See [values.yaml])
83
securityContext: {}
84
# runAsUser: 999
85
# runAsGroup: 999
86
# fsGroup: 999
87
88
# -- Mapping between IP and hostnames that will be injected as entries in the pod's hosts files
89
hostAliases: []
90
# - ip: 10.20.30.40
91
# hostnames:
92
# - git.myhostname
93
94
# Configure dual-stack used by all component services
95
dualStack:
96
# -- IP family policy to configure dual-stack see [Configure dual-stack](https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services)
97
ipFamilyPolicy: ""
98
# -- IP families that should be supported and the order in which they should be applied to ClusterIP as well. Can be IPv4 and/or IPv6.
99
ipFamilies: []
100
# Default network policy rules used by all components
101
networkPolicy:
102
# -- Create NetworkPolicy objects for all components
103
create: true
104
# -- Default deny all ingress traffic
105
defaultDenyIngress: false
106
# -- Default priority class for all components
107
priorityClassName: ""
108
# -- Default node selector for all components
109
nodeSelector:
110
kubernetes.io/os: linux
111
# -- Default tolerations for all components
112
tolerations: []
113
# Default affinity preset for all components
114
affinity:
115
# -- Default pod anti-affinity rules. Either: `none`, `soft` or `hard`
116
podAntiAffinity: soft
117
# Node affinity rules
118
nodeAffinity:
119
# -- Default node affinity rules. Either: `none`, `soft` or `hard`
120
type: hard
121
# -- Default match expressions for node affinity
122
matchExpressions: []
123
# - key: topology.kubernetes.io/zone
124
# operator: In
125
# values:
126
# - antarctica-east1
127
# - antarctica-west1
128
# -- Default [TopologySpreadConstraints] rules for all components
129
## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
130
## If labelSelector is left out, it will default to the labelSelector of the component
131
topologySpreadConstraints: []
132
# - maxSkew: 1
133
# topologyKey: topology.kubernetes.io/zone
134
# whenUnsatisfiable: DoNotSchedule
135
136
# -- Deployment strategy for the all deployed Deployments
137
deploymentStrategy: {}
138
# type: RollingUpdate
139
# rollingUpdate:
140
# maxSurge: 25%
141
# maxUnavailable: 25%
142
143
# -- Environment variables to pass to all deployed Deployments
144
env: []
145
# -- Extra volumes to add to all deployed Deployments and StatefulSets
146
extraVolumes: []
147
# Example of adding a custom CA bundle from a ConfigMap:
148
# - name: my-root-ca
149
# configMap:
150
# name: my-trustbundle
151
# items:
152
# - key: bundle.pem
153
# path: ca-certificates.crt
154
155
# -- Extra volume mounts to add to all deployed Deployments and StatefulSets
156
extraVolumeMounts: []
157
# Example of adding a custom CA bundle mount:
158
# - name: my-root-ca
159
# mountPath: /etc/ssl/certs
160
161
# -- Annotations for the all deployed Certificates
162
certificateAnnotations: {}
163
## Argo Configs
164
configs:
165
# General Argo CD configuration. Any values you put under `.configs.cm` are passed to argocd-cm ConfigMap.
166
## Ref: https://github.com/argoproj/argo-cd/blob/master/docs/operator-manual/argocd-cm.yaml
167
cm:
168
# -- Create the argocd-cm configmap for [declarative setup]
169
create: true
170
# -- Annotations to be added to argocd-cm configmap
171
annotations: {}
172
# -- The name of tracking label used by Argo CD for resource pruning
173
application.instanceLabelKey: argocd.argoproj.io/instance
174
# -- Enable control of the service account used for the sync operation (alpha)
175
## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/app-sync-using-impersonation/
176
application.sync.impersonation.enabled: false
177
# -- Enable exec feature in Argo UI
178
## Ref: https://argo-cd.readthedocs.io/en/latest/operator-manual/rbac/#exec-resource
179
exec.enabled: false
180
# -- Enable local admin user
181
## Ref: https://argo-cd.readthedocs.io/en/latest/faq/#how-to-disable-admin-user
182
admin.enabled: true
183
# -- Timeout to discover if a new manifests version got published to the repository
184
timeout.reconciliation: 120s
185
# -- Maximum jitter added to the reconciliation timeout to spread out refreshes and reduce repo-server load
186
timeout.reconciliation.jitter: 60s
187
# -- Timeout to refresh application data as well as target manifests cache
188
timeout.hard.reconciliation: 0s
189
# -- Enable Status Badge
190
## Ref: https://argo-cd.readthedocs.io/en/stable/user-guide/status-badge/
191
statusbadge.enabled: false
192
# Dex configuration
193
# dex.config: |
194
# connectors:
195
# # GitHub example
196
# - type: github
197
# id: github
198
# name: GitHub
199
# config:
200
# clientID: aabbccddeeff00112233
201
# clientSecret: $dex.github.clientSecret # Alternatively $<some_K8S_secret>:dex.github.clientSecret
202
# orgs:
203
# - name: your-github-org
204
205
# OIDC configuration as an alternative to dex (optional).
206
# oidc.config: |
207
# name: AzureAD
208
# issuer: https://login.microsoftonline.com/TENANT_ID/v2.0
209
# clientID: aaaabbbbccccddddeee
210
# clientSecret: $oidc.azuread.clientSecret
211
# # Optional: set to true to use Azure Workload Identity instead of clientSecret
212
# azure:
213
# useWorkloadIdentity: false
214
215
# Some OIDC providers require a separate clientID for different callback URLs.
216
# For example, if configuring Argo CD with self-hosted Dex, you will need a separate client ID
217
# for the 'localhost' (CLI) client to Dex. This field is optional. If omitted, the CLI will
218
# use the same clientID as the Argo CD server
219
# cliClientID: vvvvwwwwxxxxyyyyzzzz
220
221
# rootCA: |
222
# -----BEGIN CERTIFICATE-----
223
# ... encoded certificate data here ...
224
# -----END CERTIFICATE-----
225
226
# Optional list of allowed aud claims. If omitted or empty, defaults to the clientID value above (and the
227
# cliClientID, if that is also specified). If you specify a list and want the clientID to be allowed, you must
228
# explicitly include it in the list.
229
# Token verification will pass if any of the token's audiences matches any of the audiences in this list.
230
# allowedAudiences:
231
# - aaaabbbbccccddddeee
232
# - qqqqwwwweeeerrrrttt
233
234
# Optional set of OIDC claims to request on the ID token.
235
# requestedIDTokenClaims:
236
# groups:
237
# essential: true
238
239
# Optional set of OIDC scopes to request. If omitted, defaults to: ["openid", "profile", "email", "groups"]
240
# requestedScopes:
241
# - openid
242
# - profile
243
# - email
244
245
# PKCE authentication flow processes authorization flow from browser only - default false
246
# uses the clientID
247
# make sure the Identity Provider (IdP) is public and doesn't need clientSecret
248
# make sure the Identity Provider (IdP) has this redirect URI registered: https://argocd.example.com/pkce/verify
249
# enablePKCEAuthentication: true
250
251
# Extension Configuration
252
## Ref: https://argo-cd.readthedocs.io/en/latest/developer-guide/extensions/proxy-extensions/
253
# extension.config: |
254
# extensions:
255
# - name: httpbin
256
# backend:
257
# connectionTimeout: 2s
258
# keepAlive: 15s
259
# idleConnectionTimeout: 60s
260
# maxIdleConnections: 30
261
# services:
262
# - url: http://httpbin.org
263
# headers:
264
# - name: some-header
265
# value: '$some.argocd.secret.key'
266
# cluster:
267
# name: some-cluster
268
# server: https://some-cluster
269
270
## Default configuration for ignoreResourceUpdates.
271
## The ignoreResourceUpdates list contains K8s resource's properties that are known to be frequently updated
272
## by controllers and operators. These resources, when watched by argo, will cause many unnecessary updates.
273
274
# -- Ignoring status for all resources. An update will still be sent if the status update causes the health to change.
275
# @default -- See [values.yaml]
276
resource.customizations.ignoreResourceUpdates.all: |
277
jsonPointers:
278
- /status
279
# -- Some Application fields are generated and not related to the application updates itself
280
## The Application itself is already watched by the controller lister, but this configuration is applied for apps of apps
281
# @default -- See [values.yaml]
282
resource.customizations.ignoreResourceUpdates.argoproj.io_Application: |
283
jqPathExpressions:
284
- '.metadata.annotations."notified.notifications.argoproj.io"'
285
- '.metadata.annotations."argocd.argoproj.io/refresh"'
286
- '.metadata.annotations."argocd.argoproj.io/hydrate"'
287
- '.operation'
288
# -- Ignore Argo Rollouts generated fields
289
# @default -- See [values.yaml]
290
resource.customizations.ignoreResourceUpdates.argoproj.io_Rollout: |
291
jqPathExpressions:
292
- '.metadata.annotations."notified.notifications.argoproj.io"'
293
# -- Legacy annotations used on HPA autoscaling/v1
294
# @default -- See [values.yaml]
295
resource.customizations.ignoreResourceUpdates.autoscaling_HorizontalPodAutoscaler: |
296
jqPathExpressions:
297
- '.metadata.annotations."autoscaling.alpha.kubernetes.io/behavior"'
298
- '.metadata.annotations."autoscaling.alpha.kubernetes.io/conditions"'
299
- '.metadata.annotations."autoscaling.alpha.kubernetes.io/metrics"'
300
- '.metadata.annotations."autoscaling.alpha.kubernetes.io/current-metrics"'
301
# -- Ignore the cluster-autoscaler status
302
# @default -- See [values.yaml]
303
resource.customizations.ignoreResourceUpdates.ConfigMap: |
304
jqPathExpressions:
305
# Ignore the cluster-autoscaler status
306
- '.metadata.annotations."cluster-autoscaler.kubernetes.io/last-updated"'
307
# Ignore the annotation of the legacy Leases election
308
- '.metadata.annotations."control-plane.alpha.kubernetes.io/leader"'
309
# -- Ignore the common scaling annotations
310
# @default -- See [values.yaml]
311
resource.customizations.ignoreResourceUpdates.apps_ReplicaSet: |
312
jqPathExpressions:
313
- '.metadata.annotations."deployment.kubernetes.io/desired-replicas"'
314
- '.metadata.annotations."deployment.kubernetes.io/max-replicas"'
315
- '.metadata.annotations."rollout.argoproj.io/desired-replicas"'
316
# -- Ignores update if EndpointSlice is not excluded globally
317
# @default -- See [values.yaml]
318
resource.customizations.ignoreResourceUpdates.discovery.k8s.io_EndpointSlice: |
319
jsonPointers:
320
- /metadata
321
- /endpoints
322
- /ports
323
# -- Ignores update if Endpoints is not excluded globally
324
# @default -- See [values.yaml]
325
resource.customizations.ignoreResourceUpdates.Endpoints: |
326
jsonPointers:
327
- /metadata
328
- /subsets
329
## Default configuration for exclusions.
330
## The exclusion list are K8s resources that we assume will never be declared in Git,
331
## and are never child objects of managed resources that need to be presented in the resource tree.
332
## This list contains high volume and high churn metadata objects which we exclude for performance
333
## reasons, reducing connections and load to the K8s API servers of managed clusters.
334
335
# -- Resource Exclusion/Inclusion
336
# @default -- See [values.yaml]
337
resource.exclusions: |
338
### Network resources created by the Kubernetes control plane and excluded to reduce the number of watched events and UI clutter
339
- apiGroups:
340
- ''
341
- discovery.k8s.io
342
kinds:
343
- Endpoints
344
- EndpointSlice
345
### Internal Kubernetes resources excluded reduce the number of watched events
346
- apiGroups:
347
- coordination.k8s.io
348
kinds:
349
- Lease
350
### Internal Kubernetes Authz/Authn resources excluded reduce the number of watched events
351
- apiGroups:
352
- authentication.k8s.io
353
- authorization.k8s.io
354
kinds:
355
- SelfSubjectReview
356
- TokenReview
357
- LocalSubjectAccessReview
358
- SelfSubjectAccessReview
359
- SelfSubjectRulesReview
360
- SubjectAccessReview
361
### Intermediate Certificate Request excluded reduce the number of watched events
362
- apiGroups:
363
- certificates.k8s.io
364
kinds:
365
- CertificateSigningRequest
366
- apiGroups:
367
- cert-manager.io
368
kinds:
369
- CertificateRequest
370
### Cilium internal resources excluded reduce the number of watched events and UI Clutter
371
- apiGroups:
372
- cilium.io
373
kinds:
374
- CiliumIdentity
375
- CiliumEndpoint
376
- CiliumEndpointSlice
377
### Kyverno intermediate and reporting resources excluded reduce the number of watched events and improve performance
378
- apiGroups:
379
- kyverno.io
380
- reports.kyverno.io
381
- wgpolicyk8s.io
382
kinds:
383
- PolicyReport
384
- ClusterPolicyReport
385
- EphemeralReport
386
- ClusterEphemeralReport
387
- AdmissionReport
388
- ClusterAdmissionReport
389
- BackgroundScanReport
390
- ClusterBackgroundScanReport
391
- UpdateRequest
392
# -- Additional resource exclusions to append to the default `resource.exclusions` list above,
393
# so that the defaults can be kept up to date without needing to duplicate/override them.
394
# These entries are always appended, never substituted: if you also set `resource.exclusions`
395
# yourself, they are appended to your value rather than to the chart defaults.
396
# @default -- `[]`
397
resourceExclusionsAdditional: []
398
# Argo CD configuration parameters
399
## Ref: https://github.com/argoproj/argo-cd/blob/master/docs/operator-manual/argocd-cmd-params-cm.yaml
400
params:
401
# -- Create the argocd-cmd-params-cm configmap
402
# If false, it is expected the configmap will be created by something else.
403
create: true
404
# -- Annotations to be added to the argocd-cmd-params-cm ConfigMap
405
annotations: {}
406
# You can customize parameters by adding parameters here.
407
# (e.g.)
408
# otlp.address: ''
409
# Argo CD RBAC policy configuration
410
## Ref: https://github.com/argoproj/argo-cd/blob/master/docs/operator-manual/rbac.md
411
rbac:
412
# -- Create the argocd-rbac-cm configmap with ([Argo CD RBAC policy]) definitions.
413
# If false, it is expected the configmap will be created by something else.
414
# Argo CD will not work if there is no configmap created with the name above.
415
create: true
416
# -- Annotations to be added to argocd-rbac-cm configmap
417
annotations: {}
418
# -- The name of the default role which Argo CD will falls back to, when authorizing API requests (optional).
419
# If omitted or empty, users may be still be able to login, but will see no apps, projects, etc...
420
policy.default: ""
421
# -- File containing user-defined policies and role definitions.
422
# @default -- `''` (See [values.yaml])
423
policy.csv: ""
424
# Policy rules are in the form:
425
# p, subject, resource, action, object, effect
426
# Role definitions and bindings are in the form:
427
# g, subject, inherited-subject
428
# policy.csv: |
429
# p, role:org-admin, applications, *, */*, allow
430
# p, role:org-admin, clusters, get, *, allow
431
# p, role:org-admin, repositories, *, *, allow
432
# p, role:org-admin, logs, get, *, allow
433
# p, role:org-admin, exec, create, */*, allow
434
# g, your-github-org:your-team, role:org-admin
435
436
# -- OIDC scopes to examine during rbac enforcement (in addition to `sub` scope).
437
# The scope value can be a string, or a list of strings.
438
scopes: "[groups]"
439
# -- Matcher function for Casbin, `glob` for glob matcher and `regex` for regex matcher.
440
policy.matchMode: "glob"
441
# GnuPG public keys for commit verification
442
## Ref: https://argo-cd.readthedocs.io/en/stable/user-guide/gpg-verification/
443
gpg:
444
# -- Annotations to be added to argocd-gpg-keys-cm configmap
445
annotations: {}
446
# -- [GnuPG] public keys to add to the keyring
447
# @default -- `{}` (See [values.yaml])
448
## Note: Public keys should be exported with `gpg --export --armor <KEY>`
449
keys: {}
450
# 4AEE18F83AFDEB23: |
451
# -----BEGIN PGP PUBLIC KEY BLOCK-----
452
# ...
453
# -----END PGP PUBLIC KEY BLOCK-----
454
# SSH known hosts for Git repositories
455
## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/declarative-setup/#ssh-known-host-public-keys
456
ssh:
457
# -- Specifies if the argocd-ssh-known-hosts-cm configmap should be created by Helm.
458
create: true
459
# -- Annotations to be added to argocd-ssh-known-hosts-cm configmap
460
annotations: {}
461
# -- Known hosts to be added to the known host list by default.
462
# @default -- See [values.yaml]
463
knownHosts: |
464
[ssh.github.com]:443 ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBEmKSENjQEezOmxkZMy7opKgwFB9nkt5YRrYMjNuG5N87uRgg6CLrbo5wAdT/y6v0mKV0U2w0WZ2YB/++Tpockg=
465
[ssh.github.com]:443 ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOMqqnkVzrm0SdG6UOoqKLsabgH5C9okWi0dh2l9GKJl
466
[ssh.github.com]:443 ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCj7ndNxQowgcQnjshcLrqPEiiphnt+VTTvDP6mHBL9j1aNUkY4Ue1gvwnGLVlOhGeYrnZaMgRK6+PKCUXaDbC7qtbW8gIkhL7aGCsOr/C56SJMy/BCZfxd1nWzAOxSDPgVsmerOBYfNqltV9/hWCqBywINIR+5dIg6JTJ72pcEpEjcYgXkE2YEFXV1JHnsKgbLWNlhScqb2UmyRkQyytRLtL+38TGxkxCflmO+5Z8CSSNY7GidjMIZ7Q4zMjA2n1nGrlTDkzwDCsw+wqFPGQA179cnfGWOWRVruj16z6XyvxvjJwbz0wQZ75XK5tKSb7FNyeIEs4TT4jk+S4dhPeAUC5y+bDYirYgM4GC7uEnztnZyaVWQ7B381AK4Qdrwt51ZqExKbQpTUNn+EjqoTwvqNj4kqx5QUCI0ThS/YkOxJCXmPUWZbhjpCg56i+2aB6CmK2JGhn57K5mj0MNdBXA4/WnwH6XoPWJzK5Nyu2zB3nAZp+S5hpQs+p1vN1/wsjk=
467
bitbucket.org ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBPIQmuzMBuKdWeF4+a2sjSSpBK0iqitSQ+5BM9KhpexuGt20JpTVM7u5BDZngncgrqDMbWdxMWWOGtZ9UgbqgZE=
468
bitbucket.org ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIazEu89wgQZ4bqs3d63QSMzYVa0MuJ2e2gKTKqu+UUO
469
bitbucket.org ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDQeJzhupRu0u0cdegZIa8e86EG2qOCsIsD1Xw0xSeiPDlCr7kq97NLmMbpKTX6Esc30NuoqEEHCuc7yWtwp8dI76EEEB1VqY9QJq6vk+aySyboD5QF61I/1WeTwu+deCbgKMGbUijeXhtfbxSxm6JwGrXrhBdofTsbKRUsrN1WoNgUa8uqN1Vx6WAJw1JHPhglEGGHea6QICwJOAr/6mrui/oB7pkaWKHj3z7d1IC4KWLtY47elvjbaTlkN04Kc/5LFEirorGYVbt15kAUlqGM65pk6ZBxtaO3+30LVlORZkxOh+LKL/BvbZ/iRNhItLqNyieoQj/uh/7Iv4uyH/cV/0b4WDSd3DptigWq84lJubb9t/DnZlrJazxyDCulTmKdOR7vs9gMTo+uoIrPSb8ScTtvw65+odKAlBj59dhnVp9zd7QUojOpXlL62Aw56U4oO+FALuevvMjiWeavKhJqlR7i5n9srYcrNV7ttmDw7kf/97P5zauIhxcjX+xHv4M=
470
github.com ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBEmKSENjQEezOmxkZMy7opKgwFB9nkt5YRrYMjNuG5N87uRgg6CLrbo5wAdT/y6v0mKV0U2w0WZ2YB/++Tpockg=
471
github.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOMqqnkVzrm0SdG6UOoqKLsabgH5C9okWi0dh2l9GKJl
472
github.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCj7ndNxQowgcQnjshcLrqPEiiphnt+VTTvDP6mHBL9j1aNUkY4Ue1gvwnGLVlOhGeYrnZaMgRK6+PKCUXaDbC7qtbW8gIkhL7aGCsOr/C56SJMy/BCZfxd1nWzAOxSDPgVsmerOBYfNqltV9/hWCqBywINIR+5dIg6JTJ72pcEpEjcYgXkE2YEFXV1JHnsKgbLWNlhScqb2UmyRkQyytRLtL+38TGxkxCflmO+5Z8CSSNY7GidjMIZ7Q4zMjA2n1nGrlTDkzwDCsw+wqFPGQA179cnfGWOWRVruj16z6XyvxvjJwbz0wQZ75XK5tKSb7FNyeIEs4TT4jk+S4dhPeAUC5y+bDYirYgM4GC7uEnztnZyaVWQ7B381AK4Qdrwt51ZqExKbQpTUNn+EjqoTwvqNj4kqx5QUCI0ThS/YkOxJCXmPUWZbhjpCg56i+2aB6CmK2JGhn57K5mj0MNdBXA4/WnwH6XoPWJzK5Nyu2zB3nAZp+S5hpQs+p1vN1/wsjk=
473
gitlab.com ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBFSMqzJeV9rUzU4kWitGjeR4PWSa29SPqJ1fVkhtj3Hw9xjLVXVYrU9QlYWrOLXBpQ6KWjbjTDTdDkoohFzgbEY=
474
gitlab.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAfuCHKVTjquxvt6CM6tdG4SLp1Btn/nOeHHE5UOzRdf
475
gitlab.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCsj2bNKTBSpIYDEGk9KxsGh3mySTRgMtXL583qmBpzeQ+jqCMRgBqB98u3z++J1sKlXHWfM9dyhSevkMwSbhoR8XIq/U0tCNyokEi/ueaBMCvbcTHhO7FcwzY92WK4Yt0aGROY5qX2UKSeOvuP4D6TPqKF1onrSzH9bx9XUf2lEdWT/ia1NEKjunUqu1xOB/StKDHMoX4/OKyIzuS0q/T1zOATthvasJFoPrAjkohTyaDUz2LN5JoH839hViyEG82yB+MjcFV5MU3N1l1QL3cVUCh93xSaua1N85qivl+siMkPGbO5xR/En4iEY6K2XPASUEMaieWVNTRCtJ4S8H+9
476
ssh.dev.azure.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC7Hr1oTWqNqOlzGJOfGJ4NakVyIzf1rXYd4d7wo6jBlkLvCA4odBlL0mDUyZ0/QUfTTqeu+tm22gOsv+VrVTMk6vwRU75gY/y9ut5Mb3bR5BV58dKXyq9A9UeB5Cakehn5Zgm6x1mKoVyf+FFn26iYqXJRgzIZZcZ5V6hrE0Qg39kZm4az48o0AUbf6Sp4SLdvnuMa2sVNwHBboS7EJkm57XQPVU3/QpyNLHbWDdzwtrlS+ez30S3AdYhLKEOxAG8weOnyrtLJAUen9mTkol8oII1edf7mWWbWVf0nBmly21+nZcmCTISQBtdcyPaEno7fFQMDD26/s0lfKob4Kw8H
477
vs-ssh.visualstudio.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC7Hr1oTWqNqOlzGJOfGJ4NakVyIzf1rXYd4d7wo6jBlkLvCA4odBlL0mDUyZ0/QUfTTqeu+tm22gOsv+VrVTMk6vwRU75gY/y9ut5Mb3bR5BV58dKXyq9A9UeB5Cakehn5Zgm6x1mKoVyf+FFn26iYqXJRgzIZZcZ5V6hrE0Qg39kZm4az48o0AUbf6Sp4SLdvnuMa2sVNwHBboS7EJkm57XQPVU3/QpyNLHbWDdzwtrlS+ez30S3AdYhLKEOxAG8weOnyrtLJAUen9mTkol8oII1edf7mWWbWVf0nBmly21+nZcmCTISQBtdcyPaEno7fFQMDD26/s0lfKob4Kw8H
478
# -- Additional known hosts for private repositories
479
extraHosts: ""
480
# Repository TLS certificates
481
# Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/declarative-setup/#repositories-using-self-signed-tls-certificates-or-are-signed-by-custom-ca
482
tls:
