1## Argo CD configuration
2## Ref: https://github.com/argoproj/argo-cd
5# -- Provide a name in place of `argocd`
7# -- String to fully override `"argo-cd.fullname"`
9# -- Override the namespace
10# @default -- `.Release.Namespace`
12# -- Override the Kubernetes version, which is used to evaluate certain manifests
13kubeVersionOverride: ""
15# If you want to template helm charts but cannot access k8s API server
16# you can set api versions here
17apiVersionOverrides: {}
18# -- Create aggregated roles that extend existing cluster roles to interact with argo-cd resources
19## Ref: https://kubernetes.io/docs/reference/access-authn-authz/rbac/#aggregated-clusterroles
20createAggregateRoles: false
21# -- Create cluster roles for cluster-wide installation.
22## Used when you manage applications in the same cluster where Argo CD runs
23createClusterRoles: true
25 # -- enables using arbitrary uid for argo repo server
27## Custom resource configuration
29 # -- Install and upgrade CRDs
31 # -- Keep CRDs on chart uninstall
33 # -- Annotations to be added to all CRDs
35 argocd.argoproj.io/sync-options: ServerSideApply=true
36 # -- Additional labels to be added to all CRDs
38## Globally shared configuration
40 # -- Default domain used by all components
41 ## Used for ingresses, certificates, SSO, notifications, etc.
42 domain: argocd.example.com
43 # -- Runtime class name for all components
45 # -- Common labels for the all resources
49 # -- Number of old deployment ReplicaSets to retain. The rest will be garbage collected.
50 revisionHistoryLimit: 3
51 # Default image used by all components
53 # -- If defined, a repository applied to all Argo CD deployments
54 repository: chainreg.biz/chainguard-private/argocd
55 # -- Overrides the global Argo CD image tag whose default is the chart appVersion
56 tag: 3.5.3-r1@sha256:48bc1589241147b042a70a8b992dcc9b7bad3ec9b91271a88d9baef923ead1fb
57 # -- If defined, a imagePullPolicy applied to all Argo CD deployments
58 imagePullPolicy: IfNotPresent
59 # -- Secrets with credentials to pull images from a private registry
61 # Default logging options used by all components
63 # -- Set the global logging format. Either: `text` or `json`
65 # -- Set the global logging level. One of: `debug`, `info`, `warn` or `error`
67 # -- Annotations for the all deployed Statefulsets
68 statefulsetAnnotations: {}
69 # -- Labels for the all deployed Statefulsets
71 # -- Annotations for the all deployed Deployments
72 deploymentAnnotations: {}
73 # -- Labels for the all deployed Deployments
75 # -- Annotations for the all deployed pods
77 # -- Labels for the all deployed pods
79 # -- Add Prometheus scrape annotations to all metrics services. This can be used as an alternative to the ServiceMonitors.
80 addPrometheusAnnotations: false
81 # -- Toggle and define pod-level security context.
82 # @default -- `{}` (See [values.yaml])
88 # -- Mapping between IP and hostnames that will be injected as entries in the pod's hosts files
94 # Configure dual-stack used by all component services
96 # -- IP family policy to configure dual-stack see [Configure dual-stack](https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services)
98 # -- IP families that should be supported and the order in which they should be applied to ClusterIP as well. Can be IPv4 and/or IPv6.
100 # Default network policy rules used by all components
102 # -- Create NetworkPolicy objects for all components
104 # -- Default deny all ingress traffic
105 defaultDenyIngress: false
106 # -- Default priority class for all components
107 priorityClassName: ""
108 # -- Default node selector for all components
110 kubernetes.io/os: linux
111 # -- Default tolerations for all components
113 # Default affinity preset for all components
115 # -- Default pod anti-affinity rules. Either: `none`, `soft` or `hard`
116 podAntiAffinity: soft
117 # Node affinity rules
119 # -- Default node affinity rules. Either: `none`, `soft` or `hard`
121 # -- Default match expressions for node affinity
123 # - key: topology.kubernetes.io/zone
128 # -- Default [TopologySpreadConstraints] rules for all components
129 ## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
130 ## If labelSelector is left out, it will default to the labelSelector of the component
131 topologySpreadConstraints: []
133 # topologyKey: topology.kubernetes.io/zone
134 # whenUnsatisfiable: DoNotSchedule
136 # -- Deployment strategy for the all deployed Deployments
137 deploymentStrategy: {}
138 # type: RollingUpdate
141 # maxUnavailable: 25%
143 # -- Environment variables to pass to all deployed Deployments
145 # -- Extra volumes to add to all deployed Deployments and StatefulSets
147 # Example of adding a custom CA bundle from a ConfigMap:
150 # name: my-trustbundle
153 # path: ca-certificates.crt
155 # -- Extra volume mounts to add to all deployed Deployments and StatefulSets
156 extraVolumeMounts: []
157 # Example of adding a custom CA bundle mount:
159 # mountPath: /etc/ssl/certs
161 # -- Annotations for the all deployed Certificates
162 certificateAnnotations: {}
165 # General Argo CD configuration. Any values you put under `.configs.cm` are passed to argocd-cm ConfigMap.
166 ## Ref: https://github.com/argoproj/argo-cd/blob/master/docs/operator-manual/argocd-cm.yaml
168 # -- Create the argocd-cm configmap for [declarative setup]
170 # -- Annotations to be added to argocd-cm configmap
172 # -- The name of tracking label used by Argo CD for resource pruning
173 application.instanceLabelKey: argocd.argoproj.io/instance
174 # -- Enable control of the service account used for the sync operation (alpha)
175 ## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/app-sync-using-impersonation/
176 application.sync.impersonation.enabled: false
177 # -- Enable exec feature in Argo UI
178 ## Ref: https://argo-cd.readthedocs.io/en/latest/operator-manual/rbac/#exec-resource
180 # -- Enable local admin user
181 ## Ref: https://argo-cd.readthedocs.io/en/latest/faq/#how-to-disable-admin-user
183 # -- Timeout to discover if a new manifests version got published to the repository
184 timeout.reconciliation: 120s
185 # -- Maximum jitter added to the reconciliation timeout to spread out refreshes and reduce repo-server load
186 timeout.reconciliation.jitter: 60s
187 # -- Timeout to refresh application data as well as target manifests cache
188 timeout.hard.reconciliation: 0s
189 # -- Enable Status Badge
190 ## Ref: https://argo-cd.readthedocs.io/en/stable/user-guide/status-badge/
191 statusbadge.enabled: false
200 # clientID: aabbccddeeff00112233
201 # clientSecret: $dex.github.clientSecret # Alternatively $<some_K8S_secret>:dex.github.clientSecret
203 # - name: your-github-org
205 # OIDC configuration as an alternative to dex (optional).
208 # issuer: https://login.microsoftonline.com/TENANT_ID/v2.0
209 # clientID: aaaabbbbccccddddeee
210 # clientSecret: $oidc.azuread.clientSecret
211 # # Optional: set to true to use Azure Workload Identity instead of clientSecret
213 # useWorkloadIdentity: false
215 # Some OIDC providers require a separate clientID for different callback URLs.
216 # For example, if configuring Argo CD with self-hosted Dex, you will need a separate client ID
217 # for the 'localhost' (CLI) client to Dex. This field is optional. If omitted, the CLI will
218 # use the same clientID as the Argo CD server
219 # cliClientID: vvvvwwwwxxxxyyyyzzzz
222 # -----BEGIN CERTIFICATE-----
223 # ... encoded certificate data here ...
224 # -----END CERTIFICATE-----
226 # Optional list of allowed aud claims. If omitted or empty, defaults to the clientID value above (and the
227 # cliClientID, if that is also specified). If you specify a list and want the clientID to be allowed, you must
228 # explicitly include it in the list.
229 # Token verification will pass if any of the token's audiences matches any of the audiences in this list.
231 # - aaaabbbbccccddddeee
232 # - qqqqwwwweeeerrrrttt
234 # Optional set of OIDC claims to request on the ID token.
235 # requestedIDTokenClaims:
239 # Optional set of OIDC scopes to request. If omitted, defaults to: ["openid", "profile", "email", "groups"]
245 # PKCE authentication flow processes authorization flow from browser only - default false
247 # make sure the Identity Provider (IdP) is public and doesn't need clientSecret
248 # make sure the Identity Provider (IdP) has this redirect URI registered: https://argocd.example.com/pkce/verify
249 # enablePKCEAuthentication: true
251 # Extension Configuration
252 ## Ref: https://argo-cd.readthedocs.io/en/latest/developer-guide/extensions/proxy-extensions/
253 # extension.config: |
257 # connectionTimeout: 2s
259 # idleConnectionTimeout: 60s
260 # maxIdleConnections: 30
262 # - url: http://httpbin.org
264 # - name: some-header
265 # value: '$some.argocd.secret.key'
268 # server: https://some-cluster
270 ## Default configuration for ignoreResourceUpdates.
271 ## The ignoreResourceUpdates list contains K8s resource's properties that are known to be frequently updated
272 ## by controllers and operators. These resources, when watched by argo, will cause many unnecessary updates.
274 # -- Ignoring status for all resources. An update will still be sent if the status update causes the health to change.