483
# -- Annotations to be added to argocd-tls-certs-cm configmap
484
annotations: {}
485
# -- TLS certificates for Git repositories
486
# @default -- `{}` (See [values.yaml])
487
certificates: {}
488
# server.example.com: |
489
# -----BEGIN CERTIFICATE-----
490
# ...
491
# -----END CERTIFICATE-----
492
493
# -- Specifies if the argocd-tls-certs-cm configmap should be created by Helm.
494
create: true
495
# ConfigMap for Config Management Plugins
496
# Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/config-management-plugins/
497
cmp:
498
# -- Create the argocd-cmp-cm configmap
499
create: false
500
# -- Annotations to be added to argocd-cmp-cm configmap
501
annotations: {}
502
# -- Plugin yaml files to be added to argocd-cmp-cm
503
plugins: {}
504
# --- First plugin
505
# my-plugin:
506
# init:
507
# command: [sh]
508
# args: [-c, 'echo "Initializing..."']
509
# generate:
510
# command: [sh, -c]
511
# args:
512
# - |
513
# echo "{\"kind\": \"ConfigMap\", \"apiVersion\": \"v1\", \"metadata\": { \"name\": \"$ARGOCD_APP_NAME\", \"namespace\": \"$ARGOCD_APP_NAMESPACE\", \"annotations\": {\"Foo\": \"$ARGOCD_ENV_FOO\", \"KubeVersion\": \"$KUBE_VERSION\", \"KubeApiVersion\": \"$KUBE_API_VERSIONS\",\"Bar\": \"baz\"}}}"
514
# discover:
515
# fileName: "./subdir/s*.yaml"
516
# find:
517
# glob: "**/Chart.yaml"
518
# command: [sh, -c, find . -name env.yaml]
519
# --- Second plugin
520
# my-plugin2:
521
# init:
522
# command: [sh]
523
# args: [-c, 'echo "Initializing..."']
524
# generate:
525
# command: [sh, -c]
526
# args:
527
# - |
528
# echo "{\"kind\": \"ConfigMap\", \"apiVersion\": \"v1\", \"metadata\": { \"name\": \"$ARGOCD_APP_NAME\", \"namespace\": \"$ARGOCD_APP_NAMESPACE\", \"annotations\": {\"Foo\": \"$ARGOCD_ENV_FOO\", \"KubeVersion\": \"$KUBE_VERSION\", \"KubeApiVersion\": \"$KUBE_API_VERSIONS\",\"Bar\": \"baz\"}}}"
529
# discover:
530
# fileName: "./subdir/s*.yaml"
531
# find:
532
# glob: "**/Chart.yaml"
533
# command: [sh, -c, find . -name env.yaml]
534
535
# -- Provide one or multiple [external cluster credentials]
536
# @default -- `{}` (See [values.yaml])
537
## Ref:
538
## - https://argo-cd.readthedocs.io/en/stable/operator-manual/declarative-setup/#clusters
539
## - https://argo-cd.readthedocs.io/en/stable/operator-manual/security/#external-cluster-credentials
540
## - https://argo-cd.readthedocs.io/en/stable/user-guide/projects/#project-scoped-repositories-and-clusters
541
clusterCredentials: {}
542
# mycluster:
543
# server: https://mycluster.example.com
544
# labels: {}
545
# annotations: {}
546
# config:
547
# bearerToken: "<authentication token>"
548
# tlsClientConfig:
549
# insecure: false
550
# caData: "<base64 encoded certificate>"
551
# mycluster2:
552
# server: https://mycluster2.example.com
553
# labels: {}
554
# annotations: {}
555
# namespaces: namespace1,namespace2
556
# clusterResources: true
557
# config:
558
# bearerToken: "<authentication token>"
559
# tlsClientConfig:
560
# insecure: false
561
# caData: "<base64 encoded certificate>"
562
# mycluster3-project-scoped:
563
# server: https://mycluster3.example.com
564
# labels: {}
565
# annotations: {}
566
# project: my-project1
567
# config:
568
# bearerToken: "<authentication token>"
569
# tlsClientConfig:
570
# insecure: false
571
# caData: "<base64 encoded certificate>"
572
# mycluster4-sharded:
573
# shard: 1
574
# server: https://mycluster4.example.com
575
# labels: {}
576
# annotations: {}
577
# config:
578
# bearerToken: "<authentication token>"
579
# tlsClientConfig:
580
# insecure: false
581
# caData: "<base64 encoded certificate>"
582
583
# -- Repository credentials to be used as Templates for other repos
584
## Creates a secret for each key/value specified below to create repository credentials
585
credentialTemplates: {}
586
# github-enterprise-creds-1:
587
# url: https://github.com/argoproj
588
# githubAppID: 1
589
# githubAppInstallationID: 2
590
# githubAppEnterpriseBaseUrl: https://ghe.example.com/api/v3
591
# githubAppPrivateKey: |
592
# -----BEGIN OPENSSH PRIVATE KEY-----
593
# ...
594
# -----END OPENSSH PRIVATE KEY-----
595
# https-creds:
596
# url: https://github.com/argoproj
597
# password: my-password
598
# username: my-username
599
# ssh-creds:
600
# url: git@github.com:argoproj-labs
601
# sshPrivateKey: |
602
# -----BEGIN OPENSSH PRIVATE KEY-----
603
# ...
604
# -----END OPENSSH PRIVATE KEY-----
605
606
# -- Annotations to be added to `configs.credentialTemplates` Secret
607
credentialTemplatesAnnotations: {}
608
# -- Repositories list to be used by applications
609
## Creates a secret for each key/value specified below to create repositories
610
## Note: the last example in the list would use a repository credential template, configured under "configs.credentialTemplates".
611
repositories: {}
612
# istio-helm-repo:
613
# url: https://storage.googleapis.com/istio-prerelease/daily-build/master-latest-daily/charts
614
# name: istio.io
615
# type: helm
616
# private-helm-repo:
617
# url: https://my-private-chart-repo.internal
618
# name: private-repo
619
# type: helm
620
# password: my-password
621
# username: my-username
622
# private-repo:
623
# url: https://github.com/argoproj/private-repo
624
625
# -- Annotations to be added to `configs.repositories` Secret
626
repositoriesAnnotations: {}
627
# Argo CD sensitive data
628
# Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/user-management/#sensitive-data-and-sso-client-secrets
629
secret:
630
# -- Create the argocd-secret
631
createSecret: true
632
# -- Labels to be added to argocd-secret
633
labels: {}
634
# -- Annotations to be added to argocd-secret
635
annotations: {}
636
# -- Shared secret for authenticating GitHub webhook events
637
githubSecret: ""
638
# -- Shared secret for authenticating GitLab webhook events
639
gitlabSecret: ""
640
# -- Shared secret for authenticating BitbucketServer webhook events
641
bitbucketServerSecret: ""
642
# -- UUID for authenticating Bitbucket webhook events
643
bitbucketUUID: ""
644
# -- Shared secret for authenticating Gogs webhook events
645
gogsSecret: ""
646
## Azure DevOps
647
azureDevops:
648
# -- Shared secret username for authenticating Azure DevOps webhook events
649
username: ""
650
# -- Shared secret password for authenticating Azure DevOps webhook events
651
password: ""
652
# -- add additional secrets to be added to argocd-secret
653
## Custom secrets. Useful for injecting SSO secrets into environment variables.
654
## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/user-management/#sensitive-data-and-sso-client-secrets
655
## Note that all values must be non-empty.
656
extra: {}
657
# LDAP_PASSWORD: "mypassword"
658
659
# -- Bcrypt hashed admin password
660
## Argo expects the password in the secret to be bcrypt hashed. You can create this hash with
661
## `htpasswd -nbBC 10 "" $ARGO_PWD | tr -d ':\n' | sed 's/$2y/$2a/'`
662
argocdServerAdminPassword: ""
663
# -- Admin password modification time. Eg. `"2006-01-02T15:04:05Z"`
664
# @default -- `""` (defaults to current time)
665
argocdServerAdminPasswordMtime: ""
666
# -- Define custom [CSS styles] for your argo instance.
667
# This setting will automatically mount the provided CSS and reference it in the argo configuration.
668
# @default -- `""` (See [values.yaml])
669
## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/custom-styles/
670
styles: ""
671
# styles: |
672
# .sidebar {
673
# background: linear-gradient(to bottom, #999, #777, #333, #222, #111);
674
# }
675
# -- Array of extra K8s manifests to deploy
676
## Note: Supports use of custom Helm templates
677
extraObjects: []
678
# - apiVersion: secrets-store.csi.x-k8s.io/v1
679
# kind: SecretProviderClass
680
# metadata:
681
# name: argocd-secrets-store
682
# spec:
683
# provider: aws
684
# parameters:
685
# objects: |
686
# - objectName: "argocd"
687
# objectType: "secretsmanager"
688
# jmesPath:
689
# - path: "client_id"
690
# objectAlias: "client_id"
691
# - path: "client_secret"
692
# objectAlias: "client_secret"
693
# secretObjects:
694
# - data:
695
# - key: client_id
696
# objectName: client_id
697
# - key: client_secret
698
# objectName: client_secret
699
# secretName: argocd-secrets-store
700
# type: Opaque
701
# labels:
702
# app.kubernetes.io/part-of: argocd
703
704
## Application controller
705
controller:
706
# -- Application controller name string
707
name: application-controller
708
# -- The number of application controller pods to run.
709
# Additional replicas will cause sharding of managed clusters across number of replicas.
710
## With dynamic cluster distribution turned on, sharding of the clusters will gracefully
711
## rebalance if the number of replica's changes or one becomes unhealthy. (alpha)
712
replicas: 1
713
# -- Enable dynamic cluster distribution (alpha)
714
# Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/dynamic-cluster-distribution
715
## This is done using a deployment instead of a statefulSet
716
## When replicas are added or removed, the sharding algorithm is re-run to ensure that the
717
## clusters are distributed according to the algorithm. If the algorithm is well-balanced,
718
## like round-robin, then the shards will be well-balanced.
719
dynamicClusterDistribution: false
720
# -- Runtime class name for the application controller
721
# @default -- `""` (defaults to global.runtimeClassName)
722
runtimeClassName: ""
723
# -- Application controller heartbeat time
724
# Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/dynamic-cluster-distribution/#working-of-dynamic-distribution
725
heartbeatTime: 10
726
# -- Maximum number of controller revisions that will be maintained in StatefulSet history
727
revisionHistoryLimit: 5
728
## Application controller Pod Disruption Budget
729
## Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
730
pdb:
731
# -- Deploy a [PodDisruptionBudget] for the application controller
732
enabled: false
733
# -- Labels to be added to application controller pdb
734
labels: {}
735
# -- Annotations to be added to application controller pdb
736
annotations: {}
737
# -- Number of pods that are available after eviction as number or percentage (eg.: 50%)
738
# @default -- `""` (defaults to 0 if not specified)
739
minAvailable: ""
740
# -- Number of pods that are unavailable after eviction as number or percentage (eg.: 50%).
741
## Has higher precedence over `controller.pdb.minAvailable`
742
maxUnavailable: ""
743
# -- Policy for evicting unhealthy (not ready) pods, either `IfHealthyBudget` or `AlwaysAllow`
744
## Defaults to `IfHealthyBudget` if not set
745
unhealthyPodEvictionPolicy: ""
746
## Application controller Vertical Pod Autoscaler
747
## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/
748
vpa:
749
# -- Deploy a [VerticalPodAutoscaler](https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/) for the application controller
750
enabled: false
751
# -- Labels to be added to application controller vpa
752
labels: {}
753
# -- Annotations to be added to application controller vpa
754
annotations: {}
755
# -- One of the VPA operation modes
756
## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically
757
## Note: Recreate update mode requires more than one replica unless the min-replicas VPA controller flag is overridden
758
updateMode: Initial
759
# -- Controls how VPA computes the recommended resources for application controller container
760
## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/examples/hamster.yaml
761
containerPolicy: {}
762
# controlledResources: ["cpu", "memory"]
763
# minAllowed:
764
# cpu: 250m
765
# memory: 256Mi
766
# maxAllowed:
767
# cpu: 1
768
# memory: 1Gi
769
# -- The recommenders that will provide recommendations for vertical scaling. Only relevant if a named VPA recommender (e.g. one started with a custom recommender name) is in use; leave unset to use the cluster's default recommender
770
## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/docs/api.md#verticalpodautoscalerspec
771
## NOTE: specify only zero or one recommender as of VPA 1.7.1
772
recommenders: []
773
# -- Configures a startup resource boost for faster cold-start (application boot) resource allocation. NOTE: startupBoost is currently a GKE-specific extension to the VPA API and is only honored on GKE clusters; it is rendered only when set
774
## Ref: https://cloud.google.com/kubernetes-engine/docs/how-to/boost-application-startup
775
startupBoost: {}
776
# cpu:
777
# type: Factor
778
# factor: 2
779
# durationSeconds: 10
780
## Application controller image
781
image:
782
# -- Repository to use for the application controller
783
# @default -- `""` (defaults to global.image.repository)
784
repository: ""
785
# -- Tag to use for the application controller
786
# @default -- `""` (defaults to global.image.tag)
787
tag: ""
788
# -- Image pull policy for the application controller
789
# @default -- `""` (defaults to global.image.imagePullPolicy)
790
imagePullPolicy: ""
791
# -- Secrets with credentials to pull images from a private registry
792
# @default -- `[]` (defaults to global.imagePullSecrets)
793
imagePullSecrets: []
794
# -- Additional command line arguments to pass to application controller
795
extraArgs: []
796
# -- Environment variables to pass to application controller
797
env: []
798
# -- envFrom to pass to application controller
799
# @default -- `[]` (See [values.yaml])
800
envFrom: []
801
# - configMapRef:
802
# name: config-map-name
803
# - secretRef:
804
# name: secret-name
805
806
# -- Additional containers to be added to the application controller pod
807
## Note: Supports use of custom Helm templates
808
extraContainers: []
809
# -- Init containers to add to the application controller pod
810
## If your target Kubernetes cluster(s) require a custom credential (exec) plugin
811
## you could use this (and the same in the server pod) to provide such executable
812
## Ref: https://kubernetes.io/docs/reference/access-authn-authz/authentication/#client-go-credential-plugins
813
## Note: Supports use of custom Helm templates
814
initContainers: []
815
# - name: download-tools
816
# image: alpine:3
817
# command: [sh, -c]
818
# args:
819
# - wget -qO /custom-tools/kubelogin.zip https://github.com/Azure/kubelogin/releases/download/v0.2.7/kubelogin-linux-amd64.zip &&
820
# mkdir /custom-tools/tmp && unzip -d /custom-tools/tmp /custom-tools/kubelogin.zip &&
821
# mv /custom-tools/tmp/bin/linux_amd64/kubelogin /custom-tools/ && rm -rf custom-tools/tmp && rm /custom-tools/kubelogin.zip
822
# volumeMounts:
823
# - mountPath: /custom-tools
824
# name: custom-tools
825
826
# -- Additional volumeMounts to the application controller main container
827
volumeMounts: []
828
# - mountPath: /usr/local/bin/kubelogin
829
# name: custom-tools
830
# subPath: kubelogin
831
832
# -- Additional volumes to the application controller pod
833
volumes: []
834
# - name: custom-tools
835
# emptyDir: {}
836
837
## Application controller emptyDir volumes
838
emptyDir:
839
# -- EmptyDir size limit for application controller
840
# @default -- `""` (defaults not set if not specified i.e. no size limit)
841
sizeLimit: ""
842
# sizeLimit: "1Gi"
843
# -- Annotations for the application controller StatefulSet
844
statefulsetAnnotations: {}
845
# -- Labels for the application controller StatefulSet
846
statefulsetLabels: {}
847
# -- Annotations for the application controller Deployment
848
deploymentAnnotations: {}
849
# -- Labels for the application controller Deployment
850
deploymentLabels: {}
851
# -- Annotations to be added to application controller pods
852
podAnnotations: {}
853
# -- Labels to be added to application controller pods
854
podLabels: {}
855
# -- Resource limits and requests for the application controller pods
856
resources: {}
857
# limits:
858
# cpu: 500m
859
# memory: 512Mi
860
# requests:
861
# cpu: 250m
862
# memory: 256Mi
863
864
# Application controller container ports
865
containerPorts:
866
# -- Metrics container port
867
metrics: 8082
868
# -- Host Network for application controller pods
869
hostNetwork: false
870
# -- [DNS configuration]
871
dnsConfig: {}
872
# -- Alternative DNS policy for application controller pods
873
dnsPolicy: "ClusterFirst"
874
# -- Application controller container-level security context
875
# @default -- See [values.yaml]
876
containerSecurityContext:
877
runAsNonRoot: true
878
readOnlyRootFilesystem: true
879
allowPrivilegeEscalation: false
880
seccompProfile:
881
type: RuntimeDefault
882
capabilities:
883
drop:
884
- ALL
885
# Readiness probe for application controller
886
## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
887
readinessProbe:
888
# -- Http path to use for the readiness probe
889
httpPath: /healthz
890
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
891
failureThreshold: 3
892
# -- Number of seconds after the container has started before [probe] is initiated
893
initialDelaySeconds: 10
894
# -- How often (in seconds) to perform the [probe]
895
periodSeconds: 10
896
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
897
successThreshold: 1
898
# -- Number of seconds after which the [probe] times out
899
timeoutSeconds: 1
900
## Liveness probe for the application controller.
901
## Disabled by default, matching upstream: Argo CD removed this probe deliberately
902
## (argoproj/argo-cd#9557) because restarting an overloaded controller usually makes
903
## things worse. Enable only if you have a known failure mode (e.g. deadlock) where
904
## a restart is the correct remediation, and size the thresholds generously.
905
## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
906
livenessProbe:
907
# -- Enable Kubernetes liveness probe for Application controller
908
enabled: false
909
# -- Http path to use for the liveness probe
910
httpPath: /healthz
911
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
912
failureThreshold: 5
913
# -- Number of seconds after the container has started before [probe] is initiated
914
initialDelaySeconds: 10
915
# -- How often (in seconds) to perform the [probe]
916
periodSeconds: 30
917
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
918
successThreshold: 1
919
# -- Number of seconds after which the [probe] times out
920
timeoutSeconds: 5
921
## Startup probe for application controller (optional)
922
## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
923
startupProbe:
924
# -- Enable Kubernetes startup probe for application controller
925
enabled: false
926
# -- Http path to use for the startup probe
927
httpPath: /healthz
928
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
929
failureThreshold: 20
930
# -- Number of seconds after the container has started before [probe] is initiated
931
initialDelaySeconds: 10
932
# -- How often (in seconds) to perform the [probe]
933
periodSeconds: 10
934
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
935
successThreshold: 1
936
# -- Number of seconds after which the [probe] times out
937
timeoutSeconds: 1
938
# -- terminationGracePeriodSeconds for container lifecycle hook
939
terminationGracePeriodSeconds: 30
940
# -- Priority class for the application controller pods
941
# @default -- `""` (defaults to global.priorityClassName)
942
priorityClassName: ""
943
# -- [Node selector]
944
# @default -- `{}` (defaults to global.nodeSelector)
945
nodeSelector: {}
946
# -- [Tolerations] for use with node taints
947
# @default -- `[]` (defaults to global.tolerations)
948
tolerations: []
949
# -- Assign custom [affinity] rules to the deployment
950
# @default -- `{}` (defaults to global.affinity preset)
951
affinity: {}
952
# -- Assign custom [TopologySpreadConstraints] rules to the application controller
953
# @default -- `[]` (defaults to global.topologySpreadConstraints)
954
## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
955
## If labelSelector is left out, it will default to the labelSelector configuration of the deployment
956
topologySpreadConstraints: []
957
# - maxSkew: 1
958
# topologyKey: topology.kubernetes.io/zone
959
# whenUnsatisfiable: DoNotSchedule
960
961
# -- Automount API credentials for the Service Account into the pod.
962
automountServiceAccountToken: true
963
serviceAccount:
964
# -- Create a service account for the application controller
965
create: true
966
# -- Service account name
967
name: argocd-application-controller
968
# -- Annotations applied to created service account
969
annotations: {}
970
# -- Labels applied to created service account
971
labels: {}
972
# -- Automount API credentials for the Service Account
973
automountServiceAccountToken: true
974
## Application controller metrics configuration
975
metrics:
976
# -- Deploy metrics service
977
enabled: false
978
applicationLabels:
979
# -- Enables additional labels in argocd_app_labels metric
980
enabled: false
981
# -- Additional labels
982
labels: []
983
service:
984
# -- Metrics service type
985
type: ClusterIP
986
# -- Metrics service clusterIP. `None` makes a "headless service" (no virtual IP)
987
clusterIP: ""
988
# -- Metrics service annotations
989
annotations: {}
990
# -- Metrics service labels
991
labels: {}
992
# -- Metrics service port
993
servicePort: 8082
994
# -- Metrics service port name
995
portName: http-metrics
996
serviceMonitor:
997
# -- Enable a prometheus ServiceMonitor
998
enabled: false
999
# -- Prometheus ServiceMonitor interval
1000
interval: 30s
1001
# -- Prometheus ServiceMonitor scrapeTimeout. If empty, Prometheus uses the global scrape timeout unless it is less than the target's scrape interval value in which the latter is used.