275 # @default -- See [values.yaml]
276 resource.customizations.ignoreResourceUpdates.all: |
279 # -- Some Application fields are generated and not related to the application updates itself
280 ## The Application itself is already watched by the controller lister, but this configuration is applied for apps of apps
281 # @default -- See [values.yaml]
282 resource.customizations.ignoreResourceUpdates.argoproj.io_Application: |
284 - '.metadata.annotations."notified.notifications.argoproj.io"'
285 - '.metadata.annotations."argocd.argoproj.io/refresh"'
286 - '.metadata.annotations."argocd.argoproj.io/hydrate"'
288 # -- Ignore Argo Rollouts generated fields
289 # @default -- See [values.yaml]
290 resource.customizations.ignoreResourceUpdates.argoproj.io_Rollout: |
292 - '.metadata.annotations."notified.notifications.argoproj.io"'
293 # -- Legacy annotations used on HPA autoscaling/v1
294 # @default -- See [values.yaml]
295 resource.customizations.ignoreResourceUpdates.autoscaling_HorizontalPodAutoscaler: |
297 - '.metadata.annotations."autoscaling.alpha.kubernetes.io/behavior"'
298 - '.metadata.annotations."autoscaling.alpha.kubernetes.io/conditions"'
299 - '.metadata.annotations."autoscaling.alpha.kubernetes.io/metrics"'
300 - '.metadata.annotations."autoscaling.alpha.kubernetes.io/current-metrics"'
301 # -- Ignore the cluster-autoscaler status
302 # @default -- See [values.yaml]
303 resource.customizations.ignoreResourceUpdates.ConfigMap: |
305 # Ignore the cluster-autoscaler status
306 - '.metadata.annotations."cluster-autoscaler.kubernetes.io/last-updated"'
307 # Ignore the annotation of the legacy Leases election
308 - '.metadata.annotations."control-plane.alpha.kubernetes.io/leader"'
309 # -- Ignore the common scaling annotations
310 # @default -- See [values.yaml]
311 resource.customizations.ignoreResourceUpdates.apps_ReplicaSet: |
313 - '.metadata.annotations."deployment.kubernetes.io/desired-replicas"'
314 - '.metadata.annotations."deployment.kubernetes.io/max-replicas"'
315 - '.metadata.annotations."rollout.argoproj.io/desired-replicas"'
316 # -- Ignores update if EndpointSlice is not excluded globally
317 # @default -- See [values.yaml]
318 resource.customizations.ignoreResourceUpdates.discovery.k8s.io_EndpointSlice: |
323 # -- Ignores update if Endpoints is not excluded globally
324 # @default -- See [values.yaml]
325 resource.customizations.ignoreResourceUpdates.Endpoints: |
329 ## Default configuration for exclusions.
330 ## The exclusion list are K8s resources that we assume will never be declared in Git,
331 ## and are never child objects of managed resources that need to be presented in the resource tree.
332 ## This list contains high volume and high churn metadata objects which we exclude for performance
333 ## reasons, reducing connections and load to the K8s API servers of managed clusters.
335 # -- Resource Exclusion/Inclusion
336 # @default -- See [values.yaml]
337 resource.exclusions: |
338 ### Network resources created by the Kubernetes control plane and excluded to reduce the number of watched events and UI clutter
345 ### Internal Kubernetes resources excluded reduce the number of watched events
347 - coordination.k8s.io
350 ### Internal Kubernetes Authz/Authn resources excluded reduce the number of watched events
352 - authentication.k8s.io
353 - authorization.k8s.io
357 - LocalSubjectAccessReview
358 - SelfSubjectAccessReview
359 - SelfSubjectRulesReview
360 - SubjectAccessReview
361 ### Intermediate Certificate Request excluded reduce the number of watched events
363 - certificates.k8s.io
365 - CertificateSigningRequest
370 ### Cilium internal resources excluded reduce the number of watched events and UI Clutter
376 - CiliumEndpointSlice
377 ### Kyverno intermediate and reporting resources excluded reduce the number of watched events and improve performance
384 - ClusterPolicyReport
386 - ClusterEphemeralReport
388 - ClusterAdmissionReport
389 - BackgroundScanReport
390 - ClusterBackgroundScanReport
392 # -- Additional resource exclusions to append to the default `resource.exclusions` list above,
393 # so that the defaults can be kept up to date without needing to duplicate/override them.
394 # These entries are always appended, never substituted: if you also set `resource.exclusions`
395 # yourself, they are appended to your value rather than to the chart defaults.
397 resourceExclusionsAdditional: []
398 # Argo CD configuration parameters
399 ## Ref: https://github.com/argoproj/argo-cd/blob/master/docs/operator-manual/argocd-cmd-params-cm.yaml
401 # -- Create the argocd-cmd-params-cm configmap
402 # If false, it is expected the configmap will be created by something else.
404 # -- Annotations to be added to the argocd-cmd-params-cm ConfigMap
406 # You can customize parameters by adding parameters here.
409 # Argo CD RBAC policy configuration
410 ## Ref: https://github.com/argoproj/argo-cd/blob/master/docs/operator-manual/rbac.md
412 # -- Create the argocd-rbac-cm configmap with ([Argo CD RBAC policy]) definitions.
413 # If false, it is expected the configmap will be created by something else.
414 # Argo CD will not work if there is no configmap created with the name above.
416 # -- Annotations to be added to argocd-rbac-cm configmap
418 # -- The name of the default role which Argo CD will falls back to, when authorizing API requests (optional).
419 # If omitted or empty, users may be still be able to login, but will see no apps, projects, etc...
421 # -- File containing user-defined policies and role definitions.
422 # @default -- `''` (See [values.yaml])
424 # Policy rules are in the form:
425 # p, subject, resource, action, object, effect
426 # Role definitions and bindings are in the form:
427 # g, subject, inherited-subject
429 # p, role:org-admin, applications, *, */*, allow
430 # p, role:org-admin, clusters, get, *, allow
431 # p, role:org-admin, repositories, *, *, allow
432 # p, role:org-admin, logs, get, *, allow
433 # p, role:org-admin, exec, create, */*, allow
434 # g, your-github-org:your-team, role:org-admin
436 # -- OIDC scopes to examine during rbac enforcement (in addition to `sub` scope).
437 # The scope value can be a string, or a list of strings.
439 # -- Matcher function for Casbin, `glob` for glob matcher and `regex` for regex matcher.
440 policy.matchMode: "glob"
441 # GnuPG public keys for commit verification
442 ## Ref: https://argo-cd.readthedocs.io/en/stable/user-guide/gpg-verification/
444 # -- Annotations to be added to argocd-gpg-keys-cm configmap
446 # -- [GnuPG] public keys to add to the keyring
447 # @default -- `{}` (See [values.yaml])
448 ## Note: Public keys should be exported with `gpg --export --armor <KEY>`
450 # 4AEE18F83AFDEB23: |
451 # -----BEGIN PGP PUBLIC KEY BLOCK-----
453 # -----END PGP PUBLIC KEY BLOCK-----
454 # SSH known hosts for Git repositories
455 ## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/declarative-setup/#ssh-known-host-public-keys
457 # -- Specifies if the argocd-ssh-known-hosts-cm configmap should be created by Helm.
459 # -- Annotations to be added to argocd-ssh-known-hosts-cm configmap
461 # -- Known hosts to be added to the known host list by default.
462 # @default -- See [values.yaml]
464 [ssh.github.com]:443 ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBEmKSENjQEezOmxkZMy7opKgwFB9nkt5YRrYMjNuG5N87uRgg6CLrbo5wAdT/y6v0mKV0U2w0WZ2YB/++Tpockg=
465 [ssh.github.com]:443 ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOMqqnkVzrm0SdG6UOoqKLsabgH5C9okWi0dh2l9GKJl
466 [ssh.github.com]:443 ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCj7ndNxQowgcQnjshcLrqPEiiphnt+VTTvDP6mHBL9j1aNUkY4Ue1gvwnGLVlOhGeYrnZaMgRK6+PKCUXaDbC7qtbW8gIkhL7aGCsOr/C56SJMy/BCZfxd1nWzAOxSDPgVsmerOBYfNqltV9/hWCqBywINIR+5dIg6JTJ72pcEpEjcYgXkE2YEFXV1JHnsKgbLWNlhScqb2UmyRkQyytRLtL+38TGxkxCflmO+5Z8CSSNY7GidjMIZ7Q4zMjA2n1nGrlTDkzwDCsw+wqFPGQA179cnfGWOWRVruj16z6XyvxvjJwbz0wQZ75XK5tKSb7FNyeIEs4TT4jk+S4dhPeAUC5y+bDYirYgM4GC7uEnztnZyaVWQ7B381AK4Qdrwt51ZqExKbQpTUNn+EjqoTwvqNj4kqx5QUCI0ThS/YkOxJCXmPUWZbhjpCg56i+2aB6CmK2JGhn57K5mj0MNdBXA4/WnwH6XoPWJzK5Nyu2zB3nAZp+S5hpQs+p1vN1/wsjk=
467 bitbucket.org ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBPIQmuzMBuKdWeF4+a2sjSSpBK0iqitSQ+5BM9KhpexuGt20JpTVM7u5BDZngncgrqDMbWdxMWWOGtZ9UgbqgZE=
468 bitbucket.org ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIazEu89wgQZ4bqs3d63QSMzYVa0MuJ2e2gKTKqu+UUO