1002
scrapeTimeout: ""
1003
# -- When true, honorLabels preserves the metric’s labels when they collide with the target’s labels.
1004
honorLabels: false
1005
# -- Prometheus [RelabelConfigs] to apply to samples before scraping
1006
relabelings: []
1007
# -- Prometheus [MetricRelabelConfigs] to apply to samples before ingestion
1008
metricRelabelings: []
1009
# -- Prometheus ServiceMonitor selector
1010
selector: {}
1011
# prometheus: kube-prometheus
1012
1013
# -- Prometheus ServiceMonitor scheme
1014
scheme: ""
1015
# -- Prometheus ServiceMonitor tlsConfig
1016
tlsConfig: {}
1017
# -- Prometheus ServiceMonitor namespace
1018
namespace: "" # "monitoring"
1019
# -- Prometheus ServiceMonitor labels
1020
additionalLabels: {}
1021
# -- Prometheus ServiceMonitor annotations
1022
annotations: {}
1023
rules:
1024
# -- Deploy a PrometheusRule for the application controller
1025
enabled: false
1026
# -- PrometheusRule namespace
1027
namespace: "" # "monitoring"
1028
# -- PrometheusRule selector
1029
selector: {}
1030
# prometheus: kube-prometheus
1031
1032
# -- PrometheusRule labels
1033
additionalLabels: {}
1034
# -- PrometheusRule annotations
1035
annotations: {}
1036
# -- PrometheusRule.Spec for the application controller
1037
spec: []
1038
# - alert: ArgoAppMissing
1039
# expr: |
1040
# absent(argocd_app_info) == 1
1041
# for: 15m
1042
# labels:
1043
# severity: critical
1044
# annotations:
1045
# summary: "[Argo CD] No reported applications"
1046
# description: >
1047
# Argo CD has not reported any applications data for the past 15 minutes which
1048
# means that it must be down or not functioning properly. This needs to be
1049
# resolved for this cloud to continue to maintain state.
1050
# - alert: ArgoAppNotSynced
1051
# expr: |
1052
# argocd_app_info{sync_status!="Synced"} == 1
1053
# for: 12h
1054
# labels:
1055
# severity: warning
1056
# annotations:
1057
# summary: "[{{ $labels.name }}] Application not synchronized"
1058
# description: >
1059
# The application {{ $labels.name }} has not been synchronized for over
1060
# 12 hours which means that the state of this cloud has drifted away from the
1061
# state inside Git.
1062
## Enable this and set the rules: to whatever custom rules you want for the Cluster Role resource.
1063
## Defaults to off
1064
clusterRoleRules:
1065
# -- Enable custom rules for the application controller's ClusterRole resource
1066
enabled: false
1067
# -- List of custom rules for the application controller's ClusterRole resource
1068
rules: []
1069
## Enable this and set the rules: to whatever custom rules you want for the Role resource.
1070
## Defaults to off
1071
# -- List of custom rules for the application controller's Role resource
1072
roleRules: []
1073
# Default application controller's network policy
1074
networkPolicy:
1075
# -- Default network policy rules used by application controller
1076
# @default -- `false` (defaults to global.networkPolicy.create)
1077
create: false
1078
## Dex
1079
dex:
1080
# -- Enable dex
1081
enabled: true
1082
# -- Dex name
1083
name: dex-server
1084
# -- Additional command line arguments to pass to the Dex server
1085
extraArgs: []
1086
# -- Runtime class name for Dex
1087
# @default -- `""` (defaults to global.runtimeClassName)
1088
runtimeClassName: ""
1089
metrics:
1090
# -- Deploy metrics service
1091
enabled: false
1092
service:
1093
# -- Metrics service annotations
1094
annotations: {}
1095
# -- Metrics service labels
1096
labels: {}
1097
# -- Metrics service port name
1098
portName: http-metrics
1099
serviceMonitor:
1100
# -- Enable a prometheus ServiceMonitor
1101
enabled: false
1102
# -- Prometheus ServiceMonitor interval
1103
interval: 30s
1104
# -- When true, honorLabels preserves the metric’s labels when they collide with the target’s labels.
1105
honorLabels: false
1106
# -- Prometheus [RelabelConfigs] to apply to samples before scraping
1107
relabelings: []
1108
# -- Prometheus [MetricRelabelConfigs] to apply to samples before ingestion
1109
metricRelabelings: []
1110
# -- Prometheus ServiceMonitor selector
1111
selector: {}
1112
# prometheus: kube-prometheus
1113
1114
# -- Prometheus ServiceMonitor scheme
1115
scheme: ""
1116
# -- Prometheus ServiceMonitor tlsConfig
1117
tlsConfig: {}
1118
# -- Prometheus ServiceMonitor namespace
1119
namespace: "" # "monitoring"
1120
# -- Prometheus ServiceMonitor labels
1121
additionalLabels: {}
1122
# -- Prometheus ServiceMonitor annotations
1123
annotations: {}
1124
## Dex Pod Disruption Budget
1125
## Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
1126
pdb:
1127
# -- Deploy a [PodDisruptionBudget] for the Dex server
1128
enabled: false
1129
# -- Labels to be added to Dex server pdb
1130
labels: {}
1131
# -- Annotations to be added to Dex server pdb
1132
annotations: {}
1133
# -- Number of pods that are available after eviction as number or percentage (eg.: 50%)
1134
# @default -- `""` (defaults to 0 if not specified)
1135
minAvailable: ""
1136
# -- Number of pods that are unavailble after eviction as number or percentage (eg.: 50%).
1137
## Has higher precedence over `dex.pdb.minAvailable`
1138
maxUnavailable: ""
1139
# -- Policy for evicting unhealthy (not ready) pods, either `IfHealthyBudget` or `AlwaysAllow`
1140
## Defaults to `IfHealthyBudget` if not set
1141
unhealthyPodEvictionPolicy: ""
1142
## Dex Vertical Pod Autoscaler
1143
## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/
1144
vpa:
1145
# -- Deploy a [VerticalPodAutoscaler](https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/) for the Dex server
1146
enabled: false
1147
# -- Labels to be added to Dex server vpa
1148
labels: {}
1149
# -- Annotations to be added to Dex server vpa
1150
annotations: {}
1151
# -- One of the VPA operation modes
1152
## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically
1153
## Note: Recreate update mode requires more than one replica unless the min-replicas VPA controller flag is overridden
1154
updateMode: Initial
1155
# -- Controls how VPA computes the recommended resources for Dex server container
1156
## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/examples/hamster.yaml
1157
containerPolicy: {}
1158
# controlledResources: ["cpu", "memory"]
1159
# minAllowed:
1160
# cpu: 250m
1161
# memory: 256Mi
1162
# maxAllowed:
1163
# cpu: 1
1164
# memory: 1Gi
1165
# -- The recommenders that will provide recommendations for vertical scaling. Only relevant if a named VPA recommender (e.g. one started with a custom recommender name) is in use; leave unset to use the cluster's default recommender
1166
## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/docs/api.md#verticalpodautoscalerspec
1167
## NOTE: specify only zero or one recommender as of VPA 1.7.1
1168
recommenders: []
1169
# -- Configures a startup resource boost for faster cold-start (application boot) resource allocation. NOTE: startupBoost is currently a GKE-specific extension to the VPA API and is only honored on GKE clusters; it is rendered only when set
1170
## Ref: https://cloud.google.com/kubernetes-engine/docs/how-to/boost-application-startup
1171
startupBoost: {}
1172
# cpu:
1173
# type: Factor
1174
# factor: 2
1175
# durationSeconds: 10
1176
## Dex image
1177
image:
1178
# -- Dex image repository
1179
repository: chainreg.biz/chainguard-private/dex
1180
# -- Dex image tag
1181
tag: 2.45.1-r27@sha256:61e8175f9645dd939109102c8e3fe5dd128208896d78d1c08cac67f452eda414
1182
# -- Dex imagePullPolicy
1183
# @default -- `""` (defaults to global.image.imagePullPolicy)
1184
imagePullPolicy: ""
1185
# -- Secrets with credentials to pull images from a private registry
1186
# @default -- `[]` (defaults to global.imagePullSecrets)
1187
imagePullSecrets: []
1188
# Argo CD init image that creates Dex config
1189
initImage:
1190
# -- Argo CD init image repository
1191
# @default -- `""` (defaults to global.image.repository)
1192
repository: ""
1193
# -- Argo CD init image tag
1194
# @default -- `""` (defaults to global.image.tag)
1195
tag: ""
1196
# -- Argo CD init image imagePullPolicy
1197
# @default -- `""` (defaults to global.image.imagePullPolicy)
1198
imagePullPolicy: ""
1199
# -- Argo CD init image resources
1200
# @default -- `{}` (defaults to dex.resources)
1201
resources: {}
1202
# requests:
1203
# cpu: 5m
1204
# memory: 96Mi
1205
# limits:
1206
# cpu: 10m
1207
# memory: 144Mi
1208
# -- Environment variables to pass to the Dex server
1209
env: []
1210
# -- envFrom to pass to the Dex server
1211
# @default -- `[]` (See [values.yaml])
1212
envFrom: []
1213
# - configMapRef:
1214
# name: config-map-name
1215
# - secretRef:
1216
# name: secret-name
1217
1218
# -- Additional containers to be added to the dex pod
1219
## Note: Supports use of custom Helm templates
1220
extraContainers: []
1221
# -- Init containers to add to the dex pod
1222
## Note: Supports use of custom Helm templates
1223
initContainers: []
1224
# -- Additional volumeMounts to the dex main container
1225
volumeMounts: []
1226
# -- Additional volumes to the dex pod
1227
volumes: []
1228
## Dex server emptyDir volumes
1229
emptyDir:
1230
# -- EmptyDir size limit for Dex server
1231
# @default -- `""` (defaults not set if not specified i.e. no size limit)
1232
sizeLimit: ""
1233
# sizeLimit: "1Gi"
1234
# TLS certificate configuration via Secret
1235
## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/tls/#configuring-tls-to-argocd-dex-server
1236
## Note: Issuing certificates via cert-manager in not supported right now because it's not possible to restart Dex automatically without extra controllers.
1237
certificateSecret:
1238
# -- Create argocd-dex-server-tls secret
1239
enabled: false
1240
# -- Labels to be added to argocd-dex-server-tls secret
1241
labels: {}
1242
# -- Annotations to be added to argocd-dex-server-tls secret
1243
annotations: {}
1244
# -- Certificate authority. Required for self-signed certificates.
1245
ca: ""
1246
# -- Certificate private key
1247
key: ""
1248
# -- Certificate data. Must contain SANs of Dex service (ie: argocd-dex-server, argocd-dex-server.argo-cd.svc)
1249
crt: ""
1250
# -- Annotations to be added to the Dex server Deployment
1251
deploymentAnnotations: {}
1252
# -- Labels for the Dex server Deployment
1253
deploymentLabels: {}
1254
# -- Annotations to be added to the Dex server pods
1255
podAnnotations: {}
1256
# -- Labels to be added to the Dex server pods
1257
podLabels: {}
1258
# -- Resource limits and requests for dex
1259
resources: {}
1260
# limits:
1261
# cpu: 50m
1262
# memory: 64Mi
1263
# requests:
1264
# cpu: 10m
1265
# memory: 32Mi
1266
1267
# Dex container ports
1268
# NOTE: These ports are currently hardcoded and cannot be changed
1269
containerPorts:
1270
# -- HTTP container port
1271
http: 5556
1272
# -- gRPC container port
1273
grpc: 5557
1274
# -- Metrics container port
1275
metrics: 5558
1276
# -- [DNS configuration]
1277
dnsConfig: {}
1278
# -- Alternative DNS policy for Dex server pods
1279
dnsPolicy: "ClusterFirst"
1280
# -- Dex container-level security context
1281
# @default -- See [values.yaml]
1282
containerSecurityContext:
1283
runAsNonRoot: true
1284
runAsUser: 1001
1285
readOnlyRootFilesystem: true
1286
allowPrivilegeEscalation: false
1287
seccompProfile:
1288
type: RuntimeDefault
1289
capabilities:
1290
drop:
1291
- ALL
1292
## Probes for Dex server
1293
## Supported from Dex >= 2.28.0
1294
livenessProbe:
1295
# -- Enable Kubernetes liveness probe for Dex >= 2.28.0
1296
enabled: false
1297
# -- Http path to use for the liveness probe
1298
httpPath: /healthz/live
1299
# -- Http port to use for the liveness probe
1300
httpPort: metrics
1301
# -- Scheme to use for for the liveness probe (can be HTTP or HTTPS)
1302
httpScheme: HTTP
1303
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
1304
failureThreshold: 3
1305
# -- Number of seconds after the container has started before [probe] is initiated
1306
initialDelaySeconds: 10
1307
# -- How often (in seconds) to perform the [probe]
1308
periodSeconds: 10
1309
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
1310
successThreshold: 1
1311
# -- Number of seconds after which the [probe] times out
1312
timeoutSeconds: 1
1313
readinessProbe:
1314
# -- Enable Kubernetes readiness probe for Dex >= 2.28.0
1315
enabled: false
1316
# -- Http path to use for the readiness probe
1317
httpPath: /healthz/ready
1318
# -- Http port to use for the readiness probe
1319
httpPort: metrics
1320
# -- Scheme to use for for the liveness probe (can be HTTP or HTTPS)
1321
httpScheme: HTTP
1322
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
1323
failureThreshold: 3
1324
# -- Number of seconds after the container has started before [probe] is initiated
1325
initialDelaySeconds: 10
1326
# -- How often (in seconds) to perform the [probe]
1327
periodSeconds: 10
1328
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
1329
successThreshold: 1
1330
# -- Number of seconds after which the [probe] times out
1331
timeoutSeconds: 1
1332
## Startup probe for Dex server (optional)
1333
## Supported from Dex >= 2.28.0
1334
startupProbe:
1335
# -- Enable Kubernetes startup probe for Dex >= 2.28.0
1336
enabled: false
1337
# -- Http path to use for the startup probe
1338
httpPath: /healthz/ready
1339
# -- Http port to use for the startup probe
1340
httpPort: metrics
1341
# -- Scheme to use for the startup probe (can be HTTP or HTTPS)
1342
httpScheme: HTTP
1343
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
1344
failureThreshold: 20
1345
# -- Number of seconds after the container has started before [probe] is initiated
1346
initialDelaySeconds: 10
1347
# -- How often (in seconds) to perform the [probe]
1348
periodSeconds: 10
1349
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
1350
successThreshold: 1
1351
# -- Number of seconds after which the [probe] times out
1352
timeoutSeconds: 1
1353
# -- terminationGracePeriodSeconds for container lifecycle hook
1354
terminationGracePeriodSeconds: 30
1355
# -- Automount API credentials for the Service Account into the pod.
1356
automountServiceAccountToken: true
1357
serviceAccount:
1358
# -- Create dex service account
1359
create: true
1360
# -- Dex service account name
1361
name: argocd-dex-server
1362
# -- Annotations applied to created service account
1363
annotations: {}
1364
# -- Automount API credentials for the Service Account
1365
automountServiceAccountToken: true
1366
# -- Service port for HTTP access
1367
servicePortHttp: 5556
1368
# -- Service port name for HTTP access
1369
servicePortHttpName: http
1370
# -- Service port for gRPC access
1371
servicePortGrpc: 5557
1372
# -- Service port name for gRPC access
1373
servicePortGrpcName: grpc
1374
# -- Service port for metrics access
1375
servicePortMetrics: 5558
1376
# -- Priority class for the dex pods
1377
# @default -- `""` (defaults to global.priorityClassName)
1378
priorityClassName: ""
1379
# -- [Node selector]
1380
# @default -- `{}` (defaults to global.nodeSelector)
1381
nodeSelector: {}
1382
# -- [Tolerations] for use with node taints
1383
# @default -- `[]` (defaults to global.tolerations)
1384
tolerations: []
1385
# -- Assign custom [affinity] rules to the deployment
1386
# @default -- `{}` (defaults to global.affinity preset)
1387
affinity: {}
1388
# -- Assign custom [TopologySpreadConstraints] rules to dex
1389
# @default -- `[]` (defaults to global.topologySpreadConstraints)
1390
## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
1391
## If labelSelector is left out, it will default to the labelSelector configuration of the deployment
1392
topologySpreadConstraints: []
1393
# - maxSkew: 1
1394
# topologyKey: topology.kubernetes.io/zone
1395
# whenUnsatisfiable: DoNotSchedule
1396
1397
# -- Deployment strategy to be added to the Dex server Deployment
1398
deploymentStrategy: {}
1399
# type: RollingUpdate
1400
# rollingUpdate:
1401
# maxSurge: 25%
1402
# maxUnavailable: 25%
1403
1404
# Default Dex server's network policy
1405
networkPolicy:
1406
# -- Default network policy rules used by Dex server
1407
# @default -- `false` (defaults to global.networkPolicy.create)
1408
create: false
1409
# DEPRECATED - Use configs.params to override
1410
# -- Dex log format. Either `text` or `json`
1411
# @default -- `""` (defaults to global.logging.format)
1412
# logFormat: ""
1413
# -- Dex log level. One of: `debug`, `info`, `warn`, `error`
1414
# @default -- `""` (defaults to global.logging.level)
1415
# logLevel: ""
1416
## Redis
1417
redis:
1418
# -- Enable redis
1419
enabled: true
1420
# -- Redis name
1421
name: redis
1422
# -- Runtime class name for redis
1423
# @default -- `""` (defaults to global.runtimeClassName)
1424
runtimeClassName: ""
1425
# -- Existing Secret name for the embedded Redis password. The Secret must contain the key `auth`.
1426
# Only used when `redisSecretInit.enabled` is `false`, otherwise the secret name is `argocd-redis`.
1427
# Only applies to the single node Redis deployment. With `redis-ha.enabled` use `redis-ha.existingSecret` instead,
1428
# and for external Redis use `externalRedis.existingSecret`.
1429
existingSecret: ""
1430
## Redis Pod Disruption Budget
1431
## Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
1432
pdb:
1433
# -- Deploy a [PodDisruptionBudget] for the Redis
1434
enabled: false
1435
# -- Labels to be added to Redis pdb
1436
labels: {}
1437
# -- Annotations to be added to Redis pdb
1438
annotations: {}
1439
# -- Number of pods that are available after eviction as number or percentage (eg.: 50%)
1440
# @default -- `""` (defaults to 0 if not specified)
1441
minAvailable: ""
1442
# -- Number of pods that are unavailble after eviction as number or percentage (eg.: 50%).
1443
## Has higher precedence over `redis.pdb.minAvailable`
1444
maxUnavailable: ""
1445
# -- Policy for evicting unhealthy (not ready) pods, either `IfHealthyBudget` or `AlwaysAllow`
1446
## Defaults to `IfHealthyBudget` if not set
1447
unhealthyPodEvictionPolicy: ""
1448
## Redis Vertical Pod Autoscaler
1449
## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/
1450
vpa:
1451
# -- Deploy a [VerticalPodAutoscaler](https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/) for the Redis
1452
enabled: false
1453
# -- Labels to be added to Redis vpa
1454
labels: {}
1455
# -- Annotations to be added to Redis vpa
1456
annotations: {}
1457
# -- One of the VPA operation modes
1458
## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically
1459
## Note: Recreate update mode requires more than one replica unless the min-replicas VPA controller flag is overridden
1460
updateMode: Initial
1461
# -- Controls how VPA computes the recommended resources for Redis container
1462
## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/examples/hamster.yaml
1463
containerPolicy: {}
1464
# controlledResources: ["cpu", "memory"]
1465
# minAllowed:
1466
# cpu: 250m
1467
# memory: 256Mi
1468
# maxAllowed:
1469
# cpu: 1
1470
# memory: 1Gi
1471
# -- The recommenders that will provide recommendations for vertical scaling. Only relevant if a named VPA recommender (e.g. one started with a custom recommender name) is in use; leave unset to use the cluster's default recommender
1472
## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/docs/api.md#verticalpodautoscalerspec
1473
## NOTE: specify only zero or one recommender as of VPA 1.7.1
1474
recommenders: []
1475
# -- Configures a startup resource boost for faster cold-start (application boot) resource allocation. NOTE: startupBoost is currently a GKE-specific extension to the VPA API and is only honored on GKE clusters; it is rendered only when set
1476
## Ref: https://cloud.google.com/kubernetes-engine/docs/how-to/boost-application-startup
1477
startupBoost: {}
1478
# cpu:
1479
# type: Factor
1480
# factor: 2
1481
# durationSeconds: 10
1482
## Redis image
1483
image:
1484
# -- Redis repository
1485
repository: chainreg.biz/chainguard-private/redis
1486
# -- Redis tag
1487
## Do not use 7.4.0 <= v < 8.0.0, otherwise you are no longer using an open source version of Redis
1488
tag: 8.10.2-r1@sha256:56d959dee32a2fd17c6c43400b727c346acc584735d9f3c73788d20fdf37e8be
1489
# -- Redis image pull policy
1490
# @default -- `""` (defaults to global.image.imagePullPolicy)
1491
imagePullPolicy: ""
1492
## Prometheus redis-exporter sidecar
1493
exporter:
1494
# -- Enable Prometheus redis-exporter sidecar
1495
enabled: false
1496
# -- Environment variables to pass to the Redis exporter
1497
env: []
1498
## Prometheus redis-exporter image
1499
image:
1500
# -- Repository to use for the redis-exporter
1501
repository: chainreg.biz/chainguard-private/prometheus-redis-exporter
1502
# -- Tag to use for the redis-exporter
1503
tag: 1.93.0-r0@sha256:02d6b26bed0db89b43ed9533d7c94fe9e84cc4f8b1ee3498c711e82ff4f575f5
1504
# -- Image pull policy for the redis-exporter
1505
# @default -- `""` (defaults to global.image.imagePullPolicy)
1506
imagePullPolicy: ""
1507
# -- Redis exporter security context
1508
# @default -- See [values.yaml]
1509
containerSecurityContext:
1510
runAsNonRoot: true
1511
readOnlyRootFilesystem: true
1512
allowPrivilegeEscalation: false
1513
seccompProfile:
1514
type: RuntimeDefault
1515
capabilities:
1516
drop:
1517
- ALL
1518
## Probes for Redis exporter (optional)
1519
## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
1520
readinessProbe:
1521
# -- Enable Kubernetes liveness probe for Redis exporter (optional)
1522
enabled: false
1523
# -- Number of seconds after the container has started before [probe] is initiated
1524
initialDelaySeconds: 30
1525
# -- How often (in seconds) to perform the [probe]
1526
periodSeconds: 15
1527
# -- Number of seconds after which the [probe] times out
1528
timeoutSeconds: 15
1529
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
1530
successThreshold: 1
1531
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
1532
failureThreshold: 5
1533
livenessProbe:
1534
# -- Enable Kubernetes liveness probe for Redis exporter
1535
enabled: false
1536
# -- Number of seconds after the container has started before [probe] is initiated
1537
initialDelaySeconds: 30
1538
# -- How often (in seconds) to perform the [probe]
1539
periodSeconds: 15
1540
# -- Number of seconds after which the [probe] times out
1541
timeoutSeconds: 15
1542
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
1543
successThreshold: 1
1544
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
1545
failureThreshold: 5
1546
# -- Resource limits and requests for redis-exporter sidecar
1547
resources: {}
1548
# limits:
1549
# cpu: 50m
1550
# memory: 64Mi
1551
# requests:
1552
# cpu: 10m
1553
# memory: 32Mi
1554
# -- Secrets with credentials to pull images from a private registry
1555
# @default -- `[]` (defaults to global.imagePullSecrets)
1556
imagePullSecrets: []
1557
# -- Additional command line arguments to pass to redis-server
1558
extraArgs: []
1559
# - --bind
1560
# - "0.0.0.0"
1561
1562
# -- Environment variables to pass to the Redis server
1563
env: []
1564
# -- envFrom to pass to the Redis server
1565
# @default -- `[]` (See [values.yaml])
1566
envFrom: []
1567
# - configMapRef:
1568
# name: config-map-name
1569
# - secretRef:
1570
# name: secret-name
1571
1572
## Probes for Redis server (optional)
1573
## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
1574
readinessProbe:
1575
# -- Enable Kubernetes liveness probe for Redis server
1576
enabled: false
1577
# -- Number of seconds after the container has started before [probe] is initiated
1578
initialDelaySeconds: 30
1579
# -- How often (in seconds) to perform the [probe]
1580
periodSeconds: 15
1581
# -- Number of seconds after which the [probe] times out
1582
timeoutSeconds: 15
1583
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
1584
successThreshold: 1
1585
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
1586
failureThreshold: 5
1587
livenessProbe:
1588
# -- Enable Kubernetes liveness probe for Redis server
1589
enabled: false
1590
# -- Number of seconds after the container has started before [probe] is initiated
1591
initialDelaySeconds: 30
1592
# -- How often (in seconds) to perform the [probe]
1593
periodSeconds: 15
1594
# -- Number of seconds after which the [probe] times out
1595
timeoutSeconds: 15
1596
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
1597
successThreshold: 1
1598
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
1599
failureThreshold: 5
1600
# -- Additional containers to be added to the redis pod
1601
## Note: Supports use of custom Helm templates
1602
extraContainers: []
1603
# -- Init containers to add to the redis pod
1604
## Note: Supports use of custom Helm templates
1605
initContainers: []
1606
# -- Additional volumeMounts to the redis container
1607
volumeMounts: []
1608
# -- Additional volumes to the redis pod
1609
volumes: []
1610
# -- Annotations to be added to the Redis server Deployment
1611
deploymentAnnotations: {}
1612
# -- Labels for the Redis server Deployment
1613
deploymentLabels: {}
1614
# -- Annotations to be added to the Redis server pods
1615
podAnnotations: {}
1616
# -- Labels to be added to the Redis server pods
1617
podLabels: {}
1618
# -- Resource limits and requests for redis
1619
resources: {}
1620
# limits:
1621
# cpu: 200m
1622
# memory: 128Mi
1623
# requests:
1624
# cpu: 100m
1625
# memory: 64Mi
1626
1627
# -- Redis pod-level security context
1628
# @default -- See [values.yaml]
1629
securityContext:
1630
runAsNonRoot: true
1631
runAsUser: 999
1632
seccompProfile:
1633
type: RuntimeDefault
1634
# Redis container ports
1635
containerPorts:
1636
# -- Redis container port
1637
redis: 6379
1638
# -- Metrics container port
1639
metrics: 9121
1640
# -- Host Network for redis pods
1641
hostNetwork: false
1642
# -- [DNS configuration]
1643
dnsConfig: {}
1644
# -- Alternative DNS policy for Redis server pods
1645
dnsPolicy: "ClusterFirst"
1646
# -- Redis container-level security context
1647
# @default -- See [values.yaml]
1648
containerSecurityContext:
1649
readOnlyRootFilesystem: true
1650
allowPrivilegeEscalation: false
1651
capabilities:
1652
drop:
1653
- ALL
1654
# -- Redis service port
1655
servicePort: 6379
1656
# -- Priority class for redis pods
1657
# @default -- `""` (defaults to global.priorityClassName)
1658
priorityClassName: ""
1659
# -- [Node selector]
1660
# @default -- `{}` (defaults to global.nodeSelector)
1661
nodeSelector: {}
1662
# -- [Tolerations] for use with node taints
1663
# @default -- `[]` (defaults to global.tolerations)
1664
tolerations: []
1665
# -- Assign custom [affinity] rules to the deployment
1666
# @default -- `{}` (defaults to global.affinity preset)
1667
affinity: {}
1668
# -- Assign custom [TopologySpreadConstraints] rules to redis
1669
# @default -- `[]` (defaults to global.topologySpreadConstraints)
1670
## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
1671
## If labelSelector is left out, it will default to the labelSelector configuration of the deployment
1672
topologySpreadConstraints: []
1673
# - maxSkew: 1
1674
# topologyKey: topology.kubernetes.io/zone
1675
# whenUnsatisfiable: DoNotSchedule
1676
1677
# -- terminationGracePeriodSeconds for container lifecycle hook
1678
terminationGracePeriodSeconds: 30
1679
# -- Automount API credentials for the Service Account into the pod.
1680
automountServiceAccountToken: true
1681
serviceAccount:
1682
# -- Create a service account for the redis pod
1683
create: false
1684
# -- Service account name for redis pod
1685
name: ""
1686
# -- Annotations applied to created service account
1687
annotations: {}
1688
# -- Automount API credentials for the Service Account
1689
automountServiceAccountToken: false
1690
service:
1691
# -- Redis service annotations
1692
annotations: {}
1693
# -- Additional redis service labels
1694
labels: {}
1695
metrics:
1696
# -- Deploy metrics service
1697
enabled: false
1698
# Redis metrics service configuration
1699
service:
1700
# -- Metrics service type
1701
type: ClusterIP
1702
# -- Metrics service clusterIP. `None` makes a "headless service" (no virtual IP)
1703
clusterIP: None
1704
# -- Metrics service annotations
1705
annotations: {}
1706
# -- Metrics service labels
1707
labels: {}
1708
# -- Metrics service port
1709
servicePort: 9121
1710
# -- Metrics service port name
1711
portName: http-metrics
1712
serviceMonitor:
1713
# -- Enable a prometheus ServiceMonitor
1714
enabled: false
1715
# -- Interval at which metrics should be scraped
1716
interval: 30s
1717
# -- When true, honorLabels preserves the metric’s labels when they collide with the target’s labels.
1718
honorLabels: false
1719
# -- Prometheus [RelabelConfigs] to apply to samples before scraping
1720
relabelings: []
1721
# -- Prometheus [MetricRelabelConfigs] to apply to samples before ingestion
1722
metricRelabelings: []
1723
# -- Prometheus ServiceMonitor selector
1724
selector: {}
1725
# prometheus: kube-prometheus
1726
1727
# -- Prometheus ServiceMonitor scheme
1728
scheme: ""
1729
# -- Prometheus ServiceMonitor tlsConfig
1730
tlsConfig: {}
1731
# -- Prometheus ServiceMonitor namespace
1732
namespace: "" # "monitoring"
1733
# -- Prometheus ServiceMonitor labels
1734
additionalLabels: {}
1735
# -- Prometheus ServiceMonitor annotations
1736
annotations: {}
1737
# Default redis's network policy
1738
networkPolicy:
1739
# -- Default network policy rules used by redis
1740
# @default -- `false` (defaults to global.networkPolicy.create)
1741
create: false
1742
## Redis-HA subchart replaces custom redis deployment when `redis-ha.enabled=true`
1743
# Ref: https://github.com/DandyDeveloper/charts/blob/master/charts/redis-ha/values.yaml
1744
redis-ha:
1745
# -- Enables the Redis HA subchart and disables the custom Redis single node deployment
1746
enabled: false
1747
## Redis image
1748
image:
1749
# -- Redis repository
1750
repository: ecr-public.aws.com/docker/library/redis
1751
# -- Redis tag
1752
## Do not use 7.4.0 <= v < 8.0.0, otherwise you are no longer using an open source version of Redis
1753
## Runs ahead of the upstream HA manifests' pin: the redis 8.2.x line is only built on Alpine 3.22,
1754
## whose OpenSSL carries known vulnerabilities (GHSA-5p3w-hgjv-f6q3 report); 8.6.x is the patched base.
1755
tag: 8.6.4-alpine
1756
## Prometheus redis-exporter sidecar
1757
exporter:
1758
# -- Enable Prometheus redis-exporter sidecar
1759
enabled: false
1760
# -- Repository to use for the redis-exporter
1761
image: ghcr.io/oliver006/redis_exporter
1762
# -- Tag to use for the redis-exporter
1763
tag: v1.75.0
1764
persistentVolume:
1765
# -- Configures persistence on Redis nodes
1766
enabled: false
1767
## Redis specific configuration options
1768
redis:
1769
# -- Redis convention for naming the cluster group: must match `^[\\w-\\.]+$` and can be templated
1770
masterGroupName: argocd
1771
# -- Any valid redis config options in this section will be applied to each server (see `redis-ha` chart)
1772
# @default -- See [values.yaml]
1773
config:
1774
# -- Will save the DB if both the given number of seconds and the given number of write operations against the DB occurred. `""` is disabled
1775
# @default -- `'""'`
1776
save: '""'
1777
## Redis sentinel specific configuration options
1778
sentinel:
1779
# -- Sentinel container lifecycle hooks. The default `postStart` hook resets the sentinel state after a rolling update to prevent high CPU usage
1780
# @default -- See [values.yaml]
1781
lifecycle:
1782
postStart:
1783
exec:
1784
## Note: the reset command hardcodes the master group name `argocd`. If you override `redis-ha.redis.masterGroupName`, you must override this hook to match.
1785
command:
1786
- '/bin/sh'
1787
- '-c'
1788
- 'sleep 30; redis-cli -p 26379 sentinel reset argocd'
1789
## Enables a HA Proxy for better LoadBalancing / Sentinel Master support. Automatically proxies to Redis master.
1790
haproxy:
1791
# -- Enabled HAProxy LoadBalancing/Proxy
1792
enabled: true
1793
# -- Custom labels for the haproxy pod. This is relevant for Argo CD CLI.
1794
labels:
1795
app.kubernetes.io/name: argocd-redis-ha-haproxy
1796
image:
1797
# -- HAProxy Image Repository
1798
repository: ecr-public.aws.com/docker/library/haproxy
1799
metrics:
1800
# -- HAProxy enable prometheus metric scraping
1801
enabled: true
1802
# -- Whether the haproxy pods should be forced to run on separate nodes.
1803
hardAntiAffinity: true
1804
# -- Additional affinities to add to the haproxy pods.
1805
additionalAffinities: {}
1806
# -- Assign custom [affinity] rules to the haproxy pods.
1807
affinity: ""
1808
# -- [Tolerations] for use with node taints for haproxy pods.
1809
tolerations: []
1810
# -- HAProxy container-level security context
1811
# @default -- See [values.yaml]
1812
containerSecurityContext:
1813
readOnlyRootFilesystem: true
1814
# -- Configures redis-ha with AUTH
1815
auth: true
1816
# -- Existing Secret to use for redis-ha authentication.
1817
# By default the redis-secret-init Job is generating this Secret.
1818
# When `redisSecretInit.enabled` is `false`, the Argo CD components read the Redis password from this Secret too (key `redis-ha.authKey`).
1819
existingSecret: argocd-redis
1820
# -- Whether the Redis server pods should be forced to run on separate nodes.
1821
hardAntiAffinity: true
1822
# -- Additional affinities to add to the Redis server pods.
1823
additionalAffinities: {}
1824
# -- Assign custom [affinity] rules to the Redis pods.
1825
affinity: ""
1826
# -- [Tolerations] for use with node taints for Redis pods.
1827
tolerations: []
1828
# -- Assign custom [TopologySpreadConstraints] rules to the Redis pods.
1829
## https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
1830
topologySpreadConstraints:
1831
# -- Enable Redis HA topology spread constraints
1832
enabled: false
1833
# -- Max skew of pods tolerated
1834
# @default -- `""` (defaults to `1`)
1835
maxSkew: ""
1836
# -- Topology key for spread
1837
# @default -- `""` (defaults to `topology.kubernetes.io/zone`)
1838
topologyKey: ""
1839
# -- Enforcement policy, hard or soft
1840
# @default -- `""` (defaults to `ScheduleAnyway`)
1841
whenUnsatisfiable: ""
1842
# -- Redis HA statefulset container-level security context
1843
# @default -- See [values.yaml]
1844
containerSecurityContext:
1845
readOnlyRootFilesystem: true
1846
# External Redis parameters
1847
externalRedis:
1848
# -- External Redis server host
1849
host: ""
1850
# -- External Redis username
1851
username: ""
1852
# -- External Redis password
1853
password: ""
1854
# -- External Redis server port
1855
port: 6379
1856
# -- The name of an existing secret with Redis (must contain key `redis-password`. And should contain `redis-username` if username is not `default`) and Sentinel credentials.
1857
# When it's set, the `externalRedis.username` and `externalRedis.password` parameters are ignored
1858
existingSecret: ""
1859
# -- External Redis Secret annotations
1860
secretAnnotations: {}
1861
redisSecretInit:
1862
# -- Enable Redis secret initialization. If disabled, secret must be provisioned by alternative methods
1863
enabled: true
1864
# -- Redis secret-init name
1865
name: redis-secret-init
1866
image:
1867
# -- Repository to use for the Redis secret-init Job
1868
# @default -- `""` (defaults to global.image.repository)
1869
repository: "" # defaults to global.image.repository
1870
# -- Tag to use for the Redis secret-init Job
1871
# @default -- `""` (defaults to global.image.tag)
1872
tag: "" # defaults to global.image.tag
1873
# -- Image pull policy for the Redis secret-init Job
1874
# @default -- `""` (defaults to global.image.imagePullPolicy)
1875
imagePullPolicy: "" # IfNotPresent
1876
# -- Additional command line arguments for the Redis secret-init Job
1877
extraArgs: []
1878
# -- Secrets with credentials to pull images from a private registry
1879
# @default -- `[]` (defaults to global.imagePullSecrets)
1880
imagePullSecrets: []
1881
# -- Runtime class name for the Redis secret-init Job
1882
# @default -- `""` (defaults to global.runtimeClassName)
1883
runtimeClassName: ""
1884
# -- Annotations to be added to the Redis secret-init Job
1885
jobAnnotations: {}
1886
# -- Annotations to be added to the Redis secret-init Job
1887
podAnnotations: {}
1888
# -- Labels to be added to the Redis secret-init Job
1889
podLabels: {}
1890
# -- Resource limits and requests for Redis secret-init Job
1891
resources: {}
1892
# limits:
1893
# cpu: 200m
1894
# memory: 128Mi
1895
# requests:
1896
# cpu: 100m
1897
# memory: 64Mi
1898
1899
# -- Application controller container-level security context
1900
# @default -- See [values.yaml]
1901
containerSecurityContext:
1902
allowPrivilegeEscalation: false
1903
capabilities:
1904
drop:
1905
- ALL
1906
readOnlyRootFilesystem: true
1907
runAsNonRoot: true
1908
seccompProfile:
1909
type: RuntimeDefault
1910
# -- Redis secret-init Job pod-level security context
1911
securityContext: {}
1912
serviceAccount:
1913
# -- Create a service account for the redis pod
1914
create: true
1915
# -- Service account name for redis pod
1916
name: ""
1917
# -- Annotations applied to created service account
1918
annotations: {}
1919
# -- Automount API credentials for the Service Account
1920
automountServiceAccountToken: true
1921
# -- Priority class for Redis secret-init Job
1922
# @default -- `""` (defaults to global.priorityClassName)
1923
priorityClassName: ""
1924
# -- Host Network for redis-secret-init pods
1925
hostNetwork: false
1926
# -- [DNS configuration]
1927
dnsConfig: {}
1928
# -- Alternative DNS policy for Redis secret-init Job
1929
dnsPolicy: "ClusterFirst"
1930
# -- Assign custom [affinity] rules to the Redis secret-init Job
1931
affinity: {}
1932
# -- Node selector to be added to the Redis secret-init Job
1933
# @default -- `{}` (defaults to global.nodeSelector)
1934
nodeSelector: {}
1935
# -- Tolerations to be added to the Redis secret-init Job
1936
# @default -- `[]` (defaults to global.tolerations)
1937
tolerations: []
1938
## Server
1939
server:
1940
# -- Argo CD server name
1941
name: server
1942
# -- The number of server pods to run
1943
replicas: 1
1944
# -- Runtime class name for the Argo CD server
1945
# @default -- `""` (defaults to global.runtimeClassName)
1946
runtimeClassName: ""
1947
## Argo CD server Horizontal Pod Autoscaler
1948
autoscaling:
1949
# -- Enable Horizontal Pod Autoscaler ([HPA]) for the Argo CD server
1950
enabled: false
1951
# -- Minimum number of replicas for the Argo CD server [HPA]
1952
minReplicas: 1
1953
# -- Maximum number of replicas for the Argo CD server [HPA]
1954
maxReplicas: 5
1955
# -- Average CPU utilization percentage for the Argo CD server [HPA]
1956
targetCPUUtilizationPercentage: 50
1957
# -- Average memory utilization percentage for the Argo CD server [HPA]
1958
targetMemoryUtilizationPercentage: 50
1959
# -- Configures the scaling behavior of the target in both Up and Down directions.
1960
behavior: {}
1961
# scaleDown:
1962
# stabilizationWindowSeconds: 300
1963
# policies:
1964
# - type: Pods
1965
# value: 1
1966
# periodSeconds: 180
1967
# scaleUp:
1968
# stabilizationWindowSeconds: 300
1969
# policies:
1970
# - type: Pods
1971
# value: 2
1972
# periodSeconds: 60
1973
# -- Configures custom HPA metrics for the Argo CD server
1974
# Ref: https://kubernetes.io/docs/tasks/run-application/horizontal-pod-autoscale/
1975
metrics: []
1976
## Argo CD server Pod Disruption Budget
1977
## Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
1978
pdb:
1979
# -- Deploy a [PodDisruptionBudget] for the Argo CD server
1980
enabled: false
1981
# -- Labels to be added to Argo CD server pdb
1982
labels: {}
1983
# -- Annotations to be added to Argo CD server pdb
1984
annotations: {}
1985
# -- Number of pods that are available after eviction as number or percentage (eg.: 50%)
1986
# @default -- `""` (defaults to 0 if not specified)
1987
minAvailable: ""
1988
# -- Number of pods that are unavailable after eviction as number or percentage (eg.: 50%).
1989
## Has higher precedence over `server.pdb.minAvailable`
1990
maxUnavailable: ""
1991
# -- Policy for evicting unhealthy (not ready) pods, either `IfHealthyBudget` or `AlwaysAllow`
1992
## Defaults to `IfHealthyBudget` if not set
1993
unhealthyPodEvictionPolicy: ""
1994
## Argo CD server Vertical Pod Autoscaler
1995
## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/
1996
vpa:
1997
# -- Deploy a [VerticalPodAutoscaler](https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/) for the Argo CD server
1998
enabled: false
1999
# -- Labels to be added to Argo CD server vpa
2000
labels: {}
2001
# -- Annotations to be added to Argo CD server vpa
2002
annotations: {}
2003
# -- One of the VPA operation modes
2004
## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically
2005
## Note: Recreate update mode requires more than one replica unless the min-replicas VPA controller flag is overridden
2006
updateMode: Initial
2007
# -- Controls how VPA computes the recommended resources for Argo CD server container
2008
## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/examples/hamster.yaml
2009
containerPolicy: {}
2010
# controlledResources: ["cpu", "memory"]
2011
# minAllowed:
2012
# cpu: 250m
2013
# memory: 256Mi
2014
# maxAllowed:
2015
# cpu: 1
2016
# memory: 1Gi
2017
# -- The recommenders that will provide recommendations for vertical scaling. Only relevant if a named VPA recommender (e.g. one started with a custom recommender name) is in use; leave unset to use the cluster's default recommender
2018
## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/docs/api.md#verticalpodautoscalerspec
2019
## NOTE: specify only zero or one recommender as of VPA 1.7.1
2020
recommenders: []
2021
# -- Configures a startup resource boost for faster cold-start (application boot) resource allocation. NOTE: startupBoost is currently a GKE-specific extension to the VPA API and is only honored on GKE clusters; it is rendered only when set
2022
## Ref: https://cloud.google.com/kubernetes-engine/docs/how-to/boost-application-startup
2023
startupBoost: {}
2024
# cpu:
2025
# type: Factor
2026
# factor: 2
2027
# durationSeconds: 10
2028
## Argo CD server image
2029
image:
2030
# -- Repository to use for the Argo CD server
2031
# @default -- `""` (defaults to global.image.repository)
2032
repository: "" # defaults to global.image.repository
2033
# -- Tag to use for the Argo CD server
2034
# @default -- `""` (defaults to global.image.tag)
2035
tag: "" # defaults to global.image.tag
2036
# -- Image pull policy for the Argo CD server
2037
# @default -- `""` (defaults to global.image.imagePullPolicy)
2038
imagePullPolicy: "" # IfNotPresent
2039
# -- Secrets with credentials to pull images from a private registry
2040
# @default -- `[]` (defaults to global.imagePullSecrets)
2041
imagePullSecrets: []
2042
# -- Additional command line arguments to pass to Argo CD server
2043
extraArgs: []
2044
# -- Environment variables to pass to Argo CD server
2045
env: []
2046
# -- envFrom to pass to Argo CD server
2047
# @default -- `[]` (See [values.yaml])
2048
envFrom: []
2049
# - configMapRef:
2050
# name: config-map-name
2051
# - secretRef:
2052
# name: secret-name
2053
2054
# -- Specify postStart and preStop lifecycle hooks for your argo-cd-server container
2055
lifecycle: {}
2056
## Argo CD extensions
2057
## This function in tech preview stage, do expect instability or breaking changes in newer versions.
2058
## Ref: https://github.com/argoproj-labs/argocd-extension-installer
2059
## When you enable extensions, you need to configure RBAC of logged in Argo CD user.
2060
## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/rbac/#the-extensions-resource
2061
extensions:
2062
# -- Enable support for Argo CD extensions
2063
enabled: false
2064
## Argo CD extension installer image
2065
image:
2066
# -- Repository to use for extension installer image
2067
repository: chainreg.biz/chainguard-private/argocd-extension-installer
2068
# -- Tag to use for extension installer image
2069
tag: 1.1.0-r0@sha256:af610578dbc8ee874f853e70ed3b096fefc0812f097437ca29d4487684ef597c
2070
# -- Image pull policy for extensions
2071
# @default -- `""` (defaults to global.image.imagePullPolicy)
2072
imagePullPolicy: ""
2073
# -- Extensions for Argo CD
2074
# @default -- `[]` (See [values.yaml])
2075
## Ref: https://github.com/argoproj-labs/argocd-extension-metrics#install-ui-extension
2076
extensionList: []
2077
# - name: extension-metrics
2078
# env:
2079
# - name: EXTENSION_URL
2080
# value: https://github.com/argoproj-labs/argocd-extension-metrics/releases/download/v1.0.0/extension.tar.gz
2081
# - name: EXTENSION_CHECKSUM_URL
2082
# value: https://github.com/argoproj-labs/argocd-extension-metrics/releases/download/v1.0.0/extension_checksums.txt
2083
2084
# -- Server UI extensions container-level security context
2085
# @default -- See [values.yaml]
2086
containerSecurityContext:
2087
runAsNonRoot: true
2088
readOnlyRootFilesystem: true
2089
allowPrivilegeEscalation: false
2090
runAsUser: 1000
2091
seccompProfile:
2092
type: RuntimeDefault
2093
capabilities:
2094
drop:
2095
- ALL
2096
# -- Resource limits and requests for the argocd-extensions container
2097
resources: {}
2098
# limits:
2099
# cpu: 50m
2100
# memory: 128Mi
2101
# requests:
2102
# cpu: 10m
2103
# memory: 64Mi
2104
# -- Additional containers to be added to the server pod
2105
## Note: Supports use of custom Helm templates
2106
extraContainers: []
2107
# - name: my-sidecar
2108
# image: nginx:latest
2109
# - name: lemonldap-ng-controller
2110
# image: lemonldapng/lemonldap-ng-controller:0.2.0
2111
# args:
2112
# - /lemonldap-ng-controller
2113
# - --alsologtostderr
2114
# - --configmap=$(POD_NAMESPACE)/lemonldap-ng-configuration
2115
# env:
2116
# - name: POD_NAME
2117
# valueFrom:
2118
# fieldRef:
2119
# fieldPath: metadata.name
2120
# - name: POD_NAMESPACE
2121
# valueFrom:
2122
# fieldRef:
2123
# fieldPath: metadata.namespace
2124
# volumeMounts:
2125
# - name: copy-portal-skins
2126
# mountPath: /srv/var/lib/lemonldap-ng/portal/skins
2127
2128
# -- Init containers to add to the server pod
2129
## If your target Kubernetes cluster(s) require a custom credential (exec) plugin
2130
## you could use this (and the same in the application controller pod) to provide such executable
2131
## Ref: https://kubernetes.io/docs/reference/access-authn-authz/authentication/#client-go-credential-plugins
2132
initContainers: []
2133
# - name: download-tools
2134
# image: alpine:3
2135
# command: [sh, -c]
2136
# args:
2137
# - wget -qO /custom-tools/kubelogin.zip https://github.com/Azure/kubelogin/releases/download/v0.2.7/kubelogin-linux-amd64.zip &&
2138
# mkdir /custom-tools/tmp && unzip -d /custom-tools/tmp /custom-tools/kubelogin.zip &&
2139
# mv /custom-tools/tmp/bin/linux_amd64/kubelogin /custom-tools/ && rm -rf custom-tools/tmp && rm /custom-tools/kubelogin.zip
2140
# volumeMounts:
2141
# - mountPath: /custom-tools
2142
# name: custom-tools
2143
2144
# -- Additional volumeMounts to the server main container
2145
volumeMounts: []
2146
# - mountPath: /usr/local/bin/kubelogin
2147
# name: custom-tools
2148
# subPath: kubelogin
2149
2150
# -- Additional volumes to the server pod
2151
volumes: []
2152
# - name: custom-tools
2153
# emptyDir: {}
2154
2155
## Argo CD server emptyDir volumes
2156
emptyDir:
2157
# -- EmptyDir size limit for the Argo CD server
2158
# @default -- `""` (defaults not set if not specified i.e. no size limit)
2159
sizeLimit: ""
2160
# sizeLimit: "1Gi"
2161
# -- Annotations to be added to server Deployment
2162
deploymentAnnotations: {}
2163
# -- Labels for the server Deployment
2164
deploymentLabels: {}
2165
# -- Annotations to be added to server pods
2166
podAnnotations: {}
2167
# -- Labels to be added to server pods
2168
podLabels: {}
2169
# -- Resource limits and requests for the Argo CD server
2170
resources: {}
2171
# limits:
2172
# cpu: 100m
2173
# memory: 128Mi
2174
# requests:
2175
# cpu: 50m
2176
# memory: 64Mi
2177
2178
# Server container ports
2179
containerPorts:
2180
# -- Server container port
2181
server: 8080
2182
# -- Metrics container port
2183
metrics: 8083
2184
# -- Host Network for Server pods
2185
hostNetwork: false
2186
# -- [DNS configuration]
2187
dnsConfig: {}
2188
# -- Alternative DNS policy for Server pods
2189
dnsPolicy: "ClusterFirst"
2190
# -- Server container-level security context
2191
# @default -- See [values.yaml]
2192
containerSecurityContext:
2193
runAsNonRoot: true
2194
readOnlyRootFilesystem: true
2195
allowPrivilegeEscalation: false
2196
seccompProfile:
2197
type: RuntimeDefault
2198
capabilities:
2199
drop:
2200
- ALL
2201
## Readiness and liveness probes for default backend
2202
## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
2203
readinessProbe:
2204
# -- Enable Kubernetes readiness probe for default backend
2205
enabled: true
2206
# -- Http path to use for the readiness probe
2207
httpPath: /healthz
2208
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
2209
failureThreshold: 3
2210
# -- Number of seconds after the container has started before [probe] is initiated
2211
initialDelaySeconds: 10
2212
# -- How often (in seconds) to perform the [probe]
2213
periodSeconds: 10
2214
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
2215
successThreshold: 1
2216
# -- Number of seconds after which the [probe] times out
2217
timeoutSeconds: 1
2218
livenessProbe:
2219
# -- Enable Kubernetes liveness probe for default backend
2220
enabled: true
2221
# -- Http path to use for the liveness probe
2222
httpPath: /healthz?full=true
2223
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
2224
failureThreshold: 3
2225
# -- Number of seconds after the container has started before [probe] is initiated
2226
initialDelaySeconds: 10
2227
# -- How often (in seconds) to perform the [probe]
2228
periodSeconds: 10
2229
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
2230
successThreshold: 1
2231
# -- Number of seconds after which the [probe] times out
2232
timeoutSeconds: 1
2233
## Startup probe for Argo CD server (optional)
2234
## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
2235
startupProbe:
2236
# -- Enable Kubernetes startup probe for Argo CD server
2237
enabled: false
2238
# -- Http path to use for the startup probe
2239
httpPath: /healthz
2240
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
2241
failureThreshold: 20
2242
# -- Number of seconds after the container has started before [probe] is initiated
2243
initialDelaySeconds: 10
2244
# -- How often (in seconds) to perform the [probe]
2245
periodSeconds: 10
2246
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
2247
successThreshold: 1
2248
# -- Number of seconds after which the [probe] times out
2249
timeoutSeconds: 1
2250
# -- terminationGracePeriodSeconds for container lifecycle hook
2251
terminationGracePeriodSeconds: 30
2252
# -- Priority class for the Argo CD server pods
2253
# @default -- `""` (defaults to global.priorityClassName)
2254
priorityClassName: ""
2255
# -- [Node selector]
2256
# @default -- `{}` (defaults to global.nodeSelector)
2257
nodeSelector: {}
2258
# -- [Tolerations] for use with node taints
2259
# @default -- `[]` (defaults to global.tolerations)
2260
tolerations: []
2261
# -- Assign custom [affinity] rules to the deployment
2262
# @default -- `{}` (defaults to global.affinity preset)
2263
affinity: {}
2264
# -- Assign custom [TopologySpreadConstraints] rules to the Argo CD server
2265
# @default -- `[]` (defaults to global.topologySpreadConstraints)
2266
## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
2267
## If labelSelector is left out, it will default to the labelSelector configuration of the deployment
2268
topologySpreadConstraints: []
2269
# - maxSkew: 1
2270
# topologyKey: topology.kubernetes.io/zone
2271
# whenUnsatisfiable: DoNotSchedule
2272
2273
# -- Deployment strategy to be added to the server Deployment
2274
deploymentStrategy: {}
2275
# type: RollingUpdate
2276
# rollingUpdate:
2277
# maxSurge: 25%
2278
# maxUnavailable: 25%
2279
2280
# TLS certificate configuration via cert-manager
2281
## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/tls/#tls-certificates-used-by-argocd-server
2282
certificate:
2283
# -- Deploy a Certificate resource (requires cert-manager)
2284
enabled: false
2285
# -- Certificate primary domain (commonName)
2286
# @default -- `""` (defaults to global.domain)
2287
domain: ""
2288
# -- Certificate Subject Alternate Names (SANs)
2289
additionalHosts: []