469 bitbucket.org ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDQeJzhupRu0u0cdegZIa8e86EG2qOCsIsD1Xw0xSeiPDlCr7kq97NLmMbpKTX6Esc30NuoqEEHCuc7yWtwp8dI76EEEB1VqY9QJq6vk+aySyboD5QF61I/1WeTwu+deCbgKMGbUijeXhtfbxSxm6JwGrXrhBdofTsbKRUsrN1WoNgUa8uqN1Vx6WAJw1JHPhglEGGHea6QICwJOAr/6mrui/oB7pkaWKHj3z7d1IC4KWLtY47elvjbaTlkN04Kc/5LFEirorGYVbt15kAUlqGM65pk6ZBxtaO3+30LVlORZkxOh+LKL/BvbZ/iRNhItLqNyieoQj/uh/7Iv4uyH/cV/0b4WDSd3DptigWq84lJubb9t/DnZlrJazxyDCulTmKdOR7vs9gMTo+uoIrPSb8ScTtvw65+odKAlBj59dhnVp9zd7QUojOpXlL62Aw56U4oO+FALuevvMjiWeavKhJqlR7i5n9srYcrNV7ttmDw7kf/97P5zauIhxcjX+xHv4M=
470 github.com ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBEmKSENjQEezOmxkZMy7opKgwFB9nkt5YRrYMjNuG5N87uRgg6CLrbo5wAdT/y6v0mKV0U2w0WZ2YB/++Tpockg=
471 github.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOMqqnkVzrm0SdG6UOoqKLsabgH5C9okWi0dh2l9GKJl
472 github.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCj7ndNxQowgcQnjshcLrqPEiiphnt+VTTvDP6mHBL9j1aNUkY4Ue1gvwnGLVlOhGeYrnZaMgRK6+PKCUXaDbC7qtbW8gIkhL7aGCsOr/C56SJMy/BCZfxd1nWzAOxSDPgVsmerOBYfNqltV9/hWCqBywINIR+5dIg6JTJ72pcEpEjcYgXkE2YEFXV1JHnsKgbLWNlhScqb2UmyRkQyytRLtL+38TGxkxCflmO+5Z8CSSNY7GidjMIZ7Q4zMjA2n1nGrlTDkzwDCsw+wqFPGQA179cnfGWOWRVruj16z6XyvxvjJwbz0wQZ75XK5tKSb7FNyeIEs4TT4jk+S4dhPeAUC5y+bDYirYgM4GC7uEnztnZyaVWQ7B381AK4Qdrwt51ZqExKbQpTUNn+EjqoTwvqNj4kqx5QUCI0ThS/YkOxJCXmPUWZbhjpCg56i+2aB6CmK2JGhn57K5mj0MNdBXA4/WnwH6XoPWJzK5Nyu2zB3nAZp+S5hpQs+p1vN1/wsjk=
473 gitlab.com ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBFSMqzJeV9rUzU4kWitGjeR4PWSa29SPqJ1fVkhtj3Hw9xjLVXVYrU9QlYWrOLXBpQ6KWjbjTDTdDkoohFzgbEY=
474 gitlab.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAfuCHKVTjquxvt6CM6tdG4SLp1Btn/nOeHHE5UOzRdf
475 gitlab.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCsj2bNKTBSpIYDEGk9KxsGh3mySTRgMtXL583qmBpzeQ+jqCMRgBqB98u3z++J1sKlXHWfM9dyhSevkMwSbhoR8XIq/U0tCNyokEi/ueaBMCvbcTHhO7FcwzY92WK4Yt0aGROY5qX2UKSeOvuP4D6TPqKF1onrSzH9bx9XUf2lEdWT/ia1NEKjunUqu1xOB/StKDHMoX4/OKyIzuS0q/T1zOATthvasJFoPrAjkohTyaDUz2LN5JoH839hViyEG82yB+MjcFV5MU3N1l1QL3cVUCh93xSaua1N85qivl+siMkPGbO5xR/En4iEY6K2XPASUEMaieWVNTRCtJ4S8H+9
476 ssh.dev.azure.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC7Hr1oTWqNqOlzGJOfGJ4NakVyIzf1rXYd4d7wo6jBlkLvCA4odBlL0mDUyZ0/QUfTTqeu+tm22gOsv+VrVTMk6vwRU75gY/y9ut5Mb3bR5BV58dKXyq9A9UeB5Cakehn5Zgm6x1mKoVyf+FFn26iYqXJRgzIZZcZ5V6hrE0Qg39kZm4az48o0AUbf6Sp4SLdvnuMa2sVNwHBboS7EJkm57XQPVU3/QpyNLHbWDdzwtrlS+ez30S3AdYhLKEOxAG8weOnyrtLJAUen9mTkol8oII1edf7mWWbWVf0nBmly21+nZcmCTISQBtdcyPaEno7fFQMDD26/s0lfKob4Kw8H
477 vs-ssh.visualstudio.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC7Hr1oTWqNqOlzGJOfGJ4NakVyIzf1rXYd4d7wo6jBlkLvCA4odBlL0mDUyZ0/QUfTTqeu+tm22gOsv+VrVTMk6vwRU75gY/y9ut5Mb3bR5BV58dKXyq9A9UeB5Cakehn5Zgm6x1mKoVyf+FFn26iYqXJRgzIZZcZ5V6hrE0Qg39kZm4az48o0AUbf6Sp4SLdvnuMa2sVNwHBboS7EJkm57XQPVU3/QpyNLHbWDdzwtrlS+ez30S3AdYhLKEOxAG8weOnyrtLJAUen9mTkol8oII1edf7mWWbWVf0nBmly21+nZcmCTISQBtdcyPaEno7fFQMDD26/s0lfKob4Kw8H
478 # -- Additional known hosts for private repositories
480 # Repository TLS certificates
481 # Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/declarative-setup/#repositories-using-self-signed-tls-certificates-or-are-signed-by-custom-ca
483 # -- Annotations to be added to argocd-tls-certs-cm configmap
485 # -- TLS certificates for Git repositories
486 # @default -- `{}` (See [values.yaml])
488 # server.example.com: |
489 # -----BEGIN CERTIFICATE-----
491 # -----END CERTIFICATE-----
493 # -- Specifies if the argocd-tls-certs-cm configmap should be created by Helm.
495 # ConfigMap for Config Management Plugins
496 # Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/config-management-plugins/
498 # -- Create the argocd-cmp-cm configmap
500 # -- Annotations to be added to argocd-cmp-cm configmap
502 # -- Plugin yaml files to be added to argocd-cmp-cm
508 # args: [-c, 'echo "Initializing..."']
513 # echo "{\"kind\": \"ConfigMap\", \"apiVersion\": \"v1\", \"metadata\": { \"name\": \"$ARGOCD_APP_NAME\", \"namespace\": \"$ARGOCD_APP_NAMESPACE\", \"annotations\": {\"Foo\": \"$ARGOCD_ENV_FOO\", \"KubeVersion\": \"$KUBE_VERSION\", \"KubeApiVersion\": \"$KUBE_API_VERSIONS\",\"Bar\": \"baz\"}}}"
515 # fileName: "./subdir/s*.yaml"
517 # glob: "**/Chart.yaml"
518 # command: [sh, -c, find . -name env.yaml]
523 # args: [-c, 'echo "Initializing..."']
528 # echo "{\"kind\": \"ConfigMap\", \"apiVersion\": \"v1\", \"metadata\": { \"name\": \"$ARGOCD_APP_NAME\", \"namespace\": \"$ARGOCD_APP_NAMESPACE\", \"annotations\": {\"Foo\": \"$ARGOCD_ENV_FOO\", \"KubeVersion\": \"$KUBE_VERSION\", \"KubeApiVersion\": \"$KUBE_API_VERSIONS\",\"Bar\": \"baz\"}}}"
530 # fileName: "./subdir/s*.yaml"
532 # glob: "**/Chart.yaml"
533 # command: [sh, -c, find . -name env.yaml]
535 # -- Provide one or multiple [external cluster credentials]
536 # @default -- `{}` (See [values.yaml])
538 ## - https://argo-cd.readthedocs.io/en/stable/operator-manual/declarative-setup/#clusters
539 ## - https://argo-cd.readthedocs.io/en/stable/operator-manual/security/#external-cluster-credentials
540 ## - https://argo-cd.readthedocs.io/en/stable/user-guide/projects/#project-scoped-repositories-and-clusters
541 clusterCredentials: {}
543 # server: https://mycluster.example.com
547 # bearerToken: "<authentication token>"
550 # caData: "<base64 encoded certificate>"
552 # server: https://mycluster2.example.com
555 # namespaces: namespace1,namespace2
556 # clusterResources: true
558 # bearerToken: "<authentication token>"
561 # caData: "<base64 encoded certificate>"
562 # mycluster3-project-scoped:
563 # server: https://mycluster3.example.com
566 # project: my-project1
568 # bearerToken: "<authentication token>"
571 # caData: "<base64 encoded certificate>"
572 # mycluster4-sharded:
574 # server: https://mycluster4.example.com
578 # bearerToken: "<authentication token>"
581 # caData: "<base64 encoded certificate>"
583 # -- Repository credentials to be used as Templates for other repos
584 ## Creates a secret for each key/value specified below to create repository credentials
585 credentialTemplates: {}
586 # github-enterprise-creds-1:
587 # url: https://github.com/argoproj
589 # githubAppInstallationID: 2
590 # githubAppEnterpriseBaseUrl: https://ghe.example.com/api/v3
591 # githubAppPrivateKey: |
592 # -----BEGIN OPENSSH PRIVATE KEY-----
594 # -----END OPENSSH PRIVATE KEY-----
596 # url: https://github.com/argoproj
597 # password: my-password
598 # username: my-username
600 # url: git@github.com:argoproj-labs
602 # -----BEGIN OPENSSH PRIVATE KEY-----
604 # -----END OPENSSH PRIVATE KEY-----
606 # -- Annotations to be added to `configs.credentialTemplates` Secret
607 credentialTemplatesAnnotations: {}
608 # -- Repositories list to be used by applications
609 ## Creates a secret for each key/value specified below to create repositories
610 ## Note: the last example in the list would use a repository credential template, configured under "configs.credentialTemplates".
613 # url: https://storage.googleapis.com/istio-prerelease/daily-build/master-latest-daily/charts
617 # url: https://my-private-chart-repo.internal
620 # password: my-password
621 # username: my-username
623 # url: https://github.com/argoproj/private-repo
625 # -- Annotations to be added to `configs.repositories` Secret
626 repositoriesAnnotations: {}
627 # Argo CD sensitive data
628 # Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/user-management/#sensitive-data-and-sso-client-secrets
630 # -- Create the argocd-secret
632 # -- Labels to be added to argocd-secret
634 # -- Annotations to be added to argocd-secret
636 # -- Shared secret for authenticating GitHub webhook events
638 # -- Shared secret for authenticating GitLab webhook events
640 # -- Shared secret for authenticating BitbucketServer webhook events
641 bitbucketServerSecret: ""
642 # -- UUID for authenticating Bitbucket webhook events
644 # -- Shared secret for authenticating Gogs webhook events
648 # -- Shared secret username for authenticating Azure DevOps webhook events
650 # -- Shared secret password for authenticating Azure DevOps webhook events
652 # -- add additional secrets to be added to argocd-secret
653 ## Custom secrets. Useful for injecting SSO secrets into environment variables.
654 ## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/user-management/#sensitive-data-and-sso-client-secrets
655 ## Note that all values must be non-empty.
657 # LDAP_PASSWORD: "mypassword"
659 # -- Bcrypt hashed admin password
660 ## Argo expects the password in the secret to be bcrypt hashed. You can create this hash with
661 ## `htpasswd -nbBC 10 "" $ARGO_PWD | tr -d ':\n' | sed 's/$2y/$2a/'`
662 argocdServerAdminPassword: ""
663 # -- Admin password modification time. Eg. `"2006-01-02T15:04:05Z"`
664 # @default -- `""` (defaults to current time)
665 argocdServerAdminPasswordMtime: ""
666 # -- Define custom [CSS styles] for your argo instance.