2290
# -- The requested 'duration' (i.e. lifetime) of the certificate.
2291
# @default -- `""` (defaults to 2160h = 90d if not specified)
2292
## Ref: https://cert-manager.io/docs/usage/certificate/#renewal
2293
duration: ""
2294
# -- How long before the expiry a certificate should be renewed.
2295
# @default -- `""` (defaults to 360h = 15d if not specified)
2296
## Ref: https://cert-manager.io/docs/usage/certificate/#renewal
2297
renewBefore: ""
2298
# Certificate issuer
2299
## Ref: https://cert-manager.io/docs/concepts/issuer
2300
issuer:
2301
# -- Certificate issuer group. Set if using an external issuer. Eg. `cert-manager.io`
2302
group: ""
2303
# -- Certificate issuer kind. Either `Issuer` or `ClusterIssuer`
2304
kind: ""
2305
# -- Certificate issuer name. Eg. `letsencrypt`
2306
name: ""
2307
# Private key of the certificate
2308
privateKey:
2309
# -- Rotation policy of private key when certificate is re-issued. Either: `Never` or `Always`
2310
rotationPolicy: Never
2311
# -- The private key cryptography standards (PKCS) encoding for private key. Either: `PCKS1` or `PKCS8`
2312
encoding: PKCS1
2313
# -- Algorithm used to generate certificate private key. One of: `RSA`, `Ed25519` or `ECDSA`
2314
algorithm: RSA
2315
# -- Key bit size of the private key. If algorithm is set to `Ed25519`, size is ignored.
2316
size: 2048
2317
# -- Annotations to be applied to the Server Certificate
2318
annotations: {}
2319
# -- Usages for the certificate
2320
### Ref: https://cert-manager.io/docs/reference/api-docs/#cert-manager.io/v1.KeyUsage
2321
usages: []
2322
# -- Annotations that allow the certificate to be composed from data residing in existing Kubernetes Resources
2323
secretTemplateAnnotations: {}
2324
# TLS certificate configuration via Secret
2325
## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/tls/#tls-certificates-used-by-argocd-server
2326
certificateSecret:
2327
# -- Create argocd-server-tls secret
2328
enabled: false
2329
# -- Annotations to be added to argocd-server-tls secret
2330
annotations: {}
2331
# -- Labels to be added to argocd-server-tls secret
2332
labels: {}
2333
# -- Private Key of the certificate
2334
key: ""
2335
# -- Certificate data
2336
crt: ""
2337
## Server service configuration
2338
service:
2339
# -- Server service annotations
2340
annotations: {}
2341
# -- Server service labels
2342
labels: {}
2343
# -- Server service type
2344
type: ClusterIP
2345
# -- Server service http port for NodePort service type (only if `server.service.type` is set to "NodePort")
2346
nodePortHttp: 30080
2347
# -- (int) Server service http2 port for NodePort service type (only if `server.service.servicePortHttp2` is set and `server.service.type` is set to "NodePort")
2348
# @default -- `nil` (a random node port is assigned)
2349
nodePortHttp2:
2350
# -- Server service https port for NodePort service type (only if `server.service.type` is set to "NodePort")
2351
nodePortHttps: 30443
2352
# -- Server service http port
2353
servicePortHttp: 80
2354
# -- (int) Server service cleartext http2 (h2c) port, targeting the same container port as `servicePortHttp`
2355
# @default -- `nil` (disabled)
2356
## The Argo CD server serves the web UI (HTTP/1.1) and gRPC (HTTP/2) on a single container port, and
2357
## `appProtocol` is single-valued per service port. Set this to expose a second port advertising the
2358
## h2c backend protocol, for Gateway API implementations that do not infer it from the route type.
2359
## Leave empty to disable. Only rendered when `configs.params."server.insecure"` is `true`, since
2360
## h2c is not applicable to a TLS backend.
2361
servicePortHttp2:
2362
# -- Server service https port
2363
servicePortHttps: 443
2364
# -- Server service http port name, can be used to route traffic via istio
2365
servicePortHttpName: http
2366
# -- Server service http2 port name, can be used to route traffic via istio
2367
servicePortHttp2Name: http2
2368
# -- Server service https port name, can be used to route traffic via istio
2369
servicePortHttpsName: https
2370
# -- Server service http2 port appProtocol, e.g. `kubernetes.io/h2c`. Implementations that select the
2371
# protocol from the port name instead do not need it
2372
## Ref: https://kubernetes.io/docs/concepts/services-networking/service/#application-protocol
2373
servicePortHttp2AppProtocol: ""
2374
# -- Server service https port appProtocol
2375
## Ref: https://kubernetes.io/docs/concepts/services-networking/service/#application-protocol
2376
servicePortHttpsAppProtocol: ""
2377
# -- The class of the load balancer implementation
2378
loadBalancerClass: ""
2379
# -- LoadBalancer will get created with the IP specified in this field
2380
loadBalancerIP: ""
2381
# -- Source IP ranges to allow access to service from
2382
## EKS Ref: https://repost.aws/knowledge-center/eks-cidr-ip-address-loadbalancer
2383
## GKE Ref: https://cloud.google.com/kubernetes-engine/docs/concepts/network-overview#limit-connectivity-ext-lb
2384
loadBalancerSourceRanges: []
2385
# -- Server service external IPs
2386
externalIPs: []
2387
# -- Denotes if this Service desires to route external traffic to node-local or cluster-wide endpoints
2388
## Ref: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip
2389
externalTrafficPolicy: Cluster
2390
# -- Used to maintain session affinity. Supports `ClientIP` and `None`
2391
## Ref: https://kubernetes.io/docs/concepts/services-networking/service/#virtual-ips-and-service-proxies
2392
sessionAffinity: None
2393
## Server metrics service configuration
2394
metrics:
2395
# -- Deploy metrics service
2396
enabled: false
2397
service:
2398
# -- Metrics service type
2399
type: ClusterIP
2400
# -- Metrics service clusterIP. `None` makes a "headless service" (no virtual IP)
2401
clusterIP: ""
2402
# -- Metrics service annotations
2403
annotations: {}
2404
# -- Metrics service labels
2405
labels: {}
2406
# -- Metrics service port
2407
servicePort: 8083
2408
# -- Metrics service port name
2409
portName: http-metrics
2410
serviceMonitor:
2411
# -- Enable a prometheus ServiceMonitor
2412
enabled: false
2413
# -- Prometheus ServiceMonitor interval
2414
interval: 30s
2415
# -- Prometheus ServiceMonitor scrapeTimeout. If empty, Prometheus uses the global scrape timeout unless it is less than the target's scrape interval value in which the latter is used.
2416
scrapeTimeout: ""
2417
# -- When true, honorLabels preserves the metric’s labels when they collide with the target’s labels.
2418
honorLabels: false
2419
# -- Prometheus [RelabelConfigs] to apply to samples before scraping
2420
relabelings: []
2421
# -- Prometheus [MetricRelabelConfigs] to apply to samples before ingestion
2422
metricRelabelings: []
2423
# -- Prometheus ServiceMonitor selector
2424
selector: {}
2425
# prometheus: kube-prometheus
2426
2427
# -- Prometheus ServiceMonitor scheme
2428
scheme: ""
2429
# -- Prometheus ServiceMonitor tlsConfig
2430
tlsConfig: {}
2431
# -- Prometheus ServiceMonitor namespace
2432
namespace: "" # monitoring
2433
# -- Prometheus ServiceMonitor labels
2434
additionalLabels: {}
2435
# -- Prometheus ServiceMonitor annotations
2436
annotations: {}
2437
# -- Automount API credentials for the Service Account into the pod.
2438
automountServiceAccountToken: true
2439
serviceAccount:
2440
# -- Create server service account
2441
create: true
2442
# -- Server service account name
2443
name: argocd-server
2444
# -- Annotations applied to created service account
2445
annotations: {}
2446
# -- Labels applied to created service account
2447
labels: {}
2448
# -- Automount API credentials for the Service Account
2449
automountServiceAccountToken: true
2450
# Argo CD server ingress configuration
2451
ingress:
2452
# -- Enable an ingress resource for the Argo CD server
2453
enabled: false
2454
# -- Specific implementation for ingress controller. One of `generic`, `aws` or `gke`
2455
## Additional configuration might be required in related configuration sections
2456
controller: generic
2457
# -- Additional ingress labels
2458
labels: {}
2459
# -- Additional ingress annotations
2460
## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/ingress/#option-1-ssl-passthrough
2461
annotations: {}
2462
# nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
2463
# nginx.ingress.kubernetes.io/ssl-passthrough: "true"
2464
2465
# -- Defines which ingress controller will implement the resource
2466
ingressClassName: ""
2467
# -- Argo CD server hostname
2468
# @default -- `""` (defaults to global.domain)
2469
hostname: ""
2470
# -- The path to Argo CD server
2471
path: /
2472
# -- Ingress path type. One of `Exact`, `Prefix` or `ImplementationSpecific`
2473
pathType: Prefix
2474
# -- Enable TLS configuration for the hostname defined at `server.ingress.hostname`
2475
## TLS certificate will be retrieved from a TLS secret `argocd-server-tls`
2476
## You can create this secret via `certificate` or `certificateSecret` option
2477
tls: false
2478
# -- The list of additional hostnames to be covered by ingress record
2479
# @default -- `[]` (See [values.yaml])
2480
extraHosts: []
2481
# - name: argocd.example.com
2482
# path: /
2483
2484
# -- Additional ingress paths
2485
# @default -- `[]` (See [values.yaml])
2486
## Note: Supports use of custom Helm templates
2487
extraPaths: []
2488
# - path: /*
2489
# pathType: Prefix
2490
# backend:
2491
# service:
2492
# name: ssl-redirect
2493
# port:
2494
# name: use-annotation
2495
2496
# -- Additional ingress rules
2497
# @default -- `[]` (See [values.yaml])
2498
## Note: Supports use of custom Helm templates
2499
extraRules: []
2500
# - http:
2501
# paths:
2502
# - path: /
2503
# pathType: Prefix
2504
# backend:
2505
# service:
2506
# name: '{{ include "argo-cd.server.fullname" . }}'
2507
# port:
2508
# name: '{{ .Values.server.service.servicePortHttpsName }}'
2509
2510
# -- Additional TLS configuration
2511
# @default -- `[]` (See [values.yaml])
2512
extraTls: []
2513
# - hosts:
2514
# - argocd.example.com
2515
# secretName: your-certificate-name
2516
2517
# AWS specific options for Application Load Balancer
2518
# Applies only when `serv.ingress.controller` is set to `aws`
2519
## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/ingress/#aws-application-load-balancers-albs-and-classic-elb-http-mode
2520
aws:
2521
# -- Backend protocol version for the AWS ALB gRPC service
2522
## This tells AWS to send traffic from the ALB using gRPC.
2523
## For more information: https://docs.aws.amazon.com/elasticloadbalancing/latest/application/target-group-health-checks.html#health-check-settings
2524
backendProtocolVersion: GRPC
2525
# -- Service type for the AWS ALB gRPC service
2526
## Can be of type NodePort or ClusterIP depending on which mode you are running.
2527
## Instance mode needs type NodePort, IP mode needs type ClusterIP
2528
## Ref: https://kubernetes-sigs.github.io/aws-load-balancer-controller/v2.2/how-it-works/#ingress-traffic
2529
serviceType: NodePort
2530
# -- Annotations for the AWS ALB gRPC service
2531
## Allows adding custom annotations to the gRPC service for integrations like DataDog, Prometheus, etc.
2532
serviceAnnotations: {}
2533
# Google specific options for Google Application Load Balancer
2534
# Applies only when `server.ingress.controller` is set to `gke`
2535
## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/ingress/#google-cloud-load-balancers-with-kubernetes-ingress
2536
gke:
2537
# -- Google [BackendConfig] resource, for use with the GKE Ingress Controller
2538
# @default -- `{}` (See [values.yaml])
2539
## Ref: https://cloud.google.com/kubernetes-engine/docs/how-to/ingress-features#configuring_ingress_features_through_frontendconfig_parameters
2540
backendConfig: {}
2541
# iap:
2542
# enabled: true
2543
# oauthclientCredentials:
2544
# secretName: argocd-secret
2545
2546
# -- Google [FrontendConfig] resource, for use with the GKE Ingress Controller
2547
# @default -- `{}` (See [values.yaml])
2548
## Ref: https://cloud.google.com/kubernetes-engine/docs/how-to/ingress-features#configuring_ingress_features_through_frontendconfig_parameters
2549
frontendConfig: {}
2550
# redirectToHttps:
2551
# enabled: true
2552
# responseCodeName: RESPONSE_CODE
2553
2554
# Managed GKE certificate for ingress hostname
2555
managedCertificate:
2556
# -- Create ManagedCertificate resource and annotations for Google Load balancer
2557
## Ref: https://cloud.google.com/kubernetes-engine/docs/how-to/managed-certs
2558
create: true
2559
# -- Additional domains for ManagedCertificate resource
2560
extraDomains: []
2561
# - argocd.example.com
2562
# Dedicated gRPC ingress for ingress controllers that supports only single backend protocol per Ingress resource
2563
# Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/ingress/#option-2-multiple-ingress-objects-and-hosts
2564
ingressGrpc:
2565
# -- Enable an ingress resource for the Argo CD server for dedicated [gRPC-ingress]
2566
enabled: false
2567
# -- Additional ingress annotations for dedicated [gRPC-ingress]
2568
annotations: {}
2569
# -- Additional ingress labels for dedicated [gRPC-ingress]
2570
labels: {}
2571
# -- Defines which ingress controller will implement the resource [gRPC-ingress]
2572
ingressClassName: ""
2573
# -- Argo CD server hostname for dedicated [gRPC-ingress]
2574
# @default -- `""` (defaults to grpc.`server.ingress.hostname`)
2575
hostname: ""
2576
# -- Argo CD server ingress path for dedicated [gRPC-ingress]
2577
path: /
2578
# -- Ingress path type for dedicated [gRPC-ingress]. One of `Exact`, `Prefix` or `ImplementationSpecific`
2579
pathType: Prefix
2580
# -- Enable TLS configuration for the hostname defined at `server.ingressGrpc.hostname`
2581
## TLS certificate will be retrieved from a TLS secret with name: `argocd-server-grpc-tls`
2582
tls: false
2583
# -- The list of additional hostnames to be covered by ingress record
2584
# @default -- `[]` (See [values.yaml])
2585
extraHosts: []
2586
# - name: grpc.argocd.example.com
2587
# path: /
2588
2589
# -- Additional ingress paths for dedicated [gRPC-ingress]
2590
# @default -- `[]` (See [values.yaml])
2591
## Note: Supports use of custom Helm templates
2592
extraPaths: []
2593
# - path: /*
2594
# pathType: Prefix
2595
# backend:
2596
# service:
2597
# name: ssl-redirect
2598
# port:
2599
# name: use-annotation
2600
2601
# -- Additional ingress rules
2602
# @default -- `[]` (See [values.yaml])
2603
## Note: Supports use of custom Helm templates
2604
extraRules: []
2605
# - http:
2606
# paths:
2607
# - path: /
2608
# pathType: Prefix
2609
# backend:
2610
# service:
2611
# name: '{{ include "argo-cd.server.fullname" . }}'
2612
# port:
2613
# name: '{{ .Values.server.service.servicePortHttpName }}'
2614
2615
# -- Additional TLS configuration for dedicated [gRPC-ingress]
2616
# @default -- `[]` (See [values.yaml])
2617
extraTls: []
2618
# - secretName: your-certificate-name
2619
# hosts:
2620
# - argocd.example.com
2621
# Create a OpenShift Route with SSL passthrough for UI and CLI
2622
# Consider setting 'hostname' e.g. https://argocd.apps-crc.testing/ using your Default Ingress Controller Domain
2623
# Find your domain with: kubectl describe --namespace=openshift-ingress-operator ingresscontroller/default | grep Domain:
2624
# If 'hostname' is an empty string "" OpenShift will create a hostname for you.
2625
route:
2626
# -- Enable an OpenShift Route for the Argo CD server
2627
enabled: false
2628
# -- Openshift Route annotations
2629
annotations: {}
2630
# -- Hostname of OpenShift Route
2631
hostname: ""
2632
# -- Termination type of Openshift Route
2633
termination_type: passthrough
2634
# -- Termination policy of Openshift Route
2635
termination_policy: None
2636
# Gateway API HTTPRoute configuration
2637
# NOTE: Gateway API support is in EXPERIMENTAL status
2638
# Support depends on your Gateway controller implementation
2639
# Some controllers may require additional configuration (e.g., BackendTLSPolicy for HTTPS backends)
2640
# Refer to https://gateway-api.sigs.k8s.io/implementations/ for controller-specific details
2641
httproute:
2642
# -- Enable HTTPRoute resource for Argo CD server (Gateway API)
2643
enabled: false
2644
# -- Additional HTTPRoute labels
2645
labels: {}
2646
# -- Additional HTTPRoute annotations
2647
annotations: {}
2648
# -- Gateway API parentRefs for the HTTPRoute
2649
## Must reference an existing Gateway
2650
# @default -- `[]` (See [values.yaml])
2651
parentRefs: []
2652
# - name: example-gateway
2653
# namespace: example-gateway-namespace
2654
# sectionName: https
2655
# -- List of hostnames for the HTTPRoute
2656
# @default -- `[]` (See [values.yaml])
2657
hostnames: []
2658
# - argocd.example.com
2659
# -- HTTPRoute rules configuration
2660
# @default -- `[]` (See [values.yaml])
2661
rules:
2662
- matches:
2663
- path:
2664
type: PathPrefix
2665
value: /
2666
# filters: []
2667
# - type: RequestHeaderModifier
2668
# requestHeaderModifier:
2669
# add:
2670
# - name: X-Custom-Header
2671
# value: custom-value
2672
# timeouts:
2673
# request: 10s
2674
# backendRequest: 2s
2675
# Gateway API GRPCRoute configuration
2676
# NOTE: Gateway API support is in EXPERIMENTAL status
2677
# Support depends on your Gateway controller implementation
2678
# Refer to https://gateway-api.sigs.k8s.io/implementations/ for controller-specific details
2679
grpcroute:
2680
# -- Enable GRPCRoute resource for Argo CD server (Gateway API)
2681
enabled: false
2682
# -- Additional GRPCRoute labels
2683
labels: {}
2684
# -- Additional GRPCRoute annotations
2685
annotations: {}
2686
# -- Gateway API parentRefs for the GRPCRoute
2687
## Must reference an existing Gateway
2688
# @default -- `[]` (See [values.yaml])
2689
parentRefs: []
2690
# - name: example-gateway
2691
# namespace: example-gateway-namespace
2692
# sectionName: grpc
2693
# -- List of hostnames for the GRPCRoute
2694
# @default -- `[]` (See [values.yaml])
2695
hostnames: []
2696
# - grpc.argocd.example.com
2697
# -- GRPCRoute rules configuration
2698
# @default -- `[]` (See [values.yaml])
2699
rules:
2700
- matches:
2701
- method:
2702
type: Exact
2703
# filters: []
2704
# - type: RequestHeaderModifier
2705
# requestHeaderModifier:
2706
# add:
2707
# - name: X-Custom-Header
2708
# value: custom-value
2709
# Gateway API BackendTLSPolicy configuration
2710
# NOTE: BackendTLSPolicy support is in EXPERIMENTAL status
2711
# Required for HTTPS backends when using Gateway API
2712
# Not all Gateway controllers support this resource (e.g., Cilium does not support it yet)
2713
backendTLSPolicy:
2714
# -- Enable BackendTLSPolicy resource for Argo CD server (Gateway API)
2715
enabled: false
2716
# -- Additional BackendTLSPolicy labels
2717
labels: {}
2718
# -- Additional BackendTLSPolicy annotations
2719
annotations: {}
2720
# -- Target references for the BackendTLSPolicy
2721
# @default -- `[]` (See [values.yaml])
2722
targetRefs: []
2723
# - group: ""
2724
# kind: Service
2725
# name: argocd-server
2726
# sectionName: https
2727
# -- TLS validation configuration
2728
# @default -- `{}` (See [values.yaml])
2729
validation: {}
2730
# hostname: argocd-server.argocd.svc.cluster.local
2731
# caCertificateRefs:
2732
# - name: example-ca-cert
2733
# group: ""
2734
# kind: ConfigMap
2735
# wellKnownCACertificates: System
2736
# Gateway API ListenerSet configuration
2737
# NOTE: Gateway API support is in EXPERIMENTAL status
2738
# ListenerSet allows attaching additional listeners to an existing Gateway
2739
# Requires Gateway API v1alpha2 and a controller that supports ListenerSet
2740
# Refer to https://gateway-api.sigs.k8s.io/reference/spec/#gateway.networking.k8s.io/v1alpha2.ListenerSet
2741
listenerset:
2742
# -- Enable ListenerSet resource for Argo CD server (Gateway API)
2743
enabled: false
2744
# -- Additional ListenerSet labels
2745
labels: {}
2746
# -- Additional ListenerSet annotations
2747
annotations: {}
2748
# -- Gateway API parentRef for the ListenerSet
2749
## Must reference an existing Gateway. Unlike HTTPRoute, ListenerSet accepts exactly one parentRef.
2750
# @default -- `{}` (See [values.yaml])
2751
parentRef: {}
2752
# name: example-gateway
2753
# namespace: example-gateway-namespace
2754
# -- Hostname for the synthesized listener. Defaults to global.domain when empty.
2755
hostname: ""
2756
# -- Name of the synthesized listener. Also used as sectionName in auto-derived httproute parentRefs.
2757
listenerName: https
2758
# -- Port for the synthesized listener
2759
port: 443
2760
# -- Protocol for the synthesized listener
2761
protocol: HTTPS
2762
# -- TLS configuration for the synthesized listener
2763
tls:
2764
# -- Enable TLS on the synthesized listener
2765
enabled: true
2766
# -- TLS termination mode
2767
mode: Terminate
2768
# -- Secret name for TLS certificate. Defaults to `argocd-server-tls` when empty.
2769
secretName: ""
2770
# -- allowedRoutes for the synthesized listener
2771
allowedRoutes:
2772
namespaces:
2773
from: Same
2774
# -- Listeners to attach to the parent Gateway. When non-empty, used verbatim and all synthesized listener fields above are ignored.