667 # This setting will automatically mount the provided CSS and reference it in the argo configuration.
668 # @default -- `""` (See [values.yaml])
669 ## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/custom-styles/
673 # background: linear-gradient(to bottom, #999, #777, #333, #222, #111);
675# -- Array of extra K8s manifests to deploy
676## Note: Supports use of custom Helm templates
678# - apiVersion: secrets-store.csi.x-k8s.io/v1
679# kind: SecretProviderClass
681# name: argocd-secrets-store
686# - objectName: "argocd"
687# objectType: "secretsmanager"
690# objectAlias: "client_id"
691# - path: "client_secret"
692# objectAlias: "client_secret"
696# objectName: client_id
697# - key: client_secret
698# objectName: client_secret
699# secretName: argocd-secrets-store
702# app.kubernetes.io/part-of: argocd
704## Application controller
706 # -- Application controller name string
707 name: application-controller
708 # -- The number of application controller pods to run.
709 # Additional replicas will cause sharding of managed clusters across number of replicas.
710 ## With dynamic cluster distribution turned on, sharding of the clusters will gracefully
711 ## rebalance if the number of replica's changes or one becomes unhealthy. (alpha)
713 # -- Enable dynamic cluster distribution (alpha)
714 # Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/dynamic-cluster-distribution
715 ## This is done using a deployment instead of a statefulSet
716 ## When replicas are added or removed, the sharding algorithm is re-run to ensure that the
717 ## clusters are distributed according to the algorithm. If the algorithm is well-balanced,
718 ## like round-robin, then the shards will be well-balanced.
719 dynamicClusterDistribution: false
720 # -- Runtime class name for the application controller
721 # @default -- `""` (defaults to global.runtimeClassName)
723 # -- Application controller heartbeat time
724 # Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/dynamic-cluster-distribution/#working-of-dynamic-distribution
726 # -- Maximum number of controller revisions that will be maintained in StatefulSet history
727 revisionHistoryLimit: 5
728 ## Application controller Pod Disruption Budget
729 ## Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
731 # -- Deploy a [PodDisruptionBudget] for the application controller
733 # -- Labels to be added to application controller pdb
735 # -- Annotations to be added to application controller pdb
737 # -- Number of pods that are available after eviction as number or percentage (eg.: 50%)
738 # @default -- `""` (defaults to 0 if not specified)
740 # -- Number of pods that are unavailable after eviction as number or percentage (eg.: 50%).
741 ## Has higher precedence over `controller.pdb.minAvailable`
743 # -- Policy for evicting unhealthy (not ready) pods, either `IfHealthyBudget` or `AlwaysAllow`
744 ## Defaults to `IfHealthyBudget` if not set
745 unhealthyPodEvictionPolicy: ""
746 ## Application controller Vertical Pod Autoscaler
747 ## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/
749 # -- Deploy a [VerticalPodAutoscaler](https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/) for the application controller
751 # -- Labels to be added to application controller vpa
753 # -- Annotations to be added to application controller vpa
755 # -- One of the VPA operation modes
756 ## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically
757 ## Note: Recreate update mode requires more than one replica unless the min-replicas VPA controller flag is overridden
759 # -- Controls how VPA computes the recommended resources for application controller container
760 ## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/examples/hamster.yaml
762 # controlledResources: ["cpu", "memory"]
769 # -- The recommenders that will provide recommendations for vertical scaling. Only relevant if a named VPA recommender (e.g. one started with a custom recommender name) is in use; leave unset to use the cluster's default recommender
770 ## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/docs/api.md#verticalpodautoscalerspec
771 ## NOTE: specify only zero or one recommender as of VPA 1.7.1
773 # -- Configures a startup resource boost for faster cold-start (application boot) resource allocation. NOTE: startupBoost is currently a GKE-specific extension to the VPA API and is only honored on GKE clusters; it is rendered only when set
774 ## Ref: https://cloud.google.com/kubernetes-engine/docs/how-to/boost-application-startup
779 # durationSeconds: 10
780 ## Application controller image
782 # -- Repository to use for the application controller
783 # @default -- `""` (defaults to global.image.repository)
785 # -- Tag to use for the application controller
786 # @default -- `""` (defaults to global.image.tag)
788 # -- Image pull policy for the application controller
789 # @default -- `""` (defaults to global.image.imagePullPolicy)
791 # -- Secrets with credentials to pull images from a private registry
792 # @default -- `[]` (defaults to global.imagePullSecrets)
794 # -- Additional command line arguments to pass to application controller
796 # -- Environment variables to pass to application controller
798 # -- envFrom to pass to application controller
799 # @default -- `[]` (See [values.yaml])
802 # name: config-map-name
806 # -- Additional containers to be added to the application controller pod
807 ## Note: Supports use of custom Helm templates
809 # -- Init containers to add to the application controller pod
810 ## If your target Kubernetes cluster(s) require a custom credential (exec) plugin
811 ## you could use this (and the same in the server pod) to provide such executable
812 ## Ref: https://kubernetes.io/docs/reference/access-authn-authz/authentication/#client-go-credential-plugins
813 ## Note: Supports use of custom Helm templates
815 # - name: download-tools
819 # - wget -qO /custom-tools/kubelogin.zip https://github.com/Azure/kubelogin/releases/download/v0.2.7/kubelogin-linux-amd64.zip &&
820 # mkdir /custom-tools/tmp && unzip -d /custom-tools/tmp /custom-tools/kubelogin.zip &&
821 # mv /custom-tools/tmp/bin/linux_amd64/kubelogin /custom-tools/ && rm -rf custom-tools/tmp && rm /custom-tools/kubelogin.zip
823 # - mountPath: /custom-tools
826 # -- Additional volumeMounts to the application controller main container
828 # - mountPath: /usr/local/bin/kubelogin
832 # -- Additional volumes to the application controller pod
834 # - name: custom-tools
837 ## Application controller emptyDir volumes
839 # -- EmptyDir size limit for application controller
840 # @default -- `""` (defaults not set if not specified i.e. no size limit)
843 # -- Annotations for the application controller StatefulSet
844 statefulsetAnnotations: {}
845 # -- Labels for the application controller StatefulSet
846 statefulsetLabels: {}
847 # -- Annotations for the application controller Deployment
848 deploymentAnnotations: {}
849 # -- Labels for the application controller Deployment
851 # -- Annotations to be added to application controller pods
853 # -- Labels to be added to application controller pods
855 # -- Resource limits and requests for the application controller pods
864 # Application controller container ports
866 # -- Metrics container port
868 # -- Host Network for application controller pods
870 # -- [DNS configuration]
872 # -- Alternative DNS policy for application controller pods
873 dnsPolicy: "ClusterFirst"
874 # -- Application controller container-level security context
875 # @default -- See [values.yaml]
876 containerSecurityContext:
878 readOnlyRootFilesystem: true
879 allowPrivilegeEscalation: false
885 # Readiness probe for application controller
886 ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
888 # -- Http path to use for the readiness probe
890 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
892 # -- Number of seconds after the container has started before [probe] is initiated
893 initialDelaySeconds: 10
894 # -- How often (in seconds) to perform the [probe]
896 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
898 # -- Number of seconds after which the [probe] times out
900 ## Liveness probe for the application controller.
901 ## Disabled by default, matching upstream: Argo CD removed this probe deliberately
902 ## (argoproj/argo-cd#9557) because restarting an overloaded controller usually makes
903 ## things worse. Enable only if you have a known failure mode (e.g. deadlock) where
904 ## a restart is the correct remediation, and size the thresholds generously.
905 ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
907 # -- Enable Kubernetes liveness probe for Application controller
909 # -- Http path to use for the liveness probe
911 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
913 # -- Number of seconds after the container has started before [probe] is initiated
914 initialDelaySeconds: 10
915 # -- How often (in seconds) to perform the [probe]
917 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
919 # -- Number of seconds after which the [probe] times out
921 ## Startup probe for application controller (optional)
922 ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
924 # -- Enable Kubernetes startup probe for application controller
926 # -- Http path to use for the startup probe
928 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
930 # -- Number of seconds after the container has started before [probe] is initiated
931 initialDelaySeconds: 10
932 # -- How often (in seconds) to perform the [probe]
934 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
936 # -- Number of seconds after which the [probe] times out
938 # -- terminationGracePeriodSeconds for container lifecycle hook
939 terminationGracePeriodSeconds: 30
940 # -- Priority class for the application controller pods
941 # @default -- `""` (defaults to global.priorityClassName)
942 priorityClassName: ""
944 # @default -- `{}` (defaults to global.nodeSelector)
946 # -- [Tolerations] for use with node taints
947 # @default -- `[]` (defaults to global.tolerations)
949 # -- Assign custom [affinity] rules to the deployment
950 # @default -- `{}` (defaults to global.affinity preset)
952 # -- Assign custom [TopologySpreadConstraints] rules to the application controller
953 # @default -- `[]` (defaults to global.topologySpreadConstraints)
954 ## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
955 ## If labelSelector is left out, it will default to the labelSelector configuration of the deployment
956 topologySpreadConstraints: []
958 # topologyKey: topology.kubernetes.io/zone
959 # whenUnsatisfiable: DoNotSchedule
961 # -- Automount API credentials for the Service Account into the pod.
962 automountServiceAccountToken: true
964 # -- Create a service account for the application controller
966 # -- Service account name
967 name: argocd-application-controller
968 # -- Annotations applied to created service account
970 # -- Labels applied to created service account
972 # -- Automount API credentials for the Service Account
973 automountServiceAccountToken: true
974 ## Application controller metrics configuration
976 # -- Deploy metrics service
979 # -- Enables additional labels in argocd_app_labels metric
981 # -- Additional labels
984 # -- Metrics service type
986 # -- Metrics service clusterIP. `None` makes a "headless service" (no virtual IP)
988 # -- Metrics service annotations
990 # -- Metrics service labels
992 # -- Metrics service port
994 # -- Metrics service port name
995 portName: http-metrics
997 # -- Enable a prometheus ServiceMonitor
999 # -- Prometheus ServiceMonitor interval
1001 # -- Prometheus ServiceMonitor scrapeTimeout. If empty, Prometheus uses the global scrape timeout unless it is less than the target's scrape interval value in which the latter is used.