2775
# @default -- `[]` (See [values.yaml])
2776
listeners: []
2777
# - name: https
2778
# port: 443
2779
# protocol: HTTPS
2780
# hostname: argocd.example.com
2781
# tls:
2782
# mode: Terminate
2783
# certificateRefs:
2784
# - group: ""
2785
# kind: Secret
2786
# name: argocd-server-tls
2787
# allowedRoutes:
2788
# namespaces:
2789
# from: Same
2790
## Enable this and set the rules: to whatever custom rules you want for the Cluster Role resource.
2791
## Defaults to off
2792
clusterRoleRules:
2793
# -- Enable custom rules for the server's ClusterRole resource
2794
enabled: false
2795
# -- List of custom rules for the server's ClusterRole resource
2796
rules: []
2797
# Default ArgoCD Server's network policy
2798
networkPolicy:
2799
# -- Default network policy rules used by ArgoCD Server
2800
# @default -- `false` (defaults to global.networkPolicy.create)
2801
create: false
2802
## Repo Server
2803
repoServer:
2804
# -- Repo server name
2805
name: repo-server
2806
# -- The number of repo server pods to run
2807
replicas: 1
2808
# -- Runtime class name for the repo server
2809
# @default -- `""` (defaults to global.runtimeClassName)
2810
runtimeClassName: ""
2811
## Repo server Horizontal Pod Autoscaler
2812
autoscaling:
2813
# -- Enable Horizontal Pod Autoscaler ([HPA]) for the repo server
2814
enabled: false
2815
# -- Minimum number of replicas for the repo server [HPA]
2816
minReplicas: 1
2817
# -- Maximum number of replicas for the repo server [HPA]
2818
maxReplicas: 5
2819
# -- Average CPU utilization percentage for the repo server [HPA]
2820
targetCPUUtilizationPercentage: 50
2821
# -- Average memory utilization percentage for the repo server [HPA]
2822
targetMemoryUtilizationPercentage: 50
2823
# -- Configures the scaling behavior of the target in both Up and Down directions.
2824
behavior: {}
2825
# scaleDown:
2826
# stabilizationWindowSeconds: 300
2827
# policies:
2828
# - type: Pods
2829
# value: 1
2830
# periodSeconds: 180
2831
# scaleUp:
2832
# stabilizationWindowSeconds: 300
2833
# policies:
2834
# - type: Pods
2835
# value: 2
2836
# periodSeconds: 60
2837
# -- Configures custom HPA metrics for the Argo CD repo server
2838
# Ref: https://kubernetes.io/docs/tasks/run-application/horizontal-pod-autoscale/
2839
metrics: []
2840
## Repo server Pod Disruption Budget
2841
## Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
2842
pdb:
2843
# -- Deploy a [PodDisruptionBudget] for the repo server
2844
enabled: false
2845
# -- Labels to be added to repo server pdb
2846
labels: {}
2847
# -- Annotations to be added to repo server pdb
2848
annotations: {}
2849
# -- Number of pods that are available after eviction as number or percentage (eg.: 50%)
2850
# @default -- `""` (defaults to 0 if not specified)
2851
minAvailable: ""
2852
# -- Number of pods that are unavailable after eviction as number or percentage (eg.: 50%).
2853
## Has higher precedence over `repoServer.pdb.minAvailable`
2854
maxUnavailable: ""
2855
# -- Policy for evicting unhealthy (not ready) pods, either `IfHealthyBudget` or `AlwaysAllow`
2856
## Defaults to `IfHealthyBudget` if not set
2857
unhealthyPodEvictionPolicy: ""
2858
## Repo server Vertical Pod Autoscaler
2859
## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/
2860
vpa:
2861
# -- Deploy a [VerticalPodAutoscaler](https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/) for the repo server
2862
enabled: false
2863
# -- Labels to be added to repo server vpa
2864
labels: {}
2865
# -- Annotations to be added to repo server vpa
2866
annotations: {}
2867
# -- One of the VPA operation modes
2868
## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically
2869
## Note: Recreate update mode requires more than one replica unless the min-replicas VPA controller flag is overridden
2870
updateMode: Initial
2871
# -- Controls how VPA computes the recommended resources for repo server container
2872
## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/examples/hamster.yaml
2873
containerPolicy: {}
2874
# controlledResources: ["cpu", "memory"]
2875
# minAllowed:
2876
# cpu: 250m
2877
# memory: 256Mi
2878
# maxAllowed:
2879
# cpu: 1
2880
# memory: 1Gi
2881
# -- The recommenders that will provide recommendations for vertical scaling. Only relevant if a named VPA recommender (e.g. one started with a custom recommender name) is in use; leave unset to use the cluster's default recommender
2882
## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/docs/api.md#verticalpodautoscalerspec
2883
## NOTE: specify only zero or one recommender as of VPA 1.7.1
2884
recommenders: []
2885
# -- Configures a startup resource boost for faster cold-start (application boot) resource allocation. NOTE: startupBoost is currently a GKE-specific extension to the VPA API and is only honored on GKE clusters; it is rendered only when set
2886
## Ref: https://cloud.google.com/kubernetes-engine/docs/how-to/boost-application-startup
2887
startupBoost: {}
2888
# cpu:
2889
# type: Factor
2890
# factor: 2
2891
# durationSeconds: 10
2892
## Repo server image
2893
image:
2894
# -- Repository to use for the repo server
2895
# @default -- `""` (defaults to global.image.repository)
2896
repository: ""
2897
# -- Tag to use for the repo server
2898
# @default -- `""` (defaults to global.image.tag)
2899
tag: ""
2900
# -- Image pull policy for the repo server
2901
# @default -- `""` (defaults to global.image.imagePullPolicy)
2902
imagePullPolicy: ""
2903
# -- Secrets with credentials to pull images from a private registry
2904
# @default -- `[]` (defaults to global.imagePullSecrets)
2905
imagePullSecrets: []
2906
# -- Additional command line arguments to pass to repo server
2907
extraArgs: []
2908
# -- Environment variables to pass to repo server
2909
env: []
2910
# -- envFrom to pass to repo server
2911
# @default -- `[]` (See [values.yaml])
2912
envFrom: []
2913
# - configMapRef:
2914
# name: config-map-name
2915
# - secretRef:
2916
# name: secret-name
2917
2918
# -- Specify postStart and preStop lifecycle hooks for your argo-repo-server container
2919
lifecycle: {}
2920
# -- Additional containers to be added to the repo server pod
2921
## Ref: https://argo-cd.readthedocs.io/en/stable/user-guide/config-management-plugins/
2922
## Note: Supports use of custom Helm templates
2923
extraContainers: []
2924
# - name: cmp-my-plugin
2925
# command:
2926
# - "/var/run/argocd/argocd-cmp-server"
2927
# image: busybox
2928
# securityContext:
2929
# runAsNonRoot: true
2930
# runAsUser: 999
2931
# volumeMounts:
2932
# - mountPath: /var/run/argocd
2933
# name: var-files
2934
# - mountPath: /home/argocd/cmp-server/plugins
2935
# name: plugins
2936
# # Remove this volumeMount if you've chosen to bake the config file into the sidecar image.
2937
# - mountPath: /home/argocd/cmp-server/config/plugin.yaml
2938
# subPath: my-plugin.yaml
2939
# name: argocd-cmp-cm
2940
# # Starting with v2.4, do NOT mount the same tmp volume as the repo-server container. The filesystem separation helps
2941
# # mitigate path traversal attacks.
2942
# - mountPath: /tmp
2943
# name: cmp-tmp
2944
# - name: cmp-my-plugin2
2945
# command:
2946
# - "/var/run/argocd/argocd-cmp-server"
2947
# image: busybox
2948
# securityContext:
2949
# runAsNonRoot: true
2950
# runAsUser: 999
2951
# volumeMounts:
2952
# - mountPath: /var/run/argocd
2953
# name: var-files
2954
# # Remove this volumeMount if you've chosen to bake the config file into the sidecar image.
2955
# - mountPath: /home/argocd/cmp-server/plugins
2956
# name: plugins
2957
# - mountPath: /home/argocd/cmp-server/config/plugin.yaml
2958
# subPath: my-plugin2.yaml
2959
# name: argocd-cmp-cm
2960
# # Starting with v2.4, do NOT mount the same tmp volume as the repo-server container. The filesystem separation helps
2961
# # mitigate path traversal attacks.
2962
# - mountPath: /tmp
2963
# name: cmp-tmp
2964
2965
# -- Init containers to add to the repo server pods
2966
initContainers: []
2967
copyutil:
2968
# -- Extra arguments for the cp command in the repo server copyutil initContainer
2969
# @default -- `"--update=none"`
2970
extraArgs: "--update=none"
2971
# -- Resource limits and requests for the repo server copyutil initContainer
2972
resources: {}
2973
# limits:
2974
# cpu: 100m
2975
# memory: 128Mi
2976
# requests:
2977
# cpu: 50m
2978
# memory: 64Mi
2979
# -- Additional volumeMounts to the repo server main container
2980
volumeMounts: []
2981
# -- Additional volumes to the repo server pod
2982
volumes: []
2983
# - name: argocd-cmp-cm
2984
# configMap:
2985
# name: argocd-cmp-cm
2986
# - name: cmp-tmp
2987
# emptyDir: {}
2988
2989
# -- Volumes to be used in replacement of emptydir on default volumes
2990
existingVolumes: {}
2991
# gpgKeyring:
2992
# persistentVolumeClaim:
2993
# claimName: pvc-argocd-repo-server-keyring
2994
# helmWorkingDir:
2995
# persistentVolumeClaim:
2996
# claimName: pvc-argocd-repo-server-workdir
2997
# tmp:
2998
# persistentVolumeClaim:
2999
# claimName: pvc-argocd-repo-server-tmp
3000
# varFiles:
3001
# persistentVolumeClaim:
3002
# claimName: pvc-argocd-repo-server-varfiles
3003
# plugins:
3004
# persistentVolumeClaim:
3005
# claimName: pvc-argocd-repo-server-plugins
3006
3007
## RepoServer emptyDir volumes
3008
emptyDir:
3009
# -- EmptyDir size limit for repo server
3010
# @default -- `""` (defaults not set if not specified i.e. no size limit)
3011
sizeLimit: ""
3012
# sizeLimit: "1Gi"
3013
# -- Toggle the usage of a ephemeral Helm working directory
3014
useEphemeralHelmWorkingDir: true
3015
# -- Annotations to be added to repo server Deployment
3016
deploymentAnnotations: {}
3017
# -- Labels for the repo server Deployment
3018
deploymentLabels: {}
3019
# -- Annotations to be added to repo server pods
3020
podAnnotations: {}
3021
# -- Labels to be added to repo server pods
3022
podLabels: {}
3023
# -- Resource limits and requests for the repo server pods
3024
resources: {}
3025
# limits:
3026
# cpu: 50m
3027
# memory: 128Mi
3028
# requests:
3029
# cpu: 10m
3030
# memory: 64Mi
3031
3032
# Repo server container ports
3033
containerPorts:
3034
# -- Repo server container port
3035
server: 8081
3036
# -- Metrics container port
3037
metrics: 8084
3038
# -- Host Network for Repo server pods
3039
hostNetwork: false
3040
# -- [DNS configuration]
3041
dnsConfig: {}
3042
# -- Alternative DNS policy for Repo server pods
3043
dnsPolicy: "ClusterFirst"
3044
# -- Repo server container-level security context
3045
# @default -- See [values.yaml]
3046
containerSecurityContext:
3047
runAsNonRoot: true
3048
readOnlyRootFilesystem: true
3049
allowPrivilegeEscalation: false
3050
seccompProfile:
3051
type: RuntimeDefault
3052
capabilities:
3053
drop:
3054
- ALL
3055
## Readiness and liveness probes for Repo Server
3056
## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
3057
readinessProbe:
3058
# -- Enable Kubernetes readiness probe for Repo Server
3059
enabled: true
3060
# -- Http path to use for the readiness probe
3061
httpPath: /healthz
3062
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
3063
failureThreshold: 3
3064
# -- Number of seconds after the container has started before [probe] is initiated
3065
initialDelaySeconds: 10
3066
# -- How often (in seconds) to perform the [probe]
3067
periodSeconds: 10
3068
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
3069
successThreshold: 1
3070
# -- Number of seconds after which the [probe] times out
3071
timeoutSeconds: 1
3072
livenessProbe:
3073
# -- Enable Kubernetes liveness probe for Repo Server
3074
enabled: true
3075
# -- Http path to use for the liveness probe
3076
httpPath: /healthz?full=true
3077
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
3078
failureThreshold: 3
3079
# -- Number of seconds after the container has started before [probe] is initiated
3080
initialDelaySeconds: 10
3081
# -- How often (in seconds) to perform the [probe]
3082
periodSeconds: 10
3083
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
3084
successThreshold: 1
3085
# -- Number of seconds after which the [probe] times out
3086
timeoutSeconds: 1
3087
## Startup probe for Repo Server (optional)
3088
## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
3089
startupProbe:
3090
# -- Enable Kubernetes startup probe for Repo Server
3091
enabled: false
3092
# -- Http path to use for the startup probe
3093
httpPath: /healthz
3094
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
3095
failureThreshold: 20
3096
# -- Number of seconds after the container has started before [probe] is initiated
3097
initialDelaySeconds: 10
3098
# -- How often (in seconds) to perform the [probe]
3099
periodSeconds: 10
3100
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
3101
successThreshold: 1
3102
# -- Number of seconds after which the [probe] times out
3103
timeoutSeconds: 1
3104
# -- terminationGracePeriodSeconds for container lifecycle hook
3105
terminationGracePeriodSeconds: 30
3106
# -- [Node selector]
3107
# @default -- `{}` (defaults to global.nodeSelector)
3108
nodeSelector: {}
3109
# -- [Tolerations] for use with node taints
3110
# @default -- `[]` (defaults to global.tolerations)
3111
tolerations: []
3112
# -- Assign custom [affinity] rules to the deployment
3113
# @default -- `{}` (defaults to global.affinity preset)
3114
affinity: {}
3115
# -- Assign custom [TopologySpreadConstraints] rules to the repo server
3116
# @default -- `[]` (defaults to global.topologySpreadConstraints)
3117
## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
3118
## If labelSelector is left out, it will default to the labelSelector configuration of the deployment
3119
topologySpreadConstraints: []
3120
# - maxSkew: 1
3121
# topologyKey: topology.kubernetes.io/zone
3122
# whenUnsatisfiable: DoNotSchedule
3123
3124
# -- Deployment strategy to be added to the repo server Deployment
3125
deploymentStrategy: {}
3126
# type: RollingUpdate
3127
# rollingUpdate:
3128
# maxSurge: 25%
3129
# maxUnavailable: 25%
3130
3131
# -- Priority class for the repo server pods
3132
# @default -- `""` (defaults to global.priorityClassName)
3133
priorityClassName: ""
3134
# TLS certificate configuration via Secret
3135
## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/tls/#configuring-tls-to-argocd-repo-server
3136
## Note: Issuing certificates via cert-manager in not supported right now because it's not possible to restart repo server automatically without extra controllers.
3137
certificateSecret:
3138
# -- Create argocd-repo-server-tls secret
3139
enabled: false
3140
# -- Annotations to be added to argocd-repo-server-tls secret
3141
annotations: {}
3142
# -- Labels to be added to argocd-repo-server-tls secret
3143
labels: {}
3144
# -- Certificate authority. Required for self-signed certificates.
3145
ca: ""
3146
# -- Certificate private key
3147
key: ""
3148
# -- Certificate data. Must contain SANs of Repo service (ie: argocd-repo-server, argocd-repo-server.argo-cd.svc)
3149
crt: ""
3150
## Repo server service configuration
3151
service:
3152
# -- Repo server service annotations
3153
annotations: {}
3154
# -- Repo server service labels
3155
labels: {}
3156
# -- Repo server service port
3157
port: 8081
3158
# -- Repo server service port name
3159
portName: tcp-repo-server
3160
# -- Traffic distribution preference for the repo server service. If the field is not set, the implementation will apply its default routing strategy.
3161
trafficDistribution: ""
3162
## Repo server metrics service configuration
3163
metrics:
3164
# -- Deploy metrics service
3165
enabled: false
3166
service:
3167
# -- Metrics service type
3168
type: ClusterIP
3169
# -- Metrics service clusterIP. `None` makes a "headless service" (no virtual IP)
3170
clusterIP: ""
3171
# -- Metrics service annotations
3172
annotations: {}
3173
# -- Metrics service labels
3174
labels: {}
3175
# -- Metrics service port
3176
servicePort: 8084
3177
# -- Metrics service port name
3178
portName: http-metrics
3179
serviceMonitor:
3180
# -- Enable a prometheus ServiceMonitor
3181
enabled: false
3182
# -- Prometheus ServiceMonitor interval
3183
interval: 30s
3184
# -- Prometheus ServiceMonitor scrapeTimeout. If empty, Prometheus uses the global scrape timeout unless it is less than the target's scrape interval value in which the latter is used.
3185
scrapeTimeout: ""
3186
# -- When true, honorLabels preserves the metric’s labels when they collide with the target’s labels.
3187
honorLabels: false
3188
# -- Prometheus [RelabelConfigs] to apply to samples before scraping
3189
relabelings: []
3190
# -- Prometheus [MetricRelabelConfigs] to apply to samples before ingestion
3191
metricRelabelings: []
3192
# -- Prometheus ServiceMonitor selector
3193
selector: {}
3194
# prometheus: kube-prometheus
3195
3196
# -- Prometheus ServiceMonitor scheme
3197
scheme: ""
3198
# -- Prometheus ServiceMonitor tlsConfig
3199
tlsConfig: {}
3200
# -- Prometheus ServiceMonitor namespace
3201
namespace: "" # "monitoring"
3202
# -- Prometheus ServiceMonitor labels
3203
additionalLabels: {}
3204
# -- Prometheus ServiceMonitor annotations
3205
annotations: {}
3206
## Enable Custom Rules for the Repo server's Cluster Role resource
3207
## Enable this and set the rules: to whatever custom rules you want for the Cluster Role resource.
3208
## Defaults to off
3209
clusterRoleRules:
3210
# -- Enable custom rules for the Repo server's Cluster Role resource
3211
enabled: false
3212
# -- List of custom rules for the Repo server's Cluster Role resource
3213
rules: []
3214
# -- Automount API credentials for the Service Account into the pod.
3215
automountServiceAccountToken: true
3216
## Repo server service account
3217
## If create is set to true, make sure to uncomment the name and update the rbac section below
3218
serviceAccount:
3219
# -- Create repo server service account
3220
create: true
3221
# -- Repo server service account name
3222
name: "" # "argocd-repo-server"
3223
# -- Annotations applied to created service account
3224
annotations: {}
3225
# -- Labels applied to created service account
3226
labels: {}
3227
# -- Automount API credentials for the Service Account
3228
automountServiceAccountToken: true
3229
# -- Repo server rbac rules
3230
rbac: []
3231
# - apiGroups:
3232
# - argoproj.io
3233
# resources:
3234
# - applications
3235
# verbs:
3236
# - get
3237
# - list
3238
# - watch
3239
3240
# Default repo server's network policy
3241
networkPolicy:
3242
# -- Default network policy rules used by repo server
3243
# @default -- `false` (defaults to global.networkPolicy.create)
3244
create: false
3245
## ApplicationSet controller
3246
applicationSet:
3247
# -- ApplicationSet controller name string
3248
name: applicationset-controller
3249
# -- The number of ApplicationSet controller pods to run
3250
replicas: 1
3251
# -- Runtime class name for the ApplicationSet controller
3252
# @default -- `""` (defaults to global.runtimeClassName)
3253
runtimeClassName: ""
3254
## ApplicationSet controller Pod Disruption Budget
3255
## Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
3256
pdb:
3257
# -- Deploy a [PodDisruptionBudget] for the ApplicationSet controller
3258
enabled: false
3259
# -- Labels to be added to ApplicationSet controller pdb
3260
labels: {}
3261
# -- Annotations to be added to ApplicationSet controller pdb
3262
annotations: {}
3263
# -- Number of pods that are available after eviction as number or percentage (eg.: 50%)
3264
# @default -- `""` (defaults to 0 if not specified)
3265
minAvailable: ""
3266
# -- Number of pods that are unavailable after eviction as number or percentage (eg.: 50%).
3267
## Has higher precedence over `applicationSet.pdb.minAvailable`
3268
maxUnavailable: ""
3269
# -- Policy for evicting unhealthy (not ready) pods, either `IfHealthyBudget` or `AlwaysAllow`
3270
## Defaults to `IfHealthyBudget` if not set
3271
unhealthyPodEvictionPolicy: ""
3272
## ApplicationSet controller Vertical Pod Autoscaler
3273
## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/
3274
vpa:
3275
# -- Deploy a [VerticalPodAutoscaler](https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/) for the ApplicationSet controller
3276
enabled: false
3277
# -- Labels to be added to ApplicationSet controller vpa
3278
labels: {}
3279
# -- Annotations to be added to ApplicationSet controller vpa
3280
annotations: {}
3281
# -- One of the VPA operation modes
3282
## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically
3283
## Note: Recreate update mode requires more than one replica unless the min-replicas VPA controller flag is overridden
3284
updateMode: Initial
3285
# -- Controls how VPA computes the recommended resources for ApplicationSet controller container
3286
## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/examples/hamster.yaml
3287
containerPolicy: {}
3288
# controlledResources: ["cpu", "memory"]
3289
# minAllowed:
3290
# cpu: 250m
3291
# memory: 256Mi
3292
# maxAllowed:
3293
# cpu: 1
3294
# memory: 1Gi
3295
# -- The recommenders that will provide recommendations for vertical scaling. Only relevant if a named VPA recommender (e.g. one started with a custom recommender name) is in use; leave unset to use the cluster's default recommender
3296
## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/docs/api.md#verticalpodautoscalerspec
3297
## NOTE: specify only zero or one recommender as of VPA 1.7.1
3298
recommenders: []
3299
# -- Configures a startup resource boost for faster cold-start (application boot) resource allocation. NOTE: startupBoost is currently a GKE-specific extension to the VPA API and is only honored on GKE clusters; it is rendered only when set
3300
## Ref: https://cloud.google.com/kubernetes-engine/docs/how-to/boost-application-startup
3301
startupBoost: {}
3302
# cpu:
3303
# type: Factor
3304
# factor: 2
3305
# durationSeconds: 10
3306
## ApplicationSet controller image
3307
image:
3308
# -- Repository to use for the ApplicationSet controller
3309
# @default -- `""` (defaults to global.image.repository)
3310
repository: ""
3311
# -- Tag to use for the ApplicationSet controller
3312
# @default -- `""` (defaults to global.image.tag)
3313
tag: ""
3314
# -- Image pull policy for the ApplicationSet controller
3315
# @default -- `""` (defaults to global.image.imagePullPolicy)
3316
imagePullPolicy: ""
3317
# -- If defined, uses a Secret to pull an image from a private Docker registry or repository.
3318
# @default -- `[]` (defaults to global.imagePullSecrets)
3319
imagePullSecrets: []
3320
# -- ApplicationSet controller command line flags
3321
extraArgs: []
3322
# -- Environment variables to pass to the ApplicationSet controller
3323
extraEnv: []
3324
# - name: "MY_VAR"
3325
# value: "value"
3326
3327
# -- envFrom to pass to the ApplicationSet controller
3328
# @default -- `[]` (See [values.yaml])
3329
extraEnvFrom: []
3330
# - configMapRef:
3331
# name: config-map-name
3332
# - secretRef:
3333
# name: secret-name
3334
3335
# -- Additional containers to be added to the ApplicationSet controller pod
3336
## Note: Supports use of custom Helm templates
3337
extraContainers: []
3338
# -- Init containers to add to the ApplicationSet controller pod
3339
## Note: Supports use of custom Helm templates
3340
initContainers: []
3341
# -- List of extra mounts to add (normally used with extraVolumes)
3342
extraVolumeMounts: []
3343
# -- List of extra volumes to add
3344
extraVolumes: []
3345
## ApplicationSet controller emptyDir volumes
3346
emptyDir:
3347
# -- EmptyDir size limit for applicationSet controller
3348
# @default -- `""` (defaults not set if not specified i.e. no size limit)
3349
sizeLimit: ""
3350
# sizeLimit: "1Gi"
3351
## Metrics service configuration
3352
metrics:
3353
# -- Deploy metrics service
3354
enabled: false
3355
service:
3356
# -- Metrics service type
3357
type: ClusterIP
3358
# -- Metrics service clusterIP. `None` makes a "headless service" (no virtual IP)
3359
clusterIP: ""
3360
# -- Metrics service annotations
3361
annotations: {}
3362
# -- Metrics service labels
3363
labels: {}
3364
# -- Metrics service port
3365
servicePort: 8080
3366
# -- Metrics service port name
3367
portName: http-metrics
3368
serviceMonitor:
3369
# -- Enable a prometheus ServiceMonitor
3370
enabled: false
3371
# -- Prometheus ServiceMonitor interval
3372
interval: 30s
3373
# -- Prometheus ServiceMonitor scrapeTimeout. If empty, Prometheus uses the global scrape timeout unless it is less than the target's scrape interval value in which the latter is used.
3374
scrapeTimeout: ""
3375
# -- When true, honorLabels preserves the metric’s labels when they collide with the target’s labels.
3376
honorLabels: false
3377
# -- Prometheus [RelabelConfigs] to apply to samples before scraping
3378
relabelings: []
3379
# -- Prometheus [MetricRelabelConfigs] to apply to samples before ingestion
3380
metricRelabelings: []
3381
# -- Prometheus ServiceMonitor selector
3382
selector: {}
3383
# prometheus: kube-prometheus
3384
3385
# -- Prometheus ServiceMonitor scheme
3386
scheme: ""
3387
# -- Prometheus ServiceMonitor tlsConfig
3388
tlsConfig: {}
3389
# -- Prometheus ServiceMonitor namespace
3390
namespace: "" # monitoring
3391
# -- Prometheus ServiceMonitor labels
3392
additionalLabels: {}
3393
# -- Prometheus ServiceMonitor annotations
3394
annotations: {}
3395
## ApplicationSet service configuration
3396
service:
3397
# -- ApplicationSet service annotations
3398
annotations: {}
3399
# -- ApplicationSet service labels
3400
labels: {}
3401
# -- ApplicationSet service type
3402
type: ClusterIP
3403
# -- ApplicationSet service port
3404
port: 7000
3405
# -- ApplicationSet service port name
3406
portName: http-webhook
3407
# -- Automount API credentials for the Service Account into the pod.
3408
automountServiceAccountToken: true
3409
serviceAccount:
3410
# -- Create ApplicationSet controller service account
3411
create: true
3412
# -- ApplicationSet controller service account name
3413
name: argocd-applicationset-controller
3414
# -- Annotations applied to created service account
3415
annotations: {}
3416
# -- Labels applied to created service account
3417
labels: {}
3418
# -- Automount API credentials for the Service Account
3419
automountServiceAccountToken: true
3420
# -- Annotations to be added to ApplicationSet controller Deployment
3421
deploymentAnnotations: {}
3422
# -- Labels for the ApplicationSet controller Deployment
3423
deploymentLabels: {}
3424
# -- Annotations for the ApplicationSet controller pods
3425
podAnnotations: {}
3426
# -- Labels for the ApplicationSet controller pods
3427
podLabels: {}
3428
# -- Resource limits and requests for the ApplicationSet controller pods.
3429
resources: {}
3430
# limits:
3431
# cpu: 100m
3432
# memory: 128Mi
3433
# requests:
3434
# cpu: 100m
3435
# memory: 128Mi
3436
3437
# ApplicationSet controller container ports
3438
containerPorts:
3439
# -- Metrics container port
3440
metrics: 8080
3441
# -- Probe container port
3442
probe: 8081
3443
# -- Webhook container port
3444
webhook: 7000
3445
# -- [DNS configuration]
3446
dnsConfig: {}
3447
# -- Alternative DNS policy for ApplicationSet controller pods
3448
dnsPolicy: "ClusterFirst"
3449
# -- ApplicationSet controller container-level security context
3450
# @default -- See [values.yaml]
3451
containerSecurityContext:
3452
runAsNonRoot: true
3453
readOnlyRootFilesystem: true
3454
allowPrivilegeEscalation: false
3455
seccompProfile:
3456
type: RuntimeDefault
3457
capabilities:
3458
drop:
3459
- ALL
3460
## Probes for ApplicationSet controller (optional)
3461
## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
3462
readinessProbe:
3463
# -- Enable Kubernetes liveness probe for ApplicationSet controller
3464
enabled: false
3465
# -- Number of seconds after the container has started before [probe] is initiated
3466
initialDelaySeconds: 10
3467
# -- How often (in seconds) to perform the [probe]
3468
periodSeconds: 10
3469
# -- Number of seconds after which the [probe] times out
3470
timeoutSeconds: 1
3471
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
3472
successThreshold: 1
3473
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
3474
failureThreshold: 3
3475
livenessProbe:
3476
# -- Enable Kubernetes liveness probe for ApplicationSet controller
3477
enabled: false
3478
# -- Number of seconds after the container has started before [probe] is initiated
3479
initialDelaySeconds: 10
3480
# -- How often (in seconds) to perform the [probe]
3481
periodSeconds: 10
3482
# -- Number of seconds after which the [probe] times out
3483
timeoutSeconds: 1
3484
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
3485
successThreshold: 1
3486
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
3487
failureThreshold: 3
3488
## Startup probe for ApplicationSet controller (optional)
3489
## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
3490
startupProbe:
3491
# -- Enable Kubernetes startup probe for ApplicationSet controller
3492
enabled: false
3493
# -- Number of seconds after the container has started before [probe] is initiated
3494
initialDelaySeconds: 10
3495
# -- How often (in seconds) to perform the [probe]
3496
periodSeconds: 10
3497
# -- Number of seconds after which the [probe] times out
3498
timeoutSeconds: 1
3499
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
3500
successThreshold: 1
3501
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
3502
failureThreshold: 20
3503
# -- terminationGracePeriodSeconds for container lifecycle hook
3504
terminationGracePeriodSeconds: 30
3505
# -- [Node selector]
3506
# @default -- `{}` (defaults to global.nodeSelector)
3507
nodeSelector: {}
3508
# -- [Tolerations] for use with node taints
3509
# @default -- `[]` (defaults to global.tolerations)
3510
tolerations: []
3511
# -- Assign custom [affinity] rules
3512
# @default -- `{}` (defaults to global.affinity preset)
3513
affinity: {}
3514
# -- Assign custom [TopologySpreadConstraints] rules to the ApplicationSet controller
3515
# @default -- `[]` (defaults to global.topologySpreadConstraints)
3516
## Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
3517
## If labelSelector is left out, it will default to the labelSelector configuration of the deployment
3518
topologySpreadConstraints: []
3519
# - maxSkew: 1
3520
# topologyKey: topology.kubernetes.io/zone
3521
# whenUnsatisfiable: DoNotSchedule
3522
3523
# -- Deployment strategy to be added to the ApplicationSet controller Deployment
3524
deploymentStrategy: {}
3525
# type: RollingUpdate
3526
# rollingUpdate:
3527
# maxSurge: 25%
3528
# maxUnavailable: 25%
3529
3530
# -- Priority class for the ApplicationSet controller pods
3531
# @default -- `""` (defaults to global.priorityClassName)
3532
priorityClassName: ""
3533
# TLS certificate configuration via cert-manager
3534
## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/tls/#tls-configuration
3535
certificate:
3536
# -- Deploy a Certificate resource (requires cert-manager)
3537
enabled: false
3538
# -- Certificate primary domain (commonName)
3539
# @default -- `""` (defaults to global.domain)
3540
domain: ""
3541
# -- Certificate Subject Alternate Names (SANs)
3542
additionalHosts: []
3543
# -- The requested 'duration' (i.e. lifetime) of the certificate.
3544
# @default -- `""` (defaults to 2160h = 90d if not specified)
3545
## Ref: https://cert-manager.io/docs/usage/certificate/#renewal
3546
duration: ""
3547
# -- How long before the expiry a certificate should be renewed.
3548
# @default -- `""` (defaults to 360h = 15d if not specified)
3549
## Ref: https://cert-manager.io/docs/usage/certificate/#renewal
3550
renewBefore: ""
3551
# Certificate issuer
3552
## Ref: https://cert-manager.io/docs/concepts/issuer
3553
issuer:
3554
# -- Certificate issuer group. Set if using an external issuer. Eg. `cert-manager.io`
3555
group: ""
3556
# -- Certificate issuer kind. Either `Issuer` or `ClusterIssuer`
3557
kind: ""
3558
# -- Certificate issuer name. Eg. `letsencrypt`
3559
name: ""
3560
# Private key of the certificate
3561
privateKey:
3562
# -- Rotation policy of private key when certificate is re-issued. Either: `Never` or `Always`
3563
rotationPolicy: Never
3564
# -- The private key cryptography standards (PKCS) encoding for private key. Either: `PCKS1` or `PKCS8`
3565
encoding: PKCS1
3566
# -- Algorithm used to generate certificate private key. One of: `RSA`, `Ed25519` or `ECDSA`
3567
algorithm: RSA
3568
# -- Key bit size of the private key. If algorithm is set to `Ed25519`, size is ignored.
3569
size: 2048
3570
# -- Annotations to be applied to the ApplicationSet Certificate
3571
annotations: {}
3572
## Ingress for the Git Generator webhook
3573
## Ref: https://argocd-applicationset.readthedocs.io/en/master/Generators-Git/#webhook-configuration)
3574
ingress:
3575
# -- Enable an ingress resource for ApplicationSet webhook
3576
enabled: false
3577
# -- Additional ingress labels
3578
labels: {}
3579
# -- Additional ingress annotations
3580
annotations: {}
3581
# -- Defines which ingress ApplicationSet controller will implement the resource
3582
ingressClassName: ""
3583
# -- Argo CD ApplicationSet hostname
3584
# @default -- `""` (defaults to global.domain)
3585
hostname: ""
3586
# -- List of ingress paths
3587
path: /api/webhook
3588
# -- Ingress path type. One of `Exact`, `Prefix` or `ImplementationSpecific`
3589
pathType: Prefix
3590
# -- Enable TLS configuration for the hostname defined at `applicationSet.webhook.ingress.hostname`
3591
## TLS certificate will be retrieved from a TLS secret with name:`argocd-applicationset-controller-tls`
3592
tls: false
3593
# -- The list of additional hostnames to be covered by ingress record
3594
# @default -- `[]` (See [values.yaml])
3595
extraHosts: []
3596
# - name: argocd.example.com
3597
# path: /
3598
3599
# -- Additional ingress paths
3600
# @default -- `[]` (See [values.yaml])
3601
extraPaths: []
3602
# - path: /*
3603
# pathType: Prefix
3604
# backend:
3605
# service:
3606
# name: ssl-redirect
3607
# port:
3608
# name: use-annotation
3609
3610
# -- Additional ingress rules
3611
# @default -- `[]` (See [values.yaml])
3612
## Note: Supports use of custom Helm templates
3613
extraRules: []
3614
# - http:
3615
# paths:
3616
# - path: /api/webhook
3617
# pathType: Prefix
3618
# backend:
3619
# service:
3620
# name: '{{ include "argo-cd.applicationSet.fullname" . }}'
3621
# port:
3622
# name: '{{ .Values.applicationSet.service.portName }}'
3623
3624
# -- Additional ingress TLS configuration
3625
# @default -- `[]` (See [values.yaml])
3626
extraTls: []
3627
# - secretName: argocd-applicationset-tls
3628
# hosts:
3629
# - argocd-applicationset.example.com
3630
## Gateway API HTTPRoute for the Git Generator webhook
3631
## Ref: https://argocd-applicationset.readthedocs.io/en/master/Generators-Git/#webhook-configuration)
3632
# NOTE: Gateway API support is in EXPERIMENTAL status
3633
# Support depends on your Gateway controller implementation
3634
# Some controllers may require additional configuration (e.g., BackendTLSPolicy for HTTPS backends)
3635
# Refer to https://gateway-api.sigs.k8s.io/implementations/ for controller-specific details
3636
httproute:
3637
# -- Enable HTTPRoute resource for Argo CD Applicationset Webhook (Gateway API)
3638
enabled: false
3639
# -- Additional HTTPRoute labels
3640
labels: {}
3641
# -- Additional HTTPRoute annotations
3642
annotations: {}
3643
# -- Gateway API parentRefs for the HTTPRoute
3644
## Must reference an existing Gateway
3645
# @default -- `[]` (See [values.yaml])
3646
parentRefs: []
3647
# - name: example-gateway
3648
# namespace: example-gateway-namespace
3649
# sectionName: https
3650
# -- List of hostnames for the HTTPRoute
3651
# @default -- `[]` (See [values.yaml])
3652
hostnames: []
3653
# - argocd.example.com
3654
# -- HTTPRoute rules configuration
3655
# @default -- `[]` (See [values.yaml])
3656
rules:
3657
- matches:
3658
- path:
3659
type: PathPrefix
3660
value: /api/webhook
3661
# filters: []
3662
# - type: RequestHeaderModifier
3663
# requestHeaderModifier:
3664
# add:
3665
# - name: X-Custom-Header
3666
# value: custom-value
3667
# Gateway API ListenerSet configuration for the Git Generator webhook
3668
## Ref: https://argocd-applicationset.readthedocs.io/en/master/Generators-Git/#webhook-configuration
3669
# NOTE: Gateway API support is in EXPERIMENTAL status
3670
# ListenerSet allows attaching additional listeners to an existing Gateway
3671
# Requires Gateway API v1alpha2 and a controller that supports ListenerSet
3672
# Refer to https://gateway-api.sigs.k8s.io/reference/spec/#gateway.networking.k8s.io/v1alpha2.ListenerSet
3673
listenerset:
3674
# -- Enable ListenerSet resource for Argo CD ApplicationSet webhook (Gateway API)
3675
enabled: false
3676
# -- Additional ListenerSet labels
3677
labels: {}
3678
# -- Additional ListenerSet annotations
3679
annotations: {}
3680
# -- Gateway API parentRef for the ListenerSet
3681
## Must reference an existing Gateway. Unlike HTTPRoute, ListenerSet accepts exactly one parentRef.
3682
# @default -- `{}` (See [values.yaml])
3683
parentRef: {}
3684
# name: example-gateway
3685
# namespace: example-gateway-namespace
3686
# -- Hostname for the synthesized listener. Defaults to global.domain when empty.
3687
hostname: ""
3688
# -- Name of the synthesized listener. Also used as sectionName in auto-derived httproute parentRefs.
3689
listenerName: https
3690
# -- Port for the synthesized listener
3691
port: 443
3692
# -- Protocol for the synthesized listener
3693
protocol: HTTPS
3694
# -- TLS configuration for the synthesized listener
3695
tls:
3696
# -- Enable TLS on the synthesized listener
3697
enabled: true
3698
# -- TLS termination mode
3699
mode: Terminate
3700
# -- Secret name for TLS certificate. Defaults to `argocd-applicationset-controller-tls` when empty.
3701
secretName: ""
3702
# -- allowedRoutes for the synthesized listener
3703
allowedRoutes:
3704
namespaces:
3705
from: Same
3706
# -- Listeners to attach to the parent Gateway. When non-empty, used verbatim and all synthesized listener fields above are ignored.
3707
# @default -- `[]` (See [values.yaml])
3708
listeners: []
3709
# - name: https
3710
# port: 443
3711
# protocol: HTTPS
3712
# hostname: argocd.example.com
3713
# tls:
3714
# mode: Terminate
3715
# certificateRefs:
3716
# - group: ""
3717
# kind: Secret
3718
# name: argocd-applicationset-controller-tls
3719
# allowedRoutes:
3720
# namespaces:
3721
# from: Same
3722
# -- Enable ApplicationSet in any namespace feature
3723
allowAnyNamespace: false
3724
# Default ApplicationSet controller's network policy
3725
networkPolicy:
3726
# -- Default network policy rules used by ApplicationSet controller
3727
# @default -- `false` (defaults to global.networkPolicy.create)
3728
create: false
3729
## Notifications controller
3730
notifications:
3731
# -- Enable notifications controller
3732
enabled: true
3733
# -- Notifications controller name string
3734
name: notifications-controller
3735
# -- Argo CD dashboard url; used in place of {{.context.argocdUrl}} in templates
3736
# @default -- `""` (defaults to https://`global.domain`)
3737
argocdUrl: ""
3738
# -- Runtime class name for the notifications controller
3739
# @default -- `""` (defaults to global.runtimeClassName)
3740
runtimeClassName: ""
3741
## Notifications controller Pod Disruption Budget
3742
## Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
3743
pdb:
3744
# -- Deploy a [PodDisruptionBudget] for the notifications controller
3745
enabled: false
3746
# -- Labels to be added to notifications controller pdb
3747
labels: {}
3748
# -- Annotations to be added to notifications controller pdb
3749
annotations: {}
3750
# -- Number of pods that are available after eviction as number or percentage (eg.: 50%)
3751
# @default -- `""` (defaults to 0 if not specified)
3752
minAvailable: ""
3753
# -- Number of pods that are unavailable after eviction as number or percentage (eg.: 50%).
3754
## Has higher precedence over `notifications.pdb.minAvailable`
3755
maxUnavailable: ""
3756
# -- Policy for evicting unhealthy (not ready) pods, either `IfHealthyBudget` or `AlwaysAllow`
3757
## Defaults to `IfHealthyBudget` if not set
3758
unhealthyPodEvictionPolicy: ""
3759
## Notifications controller Vertical Pod Autoscaler
3760
## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/
3761
vpa:
3762
# -- Deploy a [VerticalPodAutoscaler](https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/) for the notifications controller
3763
enabled: false
3764
# -- Labels to be added to notifications controller vpa
3765
labels: {}
3766
# -- Annotations to be added to notifications controller vpa
3767
annotations: {}
3768
# -- One of the VPA operation modes
3769
## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically
3770
## Note: Recreate update mode requires more than one replica unless the min-replicas VPA controller flag is overridden
3771
updateMode: Initial
3772
# -- Controls how VPA computes the recommended resources for notifications controller container
3773
## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/examples/hamster.yaml
3774
containerPolicy: {}
3775
# controlledResources: ["cpu", "memory"]
3776
# minAllowed:
3777
# cpu: 250m
3778
# memory: 256Mi
3779
# maxAllowed:
3780
# cpu: 1
3781
# memory: 1Gi
3782
# -- The recommenders that will provide recommendations for vertical scaling. Only relevant if a named VPA recommender (e.g. one started with a custom recommender name) is in use; leave unset to use the cluster's default recommender
3783
## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/docs/api.md#verticalpodautoscalerspec
3784
## NOTE: specify only zero or one recommender as of VPA 1.7.1
3785
recommenders: []
3786
# -- Configures a startup resource boost for faster cold-start (application boot) resource allocation. NOTE: startupBoost is currently a GKE-specific extension to the VPA API and is only honored on GKE clusters; it is rendered only when set
3787
## Ref: https://cloud.google.com/kubernetes-engine/docs/how-to/boost-application-startup
3788
startupBoost: {}
3789
# cpu:
3790
# type: Factor
3791
# factor: 2
3792
# durationSeconds: 10
3793
## Notifications controller image
3794
image:
3795
# -- Repository to use for the notifications controller
3796
# @default -- `""` (defaults to global.image.repository)
3797
repository: ""
3798
# -- Tag to use for the notifications controller
3799
# @default -- `""` (defaults to global.image.tag)
3800
tag: ""
3801
# -- Image pull policy for the notifications controller
3802
# @default -- `""` (defaults to global.image.imagePullPolicy)
3803
imagePullPolicy: ""
3804
# -- Secrets with credentials to pull images from a private registry
3805
# @default -- `[]` (defaults to global.imagePullSecrets)
3806
imagePullSecrets: []
3807
# DEPRECATED - Use configs.params to override
3808
# -- Notifications controller log format. Either `text` or `json`
3809
# @default -- `""` (defaults to global.logging.format)
3810
# logFormat: ""
3811
# -- Notifications controller log level. One of: `debug`, `info`, `warn`, `error`
3812
# @default -- `""` (defaults to global.logging.level)
3813
# logLevel: ""
3814
3815
# -- Extra arguments to provide to the notifications controller
3816
extraArgs: []
3817
# -- Additional container environment variables
3818
extraEnv: []
3819
# -- envFrom to pass to the notifications controller
3820
# @default -- `[]` (See [values.yaml])
3821
extraEnvFrom: []
3822
# - configMapRef:
3823
# name: config-map-name
3824
# - secretRef:
3825
# name: secret-name
3826
3827
# -- Additional containers to be added to the notifications controller pod
3828
## Note: Supports use of custom Helm templates
3829
extraContainers: []
3830
# -- Init containers to add to the notifications controller pod
3831
## Note: Supports use of custom Helm templates
3832
initContainers: []
3833
# -- List of extra mounts to add (normally used with extraVolumes)
3834
extraVolumeMounts: []
3835
# -- List of extra volumes to add
3836
extraVolumes: []
3837
# -- Define user-defined context
3838
## For more information: https://argo-cd.readthedocs.io/en/stable/operator-manual/notifications/templates/#defining-user-defined-context
3839
context: {}
3840
# region: east
3841
# environmentName: staging
3842
3843
secret:
3844
# -- Whether helm chart creates notifications controller secret
3845
## If true, will create a secret with the name below. Otherwise, will assume existence of a secret with that name.
3846
create: true
3847
# -- notifications controller Secret name
3848
name: "argocd-notifications-secret"
3849
# -- key:value pairs of annotations to be added to the secret
3850
annotations: {}
3851
# -- key:value pairs of labels to be added to the secret
3852
labels: {}
3853
# -- Generic key:value pairs to be inserted into the secret
3854
## Can be used for templates, notification services etc. Some examples given below.
3855
## For more information: https://argo-cd.readthedocs.io/en/stable/operator-manual/notifications/services/overview/
3856
items: {}
3857
# slack-token:
3858
# # For more information: https://argo-cd.readthedocs.io/en/stable/operator-manual/notifications/services/slack/
3859
# grafana-apiKey:
3860
# # For more information: https://argo-cd.readthedocs.io/en/stable/operator-manual/notifications/services/grafana/
3861
3862
# webhooks-github-token:
3863
3864
# email-username:
3865
# email-password:
3866
# For more information: https://argo-cd.readthedocs.io/en/stable/operator-manual/notifications/services/email/
3867
3868
metrics:
3869
# -- Enables prometheus metrics server
3870
enabled: false
3871
# -- Metrics port
3872
port: 9001
3873
service:
3874
# -- Metrics service type
3875
type: ClusterIP
3876
# -- Metrics service clusterIP. `None` makes a "headless service" (no virtual IP)
3877
clusterIP: ""
3878
# -- Metrics service annotations
3879
annotations: {}
3880
# -- Metrics service labels
3881
labels: {}
3882
# -- Metrics service port name
3883
portName: http-metrics
3884
serviceMonitor:
3885
# -- Enable a prometheus ServiceMonitor
3886
enabled: false
3887
# -- Prometheus ServiceMonitor selector
3888
selector: {}
3889
# prometheus: kube-prometheus
3890
# -- Prometheus ServiceMonitor labels
3891
additionalLabels: {}
3892
# -- Prometheus ServiceMonitor annotations
3893
annotations: {}
3894
# namespace: monitoring
3895
# interval: 30s
3896
# scrapeTimeout: 10s
3897
# -- Prometheus ServiceMonitor scheme
3898
scheme: ""