1003 # -- When true, honorLabels preserves the metric’s labels when they collide with the target’s labels.
1005 # -- Prometheus [RelabelConfigs] to apply to samples before scraping
1007 # -- Prometheus [MetricRelabelConfigs] to apply to samples before ingestion
1008 metricRelabelings: []
1009 # -- Prometheus ServiceMonitor selector
1011 # prometheus: kube-prometheus
1013 # -- Prometheus ServiceMonitor scheme
1015 # -- Prometheus ServiceMonitor tlsConfig
1017 # -- Prometheus ServiceMonitor namespace
1018 namespace: "" # "monitoring"
1019 # -- Prometheus ServiceMonitor labels
1020 additionalLabels: {}
1021 # -- Prometheus ServiceMonitor annotations
1024 # -- Deploy a PrometheusRule for the application controller
1026 # -- PrometheusRule namespace
1027 namespace: "" # "monitoring"
1028 # -- PrometheusRule selector
1030 # prometheus: kube-prometheus
1032 # -- PrometheusRule labels
1033 additionalLabels: {}
1034 # -- PrometheusRule annotations
1036 # -- PrometheusRule.Spec for the application controller
1038 # - alert: ArgoAppMissing
1040 # absent(argocd_app_info) == 1
1043 # severity: critical
1045 # summary: "[Argo CD] No reported applications"
1047 # Argo CD has not reported any applications data for the past 15 minutes which
1048 # means that it must be down or not functioning properly. This needs to be
1049 # resolved for this cloud to continue to maintain state.
1050 # - alert: ArgoAppNotSynced
1052 # argocd_app_info{sync_status!="Synced"} == 1
1057 # summary: "[{{ $labels.name }}] Application not synchronized"
1059 # The application {{ $labels.name }} has not been synchronized for over
1060 # 12 hours which means that the state of this cloud has drifted away from the
1062 ## Enable this and set the rules: to whatever custom rules you want for the Cluster Role resource.
1065 # -- Enable custom rules for the application controller's ClusterRole resource
1067 # -- List of custom rules for the application controller's ClusterRole resource
1069 ## Enable this and set the rules: to whatever custom rules you want for the Role resource.
1071 # -- List of custom rules for the application controller's Role resource
1073 # Default application controller's network policy
1075 # -- Default network policy rules used by application controller
1076 # @default -- `false` (defaults to global.networkPolicy.create)
1084 # -- Additional command line arguments to pass to the Dex server
1086 # -- Runtime class name for Dex
1087 # @default -- `""` (defaults to global.runtimeClassName)
1088 runtimeClassName: ""
1090 # -- Deploy metrics service
1093 # -- Metrics service annotations
1095 # -- Metrics service labels
1097 # -- Metrics service port name
1098 portName: http-metrics
1100 # -- Enable a prometheus ServiceMonitor
1102 # -- Prometheus ServiceMonitor interval
1104 # -- When true, honorLabels preserves the metric’s labels when they collide with the target’s labels.
1106 # -- Prometheus [RelabelConfigs] to apply to samples before scraping
1108 # -- Prometheus [MetricRelabelConfigs] to apply to samples before ingestion
1109 metricRelabelings: []
1110 # -- Prometheus ServiceMonitor selector
1112 # prometheus: kube-prometheus
1114 # -- Prometheus ServiceMonitor scheme
1116 # -- Prometheus ServiceMonitor tlsConfig
1118 # -- Prometheus ServiceMonitor namespace
1119 namespace: "" # "monitoring"
1120 # -- Prometheus ServiceMonitor labels
1121 additionalLabels: {}
1122 # -- Prometheus ServiceMonitor annotations
1124 ## Dex Pod Disruption Budget
1125 ## Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
1127 # -- Deploy a [PodDisruptionBudget] for the Dex server
1129 # -- Labels to be added to Dex server pdb
1131 # -- Annotations to be added to Dex server pdb
1133 # -- Number of pods that are available after eviction as number or percentage (eg.: 50%)
1134 # @default -- `""` (defaults to 0 if not specified)
1136 # -- Number of pods that are unavailble after eviction as number or percentage (eg.: 50%).
1137 ## Has higher precedence over `dex.pdb.minAvailable`
1139 # -- Policy for evicting unhealthy (not ready) pods, either `IfHealthyBudget` or `AlwaysAllow`
1140 ## Defaults to `IfHealthyBudget` if not set
1141 unhealthyPodEvictionPolicy: ""
1142 ## Dex Vertical Pod Autoscaler
1143 ## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/
1145 # -- Deploy a [VerticalPodAutoscaler](https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/) for the Dex server
1147 # -- Labels to be added to Dex server vpa
1149 # -- Annotations to be added to Dex server vpa
1151 # -- One of the VPA operation modes
1152 ## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically
1153 ## Note: Recreate update mode requires more than one replica unless the min-replicas VPA controller flag is overridden
1155 # -- Controls how VPA computes the recommended resources for Dex server container
1156 ## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/examples/hamster.yaml
1158 # controlledResources: ["cpu", "memory"]
1165 # -- The recommenders that will provide recommendations for vertical scaling. Only relevant if a named VPA recommender (e.g. one started with a custom recommender name) is in use; leave unset to use the cluster's default recommender
1166 ## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/docs/api.md#verticalpodautoscalerspec
1167 ## NOTE: specify only zero or one recommender as of VPA 1.7.1
1169 # -- Configures a startup resource boost for faster cold-start (application boot) resource allocation. NOTE: startupBoost is currently a GKE-specific extension to the VPA API and is only honored on GKE clusters; it is rendered only when set
1170 ## Ref: https://cloud.google.com/kubernetes-engine/docs/how-to/boost-application-startup
1175 # durationSeconds: 10
1178 # -- Dex image repository
1179 repository: chainreg.biz/chainguard-private/dex
1181 tag: 2.45.1-r27@sha256:61e8175f9645dd939109102c8e3fe5dd128208896d78d1c08cac67f452eda414
1182 # -- Dex imagePullPolicy
1183 # @default -- `""` (defaults to global.image.imagePullPolicy)
1185 # -- Secrets with credentials to pull images from a private registry
1186 # @default -- `[]` (defaults to global.imagePullSecrets)
1187 imagePullSecrets: []
1188 # Argo CD init image that creates Dex config
1190 # -- Argo CD init image repository
1191 # @default -- `""` (defaults to global.image.repository)
1193 # -- Argo CD init image tag
1194 # @default -- `""` (defaults to global.image.tag)
1196 # -- Argo CD init image imagePullPolicy
1197 # @default -- `""` (defaults to global.image.imagePullPolicy)
1199 # -- Argo CD init image resources
1200 # @default -- `{}` (defaults to dex.resources)
1208 # -- Environment variables to pass to the Dex server
1210 # -- envFrom to pass to the Dex server
1211 # @default -- `[]` (See [values.yaml])
1214 # name: config-map-name
1218 # -- Additional containers to be added to the dex pod
1219 ## Note: Supports use of custom Helm templates
1221 # -- Init containers to add to the dex pod
1222 ## Note: Supports use of custom Helm templates
1224 # -- Additional volumeMounts to the dex main container
1226 # -- Additional volumes to the dex pod
1228 ## Dex server emptyDir volumes
1230 # -- EmptyDir size limit for Dex server
1231 # @default -- `""` (defaults not set if not specified i.e. no size limit)
1234 # TLS certificate configuration via Secret
1235 ## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/tls/#configuring-tls-to-argocd-dex-server
1236 ## Note: Issuing certificates via cert-manager in not supported right now because it's not possible to restart Dex automatically without extra controllers.
1238 # -- Create argocd-dex-server-tls secret
1240 # -- Labels to be added to argocd-dex-server-tls secret
1242 # -- Annotations to be added to argocd-dex-server-tls secret
1244 # -- Certificate authority. Required for self-signed certificates.
1246 # -- Certificate private key
1248 # -- Certificate data. Must contain SANs of Dex service (ie: argocd-dex-server, argocd-dex-server.argo-cd.svc)
1250 # -- Annotations to be added to the Dex server Deployment
1251 deploymentAnnotations: {}
1252 # -- Labels for the Dex server Deployment
1253 deploymentLabels: {}
1254 # -- Annotations to be added to the Dex server pods
1256 # -- Labels to be added to the Dex server pods
1258 # -- Resource limits and requests for dex
1267 # Dex container ports
1268 # NOTE: These ports are currently hardcoded and cannot be changed
1270 # -- HTTP container port
1272 # -- gRPC container port
1274 # -- Metrics container port
1276 # -- [DNS configuration]
1278 # -- Alternative DNS policy for Dex server pods
1279 dnsPolicy: "ClusterFirst"
1280 # -- Dex container-level security context
1281 # @default -- See [values.yaml]
1282 containerSecurityContext:
1285 readOnlyRootFilesystem: true
1286 allowPrivilegeEscalation: false
1288 type: RuntimeDefault
1292 ## Probes for Dex server
1293 ## Supported from Dex >= 2.28.0
1295 # -- Enable Kubernetes liveness probe for Dex >= 2.28.0
1297 # -- Http path to use for the liveness probe
1298 httpPath: /healthz/live
1299 # -- Http port to use for the liveness probe
1301 # -- Scheme to use for for the liveness probe (can be HTTP or HTTPS)
1303 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
1305 # -- Number of seconds after the container has started before [probe] is initiated
1306 initialDelaySeconds: 10
1307 # -- How often (in seconds) to perform the [probe]
1309 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
1311 # -- Number of seconds after which the [probe] times out
1314 # -- Enable Kubernetes readiness probe for Dex >= 2.28.0
1316 # -- Http path to use for the readiness probe
1317 httpPath: /healthz/ready
1318 # -- Http port to use for the readiness probe
1320 # -- Scheme to use for for the liveness probe (can be HTTP or HTTPS)
1322 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
1324 # -- Number of seconds after the container has started before [probe] is initiated
1325 initialDelaySeconds: 10
1326 # -- How often (in seconds) to perform the [probe]
1328 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
1330 # -- Number of seconds after which the [probe] times out
1332 ## Startup probe for Dex server (optional)
1333 ## Supported from Dex >= 2.28.0
1335 # -- Enable Kubernetes startup probe for Dex >= 2.28.0
1337 # -- Http path to use for the startup probe
1338 httpPath: /healthz/ready
1339 # -- Http port to use for the startup probe
1341 # -- Scheme to use for the startup probe (can be HTTP or HTTPS)
1343 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
1344 failureThreshold: 20
1345 # -- Number of seconds after the container has started before [probe] is initiated
1346 initialDelaySeconds: 10
1347 # -- How often (in seconds) to perform the [probe]
1349 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
1351 # -- Number of seconds after which the [probe] times out
1353 # -- terminationGracePeriodSeconds for container lifecycle hook
1354 terminationGracePeriodSeconds: 30
1355 # -- Automount API credentials for the Service Account into the pod.
1356 automountServiceAccountToken: true
1358 # -- Create dex service account
1360 # -- Dex service account name
1361 name: argocd-dex-server
1362 # -- Annotations applied to created service account
1364 # -- Automount API credentials for the Service Account
1365 automountServiceAccountToken: true
1366 # -- Service port for HTTP access
1367 servicePortHttp: 5556
1368 # -- Service port name for HTTP access
1369 servicePortHttpName: http
1370 # -- Service port for gRPC access
1371 servicePortGrpc: 5557
1372 # -- Service port name for gRPC access
1373 servicePortGrpcName: grpc
1374 # -- Service port for metrics access
1375 servicePortMetrics: 5558
1376 # -- Priority class for the dex pods
1377 # @default -- `""` (defaults to global.priorityClassName)
1378 priorityClassName: ""
1379 # -- [Node selector]
1380 # @default -- `{}` (defaults to global.nodeSelector)
1382 # -- [Tolerations] for use with node taints
1383 # @default -- `[]` (defaults to global.tolerations)
1385 # -- Assign custom [affinity] rules to the deployment
1386 # @default -- `{}` (defaults to global.affinity preset)
1388 # -- Assign custom [TopologySpreadConstraints] rules to dex
1389 # @default -- `[]` (defaults to global.topologySpreadConstraints)
1390 ## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
1391 ## If labelSelector is left out, it will default to the labelSelector configuration of the deployment
1392 topologySpreadConstraints: []
1394 # topologyKey: topology.kubernetes.io/zone
1395 # whenUnsatisfiable: DoNotSchedule
1397 # -- Deployment strategy to be added to the Dex server Deployment
1398 deploymentStrategy: {}
1399 # type: RollingUpdate
1402 # maxUnavailable: 25%
1404 # Default Dex server's network policy
1406 # -- Default network policy rules used by Dex server
1407 # @default -- `false` (defaults to global.networkPolicy.create)
1409 # DEPRECATED - Use configs.params to override
1410 # -- Dex log format. Either `text` or `json`
1411 # @default -- `""` (defaults to global.logging.format)
1413 # -- Dex log level. One of: `debug`, `info`, `warn`, `error`
1414 # @default -- `""` (defaults to global.logging.level)
1422 # -- Runtime class name for redis
1423 # @default -- `""` (defaults to global.runtimeClassName)
1424 runtimeClassName: ""
1425 # -- Existing Secret name for the embedded Redis password. The Secret must contain the key `auth`.
1426 # Only used when `redisSecretInit.enabled` is `false`, otherwise the secret name is `argocd-redis`.
1427 # Only applies to the single node Redis deployment. With `redis-ha.enabled` use `redis-ha.existingSecret` instead,
1428 # and for external Redis use `externalRedis.existingSecret`.
1430 ## Redis Pod Disruption Budget
1431 ## Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
1433 # -- Deploy a [PodDisruptionBudget] for the Redis
1435 # -- Labels to be added to Redis pdb
1437 # -- Annotations to be added to Redis pdb
1439 # -- Number of pods that are available after eviction as number or percentage (eg.: 50%)
1440 # @default -- `""` (defaults to 0 if not specified)
1442 # -- Number of pods that are unavailble after eviction as number or percentage (eg.: 50%).
1443 ## Has higher precedence over `redis.pdb.minAvailable`
1445 # -- Policy for evicting unhealthy (not ready) pods, either `IfHealthyBudget` or `AlwaysAllow`
1446 ## Defaults to `IfHealthyBudget` if not set
1447 unhealthyPodEvictionPolicy: ""
1448 ## Redis Vertical Pod Autoscaler
1449 ## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/
1451 # -- Deploy a [VerticalPodAutoscaler](https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/) for the Redis
1453 # -- Labels to be added to Redis vpa
1455 # -- Annotations to be added to Redis vpa
1457 # -- One of the VPA operation modes
1458 ## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically
1459 ## Note: Recreate update mode requires more than one replica unless the min-replicas VPA controller flag is overridden
1461 # -- Controls how VPA computes the recommended resources for Redis container
1462 ## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/examples/hamster.yaml
1464 # controlledResources: ["cpu", "memory"]
1471 # -- The recommenders that will provide recommendations for vertical scaling. Only relevant if a named VPA recommender (e.g. one started with a custom recommender name) is in use; leave unset to use the cluster's default recommender
1472 ## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/docs/api.md#verticalpodautoscalerspec
1473 ## NOTE: specify only zero or one recommender as of VPA 1.7.1
1475 # -- Configures a startup resource boost for faster cold-start (application boot) resource allocation. NOTE: startupBoost is currently a GKE-specific extension to the VPA API and is only honored on GKE clusters; it is rendered only when set
1476 ## Ref: https://cloud.google.com/kubernetes-engine/docs/how-to/boost-application-startup
1481 # durationSeconds: 10
1484 # -- Redis repository
1485 repository: chainreg.biz/chainguard-private/redis
1487 ## Do not use 7.4.0 <= v < 8.0.0, otherwise you are no longer using an open source version of Redis
1488 tag: 8.10.2-r1@sha256:56d959dee32a2fd17c6c43400b727c346acc584735d9f3c73788d20fdf37e8be
1489 # -- Redis image pull policy
1490 # @default -- `""` (defaults to global.image.imagePullPolicy)
1492 ## Prometheus redis-exporter sidecar
1494 # -- Enable Prometheus redis-exporter sidecar
1496 # -- Environment variables to pass to the Redis exporter
1498 ## Prometheus redis-exporter image
1500 # -- Repository to use for the redis-exporter
1501 repository: chainreg.biz/chainguard-private/prometheus-redis-exporter
1502 # -- Tag to use for the redis-exporter
1503 tag: 1.93.0-r0@sha256:02d6b26bed0db89b43ed9533d7c94fe9e84cc4f8b1ee3498c711e82ff4f575f5
1504 # -- Image pull policy for the redis-exporter
1505 # @default -- `""` (defaults to global.image.imagePullPolicy)
1507 # -- Redis exporter security context
1508 # @default -- See [values.yaml]
1509 containerSecurityContext:
1511 readOnlyRootFilesystem: true
1512 allowPrivilegeEscalation: false
1514 type: RuntimeDefault
1518 ## Probes for Redis exporter (optional)
1519 ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
1521 # -- Enable Kubernetes liveness probe for Redis exporter (optional)
1523 # -- Number of seconds after the container has started before [probe] is initiated
1524 initialDelaySeconds: 30
1525 # -- How often (in seconds) to perform the [probe]
1527 # -- Number of seconds after which the [probe] times out
1529 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
1531 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
1534 # -- Enable Kubernetes liveness probe for Redis exporter
1536 # -- Number of seconds after the container has started before [probe] is initiated
1537 initialDelaySeconds: 30
1538 # -- How often (in seconds) to perform the [probe]
1540 # -- Number of seconds after which the [probe] times out
1542 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
1544 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
1546 # -- Resource limits and requests for redis-exporter sidecar
1554 # -- Secrets with credentials to pull images from a private registry
1555 # @default -- `[]` (defaults to global.imagePullSecrets)
1556 imagePullSecrets: []
1557 # -- Additional command line arguments to pass to redis-server
1562 # -- Environment variables to pass to the Redis server
1564 # -- envFrom to pass to the Redis server
1565 # @default -- `[]` (See [values.yaml])
1568 # name: config-map-name
1572 ## Probes for Redis server (optional)
1573 ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
1575 # -- Enable Kubernetes liveness probe for Redis server
1577 # -- Number of seconds after the container has started before [probe] is initiated
1578 initialDelaySeconds: 30
1579 # -- How often (in seconds) to perform the [probe]
1581 # -- Number of seconds after which the [probe] times out
1583 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
1585 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
1588 # -- Enable Kubernetes liveness probe for Redis server
1590 # -- Number of seconds after the container has started before [probe] is initiated
1591 initialDelaySeconds: 30
1592 # -- How often (in seconds) to perform the [probe]
1594 # -- Number of seconds after which the [probe] times out
1596 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
1598 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
1600 # -- Additional containers to be added to the redis pod
1601 ## Note: Supports use of custom Helm templates
1603 # -- Init containers to add to the redis pod
1604 ## Note: Supports use of custom Helm templates
1606 # -- Additional volumeMounts to the redis container
1608 # -- Additional volumes to the redis pod
1610 # -- Annotations to be added to the Redis server Deployment
1611 deploymentAnnotations: {}
1612 # -- Labels for the Redis server Deployment
1613 deploymentLabels: {}
1614 # -- Annotations to be added to the Redis server pods
1616 # -- Labels to be added to the Redis server pods
1618 # -- Resource limits and requests for redis
1627 # -- Redis pod-level security context
1628 # @default -- See [values.yaml]
1633 type: RuntimeDefault
1634 # Redis container ports
1636 # -- Redis container port
1638 # -- Metrics container port
1640 # -- Host Network for redis pods
1642 # -- [DNS configuration]
1644 # -- Alternative DNS policy for Redis server pods
1645 dnsPolicy: "ClusterFirst"
1646 # -- Redis container-level security context
1647 # @default -- See [values.yaml]
1648 containerSecurityContext:
1649 readOnlyRootFilesystem: true
1650 allowPrivilegeEscalation: false
1654 # -- Redis service port
1656 # -- Priority class for redis pods
1657 # @default -- `""` (defaults to global.priorityClassName)
1658 priorityClassName: ""
1659 # -- [Node selector]
1660 # @default -- `{}` (defaults to global.nodeSelector)
1662 # -- [Tolerations] for use with node taints
1663 # @default -- `[]` (defaults to global.tolerations)
1665 # -- Assign custom [affinity] rules to the deployment
1666 # @default -- `{}` (defaults to global.affinity preset)
1668 # -- Assign custom [TopologySpreadConstraints] rules to redis
1669 # @default -- `[]` (defaults to global.topologySpreadConstraints)
1670 ## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
1671 ## If labelSelector is left out, it will default to the labelSelector configuration of the deployment
1672 topologySpreadConstraints: []
1674 # topologyKey: topology.kubernetes.io/zone
1675 # whenUnsatisfiable: DoNotSchedule
1677 # -- terminationGracePeriodSeconds for container lifecycle hook
1678 terminationGracePeriodSeconds: 30
1679 # -- Automount API credentials for the Service Account into the pod.