3899
# -- Prometheus ServiceMonitor tlsConfig
3900
tlsConfig: {}
3901
# -- When true, honorLabels preserves the metric’s labels when they collide with the target’s labels.
3902
honorLabels: false
3903
# -- Prometheus [RelabelConfigs] to apply to samples before scraping
3904
relabelings: []
3905
# -- Prometheus [MetricRelabelConfigs] to apply to samples before ingestion
3906
metricRelabelings: []
3907
# -- Configures notification services such as slack, email or custom webhook
3908
# @default -- See [values.yaml]
3909
## For more information: https://argo-cd.readthedocs.io/en/stable/operator-manual/notifications/services/overview/
3910
notifiers: {}
3911
# service.slack: |
3912
# token: $slack-token
3913
3914
# -- Annotations to be applied to the notifications controller Deployment
3915
deploymentAnnotations: {}
3916
# -- Labels for the notifications controller Deployment
3917
deploymentLabels: {}
3918
# -- Annotations to be applied to the notifications controller Pods
3919
podAnnotations: {}
3920
# -- Labels to be applied to the notifications controller Pods
3921
podLabels: {}
3922
# -- Resource limits and requests for the notifications controller
3923
resources: {}
3924
# limits:
3925
# cpu: 100m
3926
# memory: 128Mi
3927
# requests:
3928
# cpu: 100m
3929
# memory: 128Mi
3930
3931
# Notification controller container ports
3932
containerPorts:
3933
# -- Metrics container port
3934
metrics: 9001
3935
# -- [DNS configuration]
3936
dnsConfig: {}
3937
# -- Alternative DNS policy for notifications controller Pods
3938
dnsPolicy: "ClusterFirst"
3939
# -- Notification controller container-level security Context
3940
# @default -- See [values.yaml]
3941
containerSecurityContext:
3942
runAsNonRoot: true
3943
readOnlyRootFilesystem: true
3944
allowPrivilegeEscalation: false
3945
seccompProfile:
3946
type: RuntimeDefault
3947
capabilities:
3948
drop:
3949
- ALL
3950
## Probes for notifications controller Pods (optional)
3951
## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
3952
readinessProbe:
3953
# -- Enable Kubernetes liveness probe for notifications controller Pods
3954
enabled: false
3955
# -- Number of seconds after the container has started before [probe] is initiated
3956
initialDelaySeconds: 10
3957
# -- How often (in seconds) to perform the [probe]
3958
periodSeconds: 10
3959
# -- Number of seconds after which the [probe] times out
3960
timeoutSeconds: 1
3961
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
3962
successThreshold: 1
3963
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
3964
failureThreshold: 3
3965
livenessProbe:
3966
# -- Enable Kubernetes liveness probe for notifications controller Pods
3967
enabled: false
3968
# -- Number of seconds after the container has started before [probe] is initiated
3969
initialDelaySeconds: 10
3970
# -- How often (in seconds) to perform the [probe]
3971
periodSeconds: 10
3972
# -- Number of seconds after which the [probe] times out
3973
timeoutSeconds: 1
3974
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
3975
successThreshold: 1
3976
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
3977
failureThreshold: 3
3978
## Startup probe for notifications controller Pods (optional)
3979
## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
3980
startupProbe:
3981
# -- Enable Kubernetes startup probe for notifications controller Pods
3982
enabled: false
3983
# -- Number of seconds after the container has started before [probe] is initiated
3984
initialDelaySeconds: 10
3985
# -- How often (in seconds) to perform the [probe]
3986
periodSeconds: 10
3987
# -- Number of seconds after which the [probe] times out
3988
timeoutSeconds: 1
3989
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
3990
successThreshold: 1
3991
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
3992
failureThreshold: 20
3993
# -- terminationGracePeriodSeconds for container lifecycle hook
3994
terminationGracePeriodSeconds: 30
3995
# -- [Node selector]
3996
# @default -- `{}` (defaults to global.nodeSelector)
3997
nodeSelector: {}
3998
# -- [Tolerations] for use with node taints
3999
# @default -- `[]` (defaults to global.tolerations)
4000
tolerations: []
4001
# -- Assign custom [affinity] rules
4002
# @default -- `{}` (defaults to global.affinity preset)
4003
affinity: {}
4004
# -- Assign custom [TopologySpreadConstraints] rules to the application controller
4005
# @default -- `[]` (defaults to global.topologySpreadConstraints)
4006
## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
4007
## If labelSelector is left out, it will default to the labelSelector configuration of the deployment
4008
topologySpreadConstraints: []
4009
# - maxSkew: 1
4010
# topologyKey: topology.kubernetes.io/zone
4011
# whenUnsatisfiable: DoNotSchedule
4012
4013
# -- Deployment strategy to be added to the notifications controller Deployment
4014
deploymentStrategy:
4015
type: Recreate
4016
# -- Priority class for the notifications controller pods
4017
# @default -- `""` (defaults to global.priorityClassName)
4018
priorityClassName: ""
4019
# -- Automount API credentials for the Service Account into the pod.
4020
automountServiceAccountToken: true
4021
serviceAccount:
4022
# -- Create notifications controller service account
4023
create: true
4024
# -- Notification controller service account name
4025
name: argocd-notifications-controller
4026
# -- Annotations applied to created service account
4027
annotations: {}
4028
# -- Labels applied to created service account
4029
labels: {}
4030
# -- Automount API credentials for the Service Account
4031
automountServiceAccountToken: true
4032
cm:
4033
# -- Whether helm chart creates notifications controller config map
4034
create: true
4035
## Enable this and set the rules: to whatever custom rules you want for the Cluster Role resource.
4036
## Defaults to off
4037
clusterRoleRules:
4038
# -- List of custom rules for the notifications controller's ClusterRole resource
4039
rules: []
4040
# -- Contains centrally managed global application subscriptions
4041
## For more information: https://argo-cd.readthedocs.io/en/stable/operator-manual/notifications/subscriptions/
4042
subscriptions: []
4043
# # subscription for on-sync-status-unknown trigger notifications
4044
# - recipients:
4045
# - slack:test2
4046
# - email:test@gmail.com
4047
# triggers:
4048
# - on-sync-status-unknown
4049
# # subscription restricted to applications with matching labels only
4050
# - recipients:
4051
# - slack:test3
4052
# selector: test=true
4053
# triggers:
4054
# - on-sync-status-unknown
4055
4056
# -- The notification template is used to generate the notification content
4057
## For more information: https://argo-cd.readthedocs.io/en/stable/operator-manual/notifications/templates/
4058
templates: {}
4059
# template.app-deployed: |
4060
# email:
4061
# subject: New version of an application {{.app.metadata.name}} is up and running.
4062
# message: |
4063
# {{if eq .serviceType "slack"}}:white_check_mark:{{end}} Application {{.app.metadata.name}} is now running new version of deployments manifests.
4064
# slack:
4065
# attachments: |
4066
# [{
4067
# "title": "{{ .app.metadata.name}}",
4068
# "title_link":"{{.context.argocdUrl}}/applications/{{.app.metadata.name}}",
4069
# "color": "#18be52",
4070
# "fields": [
4071
# {
4072
# "title": "Sync Status",
4073
# "value": "{{.app.status.sync.status}}",
4074
# "short": true
4075
# },
4076
# {
4077
# "title": "Repository",
4078
# "value": "{{.app.spec.source.repoURL}}",
4079
# "short": true
4080
# },
4081
# {
4082
# "title": "Revision",
4083
# "value": "{{.app.status.sync.revision}}",
4084
# "short": true
4085
# }
4086
# {{range $index, $c := .app.status.conditions}}
4087
# {{if not $index}},{{end}}
4088
# {{if $index}},{{end}}
4089
# {
4090
# "title": "{{$c.type}}",
4091
# "value": "{{$c.message}}",
4092
# "short": true
4093
# }
4094
# {{end}}
4095
# ]
4096
# }]
4097
# template.app-health-degraded: |
4098
# email:
4099
# subject: Application {{.app.metadata.name}} has degraded.
4100
# message: |
4101
# {{if eq .serviceType "slack"}}:exclamation:{{end}} Application {{.app.metadata.name}} has degraded.
4102
# Application details: {{.context.argocdUrl}}/applications/{{.app.metadata.name}}.
4103
# slack:
4104
# attachments: |-
4105
# [{
4106
# "title": "{{ .app.metadata.name}}",
4107
# "title_link": "{{.context.argocdUrl}}/applications/{{.app.metadata.name}}",
4108
# "color": "#f4c030",
4109
# "fields": [
4110
# {
4111
# "title": "Sync Status",
4112
# "value": "{{.app.status.sync.status}}",
4113
# "short": true
4114
# },
4115
# {
4116
# "title": "Repository",
4117
# "value": "{{.app.spec.source.repoURL}}",
4118
# "short": true
4119
# }
4120
# {{range $index, $c := .app.status.conditions}}
4121
# {{if not $index}},{{end}}
4122
# {{if $index}},{{end}}
4123
# {
4124
# "title": "{{$c.type}}",
4125
# "value": "{{$c.message}}",
4126
# "short": true
4127
# }
4128
# {{end}}
4129
# ]
4130
# }]
4131
# template.app-sync-failed: |
4132
# email:
4133
# subject: Failed to sync application {{.app.metadata.name}}.
4134
# message: |
4135
# {{if eq .serviceType "slack"}}:exclamation:{{end}} The sync operation of application {{.app.metadata.name}} has failed at {{.app.status.operationState.finishedAt}} with the following error: {{.app.status.operationState.message}}
4136
# Sync operation details are available at: {{.context.argocdUrl}}/applications/{{.app.metadata.name}}?operation=true .
4137
# slack:
4138
# attachments: |-
4139
# [{
4140
# "title": "{{ .app.metadata.name}}",
4141
# "title_link":"{{.context.argocdUrl}}/applications/{{.app.metadata.name}}",
4142
# "color": "#E96D76",
4143
# "fields": [
4144
# {
4145
# "title": "Sync Status",
4146
# "value": "{{.app.status.sync.status}}",
4147
# "short": true
4148
# },
4149
# {
4150
# "title": "Repository",
4151
# "value": "{{.app.spec.source.repoURL}}",
4152
# "short": true
4153
# }
4154
# {{range $index, $c := .app.status.conditions}}
4155
# {{if not $index}},{{end}}
4156
# {{if $index}},{{end}}
4157
# {
4158
# "title": "{{$c.type}}",
4159
# "value": "{{$c.message}}",
4160
# "short": true
4161
# }
4162
# {{end}}
4163
# ]
4164
# }]
4165
# template.app-sync-running: |
4166
# email:
4167
# subject: Start syncing application {{.app.metadata.name}}.
4168
# message: |
4169
# The sync operation of application {{.app.metadata.name}} has started at {{.app.status.operationState.startedAt}}.
4170
# Sync operation details are available at: {{.context.argocdUrl}}/applications/{{.app.metadata.name}}?operation=true .
4171
# slack:
4172
# attachments: |-
4173
# [{
4174
# "title": "{{ .app.metadata.name}}",
4175
# "title_link":"{{.context.argocdUrl}}/applications/{{.app.metadata.name}}",
4176
# "color": "#0DADEA",
4177
# "fields": [
4178
# {
4179
# "title": "Sync Status",
4180
# "value": "{{.app.status.sync.status}}",
4181
# "short": true
4182
# },
4183
# {
4184
# "title": "Repository",
4185
# "value": "{{.app.spec.source.repoURL}}",
4186
# "short": true
4187
# }
4188
# {{range $index, $c := .app.status.conditions}}
4189
# {{if not $index}},{{end}}
4190
# {{if $index}},{{end}}
4191
# {
4192
# "title": "{{$c.type}}",
4193
# "value": "{{$c.message}}",
4194
# "short": true
4195
# }
4196
# {{end}}
4197
# ]
4198
# }]
4199
# template.app-sync-status-unknown: |
4200
# email:
4201
# subject: Application {{.app.metadata.name}} sync status is 'Unknown'
4202
# message: |
4203
# {{if eq .serviceType "slack"}}:exclamation:{{end}} Application {{.app.metadata.name}} sync is 'Unknown'.
4204
# Application details: {{.context.argocdUrl}}/applications/{{.app.metadata.name}}.
4205
# {{if ne .serviceType "slack"}}
4206
# {{range $c := .app.status.conditions}}
4207
# * {{$c.message}}
4208
# {{end}}
4209
# {{end}}
4210
# slack:
4211
# attachments: |-
4212
# [{
4213
# "title": "{{ .app.metadata.name}}",
4214
# "title_link":"{{.context.argocdUrl}}/applications/{{.app.metadata.name}}",
4215
# "color": "#E96D76",
4216
# "fields": [
4217
# {
4218
# "title": "Sync Status",
4219
# "value": "{{.app.status.sync.status}}",
4220
# "short": true
4221
# },
4222
# {
4223
# "title": "Repository",
4224
# "value": "{{.app.spec.source.repoURL}}",
4225
# "short": true
4226
# }
4227
# {{range $index, $c := .app.status.conditions}}
4228
# {{if not $index}},{{end}}
4229
# {{if $index}},{{end}}
4230
# {
4231
# "title": "{{$c.type}}",
4232
# "value": "{{$c.message}}",
4233
# "short": true
4234
# }
4235
# {{end}}
4236
# ]
4237
# }]
4238
# template.app-sync-succeeded: |
4239
# email:
4240
# subject: Application {{.app.metadata.name}} has been successfully synced.
4241
# message: |
4242
# {{if eq .serviceType "slack"}}:white_check_mark:{{end}} Application {{.app.metadata.name}} has been successfully synced at {{.app.status.operationState.finishedAt}}.
4243
# Sync operation details are available at: {{.context.argocdUrl}}/applications/{{.app.metadata.name}}?operation=true .
4244
# slack:
4245
# attachments: |-
4246
# [{
4247
# "title": "{{ .app.metadata.name}}",
4248
# "title_link":"{{.context.argocdUrl}}/applications/{{.app.metadata.name}}",
4249
# "color": "#18be52",
4250
# "fields": [
4251
# {
4252
# "title": "Sync Status",
4253
# "value": "{{.app.status.sync.status}}",
4254
# "short": true
4255
# },
4256
# {
4257
# "title": "Repository",
4258
# "value": "{{.app.spec.source.repoURL}}",
4259
# "short": true
4260
# }
4261
# {{range $index, $c := .app.status.conditions}}
4262
# {{if not $index}},{{end}}
4263
# {{if $index}},{{end}}
4264
# {
4265
# "title": "{{$c.type}}",
4266
# "value": "{{$c.message}}",
4267
# "short": true
4268
# }
4269
# {{end}}
4270
# ]
4271
# }]
4272
4273
# -- The trigger defines the condition when the notification should be sent
4274
## For more information: https://argo-cd.readthedocs.io/en/stable/operator-manual/notifications/triggers/
4275
triggers: {}
4276
# trigger.on-deployed: |
4277
# - description: Application is synced and healthy. Triggered once per commit.
4278
# oncePer: app.status.sync.revision
4279
# send:
4280
# - app-deployed
4281
# when: app.status.operationState.phase in ['Succeeded'] and app.status.health.status == 'Healthy'
4282
# trigger.on-health-degraded: |
4283
# - description: Application has degraded
4284
# send:
4285
# - app-health-degraded
4286
# when: app.status.health.status == 'Degraded'
4287
# trigger.on-sync-failed: |
4288
# - description: Application syncing has failed
4289
# send:
4290
# - app-sync-failed
4291
# when: app.status.operationState.phase in ['Error', 'Failed']
4292
# trigger.on-sync-running: |
4293
# - description: Application is being synced
4294
# send:
4295
# - app-sync-running
4296
# when: app.status.operationState.phase in ['Running']
4297
# trigger.on-sync-status-unknown: |
4298
# - description: Application status is 'Unknown'
4299
# send:
4300
# - app-sync-status-unknown
4301
# when: app.status.sync.status == 'Unknown'
4302
# trigger.on-sync-succeeded: |
4303
# - description: Application syncing has succeeded
4304
# send:
4305
# - app-sync-succeeded
4306
# when: app.status.operationState.phase in ['Succeeded']
4307
#
4308
# For more information: https://argo-cd.readthedocs.io/en/stable/operator-manual/notifications/triggers/#default-triggers
4309
# defaultTriggers: |
4310
# - on-sync-status-unknown
4311
4312
# Default notifications controller's network policy
4313
networkPolicy:
4314
# -- Default network policy rules used by notifications controller
4315
# @default -- `false` (defaults to global.networkPolicy.create)
4316
create: false
4317
commitServer:
4318
# -- Enable commit server
4319
enabled: false
4320
# -- Commit server name
4321
name: commit-server
4322
# -- Runtime class name for the commit server
4323
# @default -- `""` (defaults to global.runtimeClassName)
4324
runtimeClassName: ""
4325
## commit server controller image
4326
image:
4327
# -- Repository to use for the commit server
4328
# @default -- `""` (defaults to global.image.repository)
4329
repository: ""
4330
# -- Tag to use for the commit server
4331
# @default -- `""` (defaults to global.image.tag)
4332
tag: ""
4333
# -- Image pull policy for the commit server
4334
# @default -- `""` (defaults to global.image.imagePullPolicy)
4335
imagePullPolicy: ""
4336
# -- commit server command line flags
4337
extraArgs: []
4338
# -- Environment variables to pass to the commit server
4339
extraEnv: []
4340
# - name: "MY_VAR"
4341
# value: "value"
4342
4343
# -- envFrom to pass to the commit server
4344
# @default -- `[]` (See [values.yaml])
4345
extraEnvFrom: []
4346
# - configMapRef:
4347
# name: config-map-name
4348
# - secretRef:
4349
# name: secret-name
4350
4351
# -- List of extra mounts to add (normally used with extraVolumes)
4352
extraVolumeMounts: []
4353
# -- List of extra volumes to add
4354
extraVolumes: []
4355
metrics:
4356
# -- Enables prometheus metrics server
4357
enabled: false
4358
service:
4359
# -- Metrics service type
4360
type: ClusterIP
4361
# -- Metrics service clusterIP. `None` makes a "headless service" (no virtual IP)
4362
clusterIP: ""
4363
# -- Metrics service annotations
4364
annotations: {}
4365
# -- Metrics service labels
4366
labels: {}
4367
# -- Metrics service port
4368
servicePort: 8087
4369
# -- Metrics service port name
4370
portName: metrics
4371
## commit server service configuration
4372
service:
4373
# -- commit server service annotations
4374
annotations: {}
4375
# -- commit server service labels
4376
labels: {}
4377
# -- commit server service port
4378
port: 8086
4379
# -- commit server service port name
4380
portName: server
4381
# -- Automount API credentials for the Service Account into the pod.
4382
automountServiceAccountToken: false
4383
serviceAccount:
4384
# -- Create commit server service account
4385
create: true
4386
# -- commit server service account name
4387
name: argocd-commit-server
4388
# -- Annotations applied to created service account
4389
annotations: {}
4390
# -- Labels applied to created service account
4391
labels: {}
4392
# -- Automount API credentials for the Service Account
4393
automountServiceAccountToken: true
4394
# -- Annotations to be added to commit server Deployment
4395
deploymentAnnotations: {}
4396
# -- Labels for the commit server Deployment
4397
deploymentLabels: {}
4398
# -- Annotations for the commit server pods
4399
podAnnotations: {}
4400
# -- Labels for the commit server pods
4401
podLabels: {}
4402
# -- Resource limits and requests for the commit server pods.
4403
resources: {}
4404
# limits:
4405
# cpu: 100m
4406
# memory: 128Mi
4407
# requests:
4408
# cpu: 100m
4409
# memory: 128Mi
4410
4411
# -- [DNS configuration]
4412
dnsConfig: {}
4413
# -- Alternative DNS policy for commit server pods
4414
dnsPolicy: "ClusterFirst"
4415
# -- commit server container-level security context
4416
# @default -- See [values.yaml]
4417
containerSecurityContext:
4418
runAsNonRoot: true
4419
readOnlyRootFilesystem: true
4420
allowPrivilegeEscalation: false
4421
capabilities:
4422
drop:
4423
- ALL
4424
seccompProfile:
4425
type: RuntimeDefault
4426
## Probes for commit server (optional)
4427
## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
4428
readinessProbe:
4429
# -- Enable Kubernetes liveness probe for commit server
4430
enabled: true
4431
# -- Http path to use for the readiness probe
4432
httpPath: /healthz
4433
# -- Number of seconds after the container has started before [probe] is initiated
4434
initialDelaySeconds: 5
4435
# -- How often (in seconds) to perform the [probe]
4436
periodSeconds: 10
4437
# -- Number of seconds after which the [probe] times out
4438
timeoutSeconds: 1
4439
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
4440
failureThreshold: 3
4441
livenessProbe:
4442
# -- Enable Kubernetes liveness probe for commit server
4443
enabled: true
4444
# -- Http path to use for the liveness probe
4445
httpPath: /healthz?full=true
4446
# -- Number of seconds after the container has started before [probe] is initiated
4447
initialDelaySeconds: 30
4448
# -- How often (in seconds) to perform the [probe]
4449
periodSeconds: 30
4450
# -- Number of seconds after which the [probe] times out
4451
timeoutSeconds: 5
4452
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
4453
failureThreshold: 3
4454
## Startup probe for commit server (optional)
4455
## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
4456
startupProbe:
4457
# -- Enable Kubernetes startup probe for commit server
4458
enabled: false
4459
# -- Http path to use for the startup probe
4460
httpPath: /healthz
4461
# -- Number of seconds after the container has started before [probe] is initiated
4462
initialDelaySeconds: 10
4463
# -- How often (in seconds) to perform the [probe]
4464
periodSeconds: 10
4465
# -- Number of seconds after which the [probe] times out
4466
timeoutSeconds: 1
4467
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
4468
failureThreshold: 20
4469
# -- terminationGracePeriodSeconds for container lifecycle hook
4470
terminationGracePeriodSeconds: 30
4471
# -- [Node selector]
4472
# @default -- `{}` (defaults to global.nodeSelector)
4473
nodeSelector: {}
4474
# -- [Tolerations] for use with node taints
4475
# @default -- `[]` (defaults to global.tolerations)
4476
tolerations: []
4477
# -- Assign custom [affinity] rules
4478
# @default -- `{}` (defaults to global.affinity preset)
4479
affinity: {}
4480
# -- Assign custom [TopologySpreadConstraints] rules to the commit server
4481
# @default -- `[]` (defaults to global.topologySpreadConstraints)
4482
## Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
4483
## If labelSelector is left out, it will default to the labelSelector configuration of the deployment
4484
topologySpreadConstraints: []
4485
# - maxSkew: 1
4486
# topologyKey: topology.kubernetes.io/zone
4487
# whenUnsatisfiable: DoNotSchedule
4488
4489
# -- Deployment strategy to be added to the commit server Deployment
4490
deploymentStrategy: {}
4491
# type: RollingUpdate
4492
# rollingUpdate:
4493
# maxSurge: 25%
4494
# maxUnavailable: 25%
4495
4496
# -- Priority class for the commit server pods
4497
# @default -- `""` (defaults to global.priorityClassName)
4498
priorityClassName: ""
4499
# Default commit server's network policy
4500
networkPolicy:
4501
# -- Default network policy rules used by commit server
4502
# @default -- `false` (defaults to global.networkPolicy.create)
4503
create: false
4504
## Commit server Vertical Pod Autoscaler
4505
## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/
4506
vpa:
4507
# -- Deploy a [VerticalPodAutoscaler](https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/) for the commit server
4508
enabled: false
4509
# -- Labels to be added to commit server vpa
4510
labels: {}
4511
# -- Annotations to be added to commit server vpa
4512
annotations: {}
4513
# -- One of the VPA operation modes
4514
## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically
4515
## Note: Recreate update mode requires more than one replica unless the min-replicas VPA controller flag is overridden
4516
updateMode: Initial
4517
# -- Controls how VPA computes the recommended resources for commit server container
4518
## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/examples/hamster.yaml
4519
containerPolicy: {}
4520
# controlledResources: ["cpu", "memory"]
4521
# minAllowed:
4522
# cpu: 250m
4523
# memory: 256Mi
4524
# maxAllowed:
4525
# cpu: 1
4526
# memory: 1Gi
4527
# -- The recommenders that will provide recommendations for vertical scaling. Only relevant if a named VPA recommender (e.g. one started with a custom recommender name) is in use; leave unset to use the cluster's default recommender
4528
## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/docs/api.md#verticalpodautoscalerspec
4529
## NOTE: specify only zero or one recommender as of VPA 1.7.1
4530
recommenders: []
4531
# -- Configures a startup resource boost for faster cold-start (application boot) resource allocation. NOTE: startupBoost is currently a GKE-specific extension to the VPA API and is only honored on GKE clusters; it is rendered only when set
4532
## Ref: https://cloud.google.com/kubernetes-engine/docs/how-to/boost-application-startup
4533
startupBoost: {}
4534
# cpu:
4535
# type: Factor
4536
# factor: 2
4537
# durationSeconds: 10
4538

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.