1680 automountServiceAccountToken: true
1682 # -- Create a service account for the redis pod
1684 # -- Service account name for redis pod
1686 # -- Annotations applied to created service account
1688 # -- Automount API credentials for the Service Account
1689 automountServiceAccountToken: false
1691 # -- Redis service annotations
1693 # -- Additional redis service labels
1696 # -- Deploy metrics service
1698 # Redis metrics service configuration
1700 # -- Metrics service type
1702 # -- Metrics service clusterIP. `None` makes a "headless service" (no virtual IP)
1704 # -- Metrics service annotations
1706 # -- Metrics service labels
1708 # -- Metrics service port
1710 # -- Metrics service port name
1711 portName: http-metrics
1713 # -- Enable a prometheus ServiceMonitor
1715 # -- Interval at which metrics should be scraped
1717 # -- When true, honorLabels preserves the metric’s labels when they collide with the target’s labels.
1719 # -- Prometheus [RelabelConfigs] to apply to samples before scraping
1721 # -- Prometheus [MetricRelabelConfigs] to apply to samples before ingestion
1722 metricRelabelings: []
1723 # -- Prometheus ServiceMonitor selector
1725 # prometheus: kube-prometheus
1727 # -- Prometheus ServiceMonitor scheme
1729 # -- Prometheus ServiceMonitor tlsConfig
1731 # -- Prometheus ServiceMonitor namespace
1732 namespace: "" # "monitoring"
1733 # -- Prometheus ServiceMonitor labels
1734 additionalLabels: {}
1735 # -- Prometheus ServiceMonitor annotations
1737 # Default redis's network policy
1739 # -- Default network policy rules used by redis
1740 # @default -- `false` (defaults to global.networkPolicy.create)
1742## Redis-HA subchart replaces custom redis deployment when `redis-ha.enabled=true`
1743# Ref: https://github.com/DandyDeveloper/charts/blob/master/charts/redis-ha/values.yaml
1745 # -- Enables the Redis HA subchart and disables the custom Redis single node deployment
1749 # -- Redis repository
1750 repository: ecr-public.aws.com/docker/library/redis
1752 ## Do not use 7.4.0 <= v < 8.0.0, otherwise you are no longer using an open source version of Redis
1753 ## Runs ahead of the upstream HA manifests' pin: the redis 8.2.x line is only built on Alpine 3.22,
1754 ## whose OpenSSL carries known vulnerabilities (GHSA-5p3w-hgjv-f6q3 report); 8.6.x is the patched base.
1756 ## Prometheus redis-exporter sidecar
1758 # -- Enable Prometheus redis-exporter sidecar
1760 # -- Repository to use for the redis-exporter
1761 image: ghcr.io/oliver006/redis_exporter
1762 # -- Tag to use for the redis-exporter
1765 # -- Configures persistence on Redis nodes
1767 ## Redis specific configuration options
1769 # -- Redis convention for naming the cluster group: must match `^[\\w-\\.]+$` and can be templated
1770 masterGroupName: argocd
1771 # -- Any valid redis config options in this section will be applied to each server (see `redis-ha` chart)
1772 # @default -- See [values.yaml]
1774 # -- Will save the DB if both the given number of seconds and the given number of write operations against the DB occurred. `""` is disabled
1775 # @default -- `'""'`
1777 ## Redis sentinel specific configuration options
1779 # -- Sentinel container lifecycle hooks. The default `postStart` hook resets the sentinel state after a rolling update to prevent high CPU usage
1780 # @default -- See [values.yaml]
1784 ## Note: the reset command hardcodes the master group name `argocd`. If you override `redis-ha.redis.masterGroupName`, you must override this hook to match.
1788 - 'sleep 30; redis-cli -p 26379 sentinel reset argocd'
1789 ## Enables a HA Proxy for better LoadBalancing / Sentinel Master support. Automatically proxies to Redis master.
1791 # -- Enabled HAProxy LoadBalancing/Proxy
1793 # -- Custom labels for the haproxy pod. This is relevant for Argo CD CLI.
1795 app.kubernetes.io/name: argocd-redis-ha-haproxy
1797 # -- HAProxy Image Repository
1798 repository: ecr-public.aws.com/docker/library/haproxy
1800 # -- HAProxy enable prometheus metric scraping
1802 # -- Whether the haproxy pods should be forced to run on separate nodes.
1803 hardAntiAffinity: true
1804 # -- Additional affinities to add to the haproxy pods.
1805 additionalAffinities: {}
1806 # -- Assign custom [affinity] rules to the haproxy pods.
1808 # -- [Tolerations] for use with node taints for haproxy pods.
1810 # -- HAProxy container-level security context
1811 # @default -- See [values.yaml]
1812 containerSecurityContext:
1813 readOnlyRootFilesystem: true
1814 # -- Configures redis-ha with AUTH
1816 # -- Existing Secret to use for redis-ha authentication.
1817 # By default the redis-secret-init Job is generating this Secret.
1818 # When `redisSecretInit.enabled` is `false`, the Argo CD components read the Redis password from this Secret too (key `redis-ha.authKey`).
1819 existingSecret: argocd-redis
1820 # -- Whether the Redis server pods should be forced to run on separate nodes.
1821 hardAntiAffinity: true
1822 # -- Additional affinities to add to the Redis server pods.
1823 additionalAffinities: {}
1824 # -- Assign custom [affinity] rules to the Redis pods.
1826 # -- [Tolerations] for use with node taints for Redis pods.
1828 # -- Assign custom [TopologySpreadConstraints] rules to the Redis pods.
1829 ## https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
1830 topologySpreadConstraints:
1831 # -- Enable Redis HA topology spread constraints
1833 # -- Max skew of pods tolerated
1834 # @default -- `""` (defaults to `1`)
1836 # -- Topology key for spread
1837 # @default -- `""` (defaults to `topology.kubernetes.io/zone`)
1839 # -- Enforcement policy, hard or soft
1840 # @default -- `""` (defaults to `ScheduleAnyway`)
1841 whenUnsatisfiable: ""
1842 # -- Redis HA statefulset container-level security context
1843 # @default -- See [values.yaml]
1844 containerSecurityContext:
1845 readOnlyRootFilesystem: true
1846# External Redis parameters
1848 # -- External Redis server host
1850 # -- External Redis username
1852 # -- External Redis password
1854 # -- External Redis server port
1856 # -- The name of an existing secret with Redis (must contain key `redis-password`. And should contain `redis-username` if username is not `default`) and Sentinel credentials.
1857 # When it's set, the `externalRedis.username` and `externalRedis.password` parameters are ignored
1859 # -- External Redis Secret annotations
1860 secretAnnotations: {}
1862 # -- Enable Redis secret initialization. If disabled, secret must be provisioned by alternative methods
1864 # -- Redis secret-init name
1865 name: redis-secret-init
1867 # -- Repository to use for the Redis secret-init Job
1868 # @default -- `""` (defaults to global.image.repository)
1869 repository: "" # defaults to global.image.repository
1870 # -- Tag to use for the Redis secret-init Job
1871 # @default -- `""` (defaults to global.image.tag)
1872 tag: "" # defaults to global.image.tag
1873 # -- Image pull policy for the Redis secret-init Job
1874 # @default -- `""` (defaults to global.image.imagePullPolicy)
1875 imagePullPolicy: "" # IfNotPresent
1876 # -- Additional command line arguments for the Redis secret-init Job
1878 # -- Secrets with credentials to pull images from a private registry
1879 # @default -- `[]` (defaults to global.imagePullSecrets)
1880 imagePullSecrets: []
1881 # -- Runtime class name for the Redis secret-init Job
1882 # @default -- `""` (defaults to global.runtimeClassName)
1883 runtimeClassName: ""
1884 # -- Annotations to be added to the Redis secret-init Job
1886 # -- Annotations to be added to the Redis secret-init Job
1888 # -- Labels to be added to the Redis secret-init Job
1890 # -- Resource limits and requests for Redis secret-init Job
1899 # -- Application controller container-level security context
1900 # @default -- See [values.yaml]
1901 containerSecurityContext:
1902 allowPrivilegeEscalation: false
1906 readOnlyRootFilesystem: true
1909 type: RuntimeDefault
1910 # -- Redis secret-init Job pod-level security context
1913 # -- Create a service account for the redis pod
1915 # -- Service account name for redis pod
1917 # -- Annotations applied to created service account
1919 # -- Automount API credentials for the Service Account
1920 automountServiceAccountToken: true
1921 # -- Priority class for Redis secret-init Job
1922 # @default -- `""` (defaults to global.priorityClassName)
1923 priorityClassName: ""
1924 # -- Host Network for redis-secret-init pods
1926 # -- [DNS configuration]
1928 # -- Alternative DNS policy for Redis secret-init Job
1929 dnsPolicy: "ClusterFirst"
1930 # -- Assign custom [affinity] rules to the Redis secret-init Job
1932 # -- Node selector to be added to the Redis secret-init Job
1933 # @default -- `{}` (defaults to global.nodeSelector)
1935 # -- Tolerations to be added to the Redis secret-init Job
1936 # @default -- `[]` (defaults to global.tolerations)
1940 # -- Argo CD server name
1942 # -- The number of server pods to run
1944 # -- Runtime class name for the Argo CD server
1945 # @default -- `""` (defaults to global.runtimeClassName)
1946 runtimeClassName: ""
1947 ## Argo CD server Horizontal Pod Autoscaler
1949 # -- Enable Horizontal Pod Autoscaler ([HPA]) for the Argo CD server
1951 # -- Minimum number of replicas for the Argo CD server [HPA]
1953 # -- Maximum number of replicas for the Argo CD server [HPA]
1955 # -- Average CPU utilization percentage for the Argo CD server [HPA]
1956 targetCPUUtilizationPercentage: 50
1957 # -- Average memory utilization percentage for the Argo CD server [HPA]
1958 targetMemoryUtilizationPercentage: 50
1959 # -- Configures the scaling behavior of the target in both Up and Down directions.
1962 # stabilizationWindowSeconds: 300
1966 # periodSeconds: 180
1968 # stabilizationWindowSeconds: 300
1973 # -- Configures custom HPA metrics for the Argo CD server
1974 # Ref: https://kubernetes.io/docs/tasks/run-application/horizontal-pod-autoscale/
1976 ## Argo CD server Pod Disruption Budget
1977 ## Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
1979 # -- Deploy a [PodDisruptionBudget] for the Argo CD server
1981 # -- Labels to be added to Argo CD server pdb
1983 # -- Annotations to be added to Argo CD server pdb
1985 # -- Number of pods that are available after eviction as number or percentage (eg.: 50%)
1986 # @default -- `""` (defaults to 0 if not specified)
1988 # -- Number of pods that are unavailable after eviction as number or percentage (eg.: 50%).
1989 ## Has higher precedence over `server.pdb.minAvailable`
1991 # -- Policy for evicting unhealthy (not ready) pods, either `IfHealthyBudget` or `AlwaysAllow`
1992 ## Defaults to `IfHealthyBudget` if not set
1993 unhealthyPodEvictionPolicy: ""
1994 ## Argo CD server Vertical Pod Autoscaler
1995 ## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/
1997 # -- Deploy a [VerticalPodAutoscaler](https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/) for the Argo CD server
1999 # -- Labels to be added to Argo CD server vpa
2001 # -- Annotations to be added to Argo CD server vpa
2003 # -- One of the VPA operation modes
2004 ## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically
2005 ## Note: Recreate update mode requires more than one replica unless the min-replicas VPA controller flag is overridden
2007 # -- Controls how VPA computes the recommended resources for Argo CD server container
2008 ## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/examples/hamster.yaml
2010 # controlledResources: ["cpu", "memory"]
2017 # -- The recommenders that will provide recommendations for vertical scaling. Only relevant if a named VPA recommender (e.g. one started with a custom recommender name) is in use; leave unset to use the cluster's default recommender
2018 ## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/docs/api.md#verticalpodautoscalerspec
2019 ## NOTE: specify only zero or one recommender as of VPA 1.7.1
2021 # -- Configures a startup resource boost for faster cold-start (application boot) resource allocation. NOTE: startupBoost is currently a GKE-specific extension to the VPA API and is only honored on GKE clusters; it is rendered only when set
2022 ## Ref: https://cloud.google.com/kubernetes-engine/docs/how-to/boost-application-startup
2027 # durationSeconds: 10
2028 ## Argo CD server image
2030 # -- Repository to use for the Argo CD server
2031 # @default -- `""` (defaults to global.image.repository)
2032 repository: "" # defaults to global.image.repository
2033 # -- Tag to use for the Argo CD server
2034 # @default -- `""` (defaults to global.image.tag)
2035 tag: "" # defaults to global.image.tag
2036 # -- Image pull policy for the Argo CD server
2037 # @default -- `""` (defaults to global.image.imagePullPolicy)
2038 imagePullPolicy: "" # IfNotPresent
2039 # -- Secrets with credentials to pull images from a private registry
2040 # @default -- `[]` (defaults to global.imagePullSecrets)
2041 imagePullSecrets: []
2042 # -- Additional command line arguments to pass to Argo CD server
2044 # -- Environment variables to pass to Argo CD server
2046 # -- envFrom to pass to Argo CD server
2047 # @default -- `[]` (See [values.yaml])
2050 # name: config-map-name
2054 # -- Specify postStart and preStop lifecycle hooks for your argo-cd-server container
2056 ## Argo CD extensions
2057 ## This function in tech preview stage, do expect instability or breaking changes in newer versions.
2058 ## Ref: https://github.com/argoproj-labs/argocd-extension-installer
2059 ## When you enable extensions, you need to configure RBAC of logged in Argo CD user.
2060 ## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/rbac/#the-extensions-resource
2062 # -- Enable support for Argo CD extensions
2064 ## Argo CD extension installer image
2066 # -- Repository to use for extension installer image
2067 repository: chainreg.biz/chainguard-private/argocd-extension-installer
2068 # -- Tag to use for extension installer image
2069 tag: 1.1.0-r0@sha256:af610578dbc8ee874f853e70ed3b096fefc0812f097437ca29d4487684ef597c
2070 # -- Image pull policy for extensions
2071 # @default -- `""` (defaults to global.image.imagePullPolicy)
2073 # -- Extensions for Argo CD
2074 # @default -- `[]` (See [values.yaml])
2075 ## Ref: https://github.com/argoproj-labs/argocd-extension-metrics#install-ui-extension
2077 # - name: extension-metrics
2079 # - name: EXTENSION_URL
2080 # value: https://github.com/argoproj-labs/argocd-extension-metrics/releases/download/v1.0.0/extension.tar.gz
2081 # - name: EXTENSION_CHECKSUM_URL
2082 # value: https://github.com/argoproj-labs/argocd-extension-metrics/releases/download/v1.0.0/extension_checksums.txt
2084 # -- Server UI extensions container-level security context
2085 # @default -- See [values.yaml]
2086 containerSecurityContext:
2088 readOnlyRootFilesystem: true
2089 allowPrivilegeEscalation: false
2092 type: RuntimeDefault
2096 # -- Resource limits and requests for the argocd-extensions container
2104 # -- Additional containers to be added to the server pod
2105 ## Note: Supports use of custom Helm templates
2107 # - name: my-sidecar
2108 # image: nginx:latest
2109 # - name: lemonldap-ng-controller
2110 # image: lemonldapng/lemonldap-ng-controller:0.2.0
2112 # - /lemonldap-ng-controller
2113 # - --alsologtostderr
2114 # - --configmap=$(POD_NAMESPACE)/lemonldap-ng-configuration
2119 # fieldPath: metadata.name
2120 # - name: POD_NAMESPACE
2123 # fieldPath: metadata.namespace
2125 # - name: copy-portal-skins
2126 # mountPath: /srv/var/lib/lemonldap-ng/portal/skins
2128 # -- Init containers to add to the server pod
2129 ## If your target Kubernetes cluster(s) require a custom credential (exec) plugin
2130 ## you could use this (and the same in the application controller pod) to provide such executable
2131 ## Ref: https://kubernetes.io/docs/reference/access-authn-authz/authentication/#client-go-credential-plugins
2133 # - name: download-tools
2137 # - wget -qO /custom-tools/kubelogin.zip https://github.com/Azure/kubelogin/releases/download/v0.2.7/kubelogin-linux-amd64.zip &&
2138 # mkdir /custom-tools/tmp && unzip -d /custom-tools/tmp /custom-tools/kubelogin.zip &&
2139 # mv /custom-tools/tmp/bin/linux_amd64/kubelogin /custom-tools/ && rm -rf custom-tools/tmp && rm /custom-tools/kubelogin.zip
2141 # - mountPath: /custom-tools
2142 # name: custom-tools
2144 # -- Additional volumeMounts to the server main container
2146 # - mountPath: /usr/local/bin/kubelogin
2147 # name: custom-tools
2148 # subPath: kubelogin
2150 # -- Additional volumes to the server pod
2152 # - name: custom-tools
2155 ## Argo CD server emptyDir volumes
2157 # -- EmptyDir size limit for the Argo CD server
2158 # @default -- `""` (defaults not set if not specified i.e. no size limit)
2161 # -- Annotations to be added to server Deployment
2162 deploymentAnnotations: {}
2163 # -- Labels for the server Deployment
2164 deploymentLabels: {}
2165 # -- Annotations to be added to server pods
2167 # -- Labels to be added to server pods
2169 # -- Resource limits and requests for the Argo CD server
2178 # Server container ports
2180 # -- Server container port
2182 # -- Metrics container port
2184 # -- Host Network for Server pods
2186 # -- [DNS configuration]
2188 # -- Alternative DNS policy for Server pods
2189 dnsPolicy: "ClusterFirst"
2190 # -- Server container-level security context
2191 # @default -- See [values.yaml]
2192 containerSecurityContext:
2194 readOnlyRootFilesystem: true
2195 allowPrivilegeEscalation: false
2197 type: RuntimeDefault
2201 ## Readiness and liveness probes for default backend
2202 ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
2204 # -- Enable Kubernetes readiness probe for default backend
2206 # -- Http path to use for the readiness probe
2208 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
2210 # -- Number of seconds after the container has started before [probe] is initiated
2211 initialDelaySeconds: 10
2212 # -- How often (in seconds) to perform the [probe]
2214 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
2216 # -- Number of seconds after which the [probe] times out
2219 # -- Enable Kubernetes liveness probe for default backend
2221 # -- Http path to use for the liveness probe
2222 httpPath: /healthz?full=true
2223 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
2225 # -- Number of seconds after the container has started before [probe] is initiated
2226 initialDelaySeconds: 10
2227 # -- How often (in seconds) to perform the [probe]
2229 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
2231 # -- Number of seconds after which the [probe] times out
2233 ## Startup probe for Argo CD server (optional)
2234 ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
2236 # -- Enable Kubernetes startup probe for Argo CD server
2238 # -- Http path to use for the startup probe
2240 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
2241 failureThreshold: 20
2242 # -- Number of seconds after the container has started before [probe] is initiated
2243 initialDelaySeconds: 10
2244 # -- How often (in seconds) to perform the [probe]
2246 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
2248 # -- Number of seconds after which the [probe] times out
2250 # -- terminationGracePeriodSeconds for container lifecycle hook
2251 terminationGracePeriodSeconds: 30
2252 # -- Priority class for the Argo CD server pods
2253 # @default -- `""` (defaults to global.priorityClassName)
2254 priorityClassName: ""
2255 # -- [Node selector]
2256 # @default -- `{}` (defaults to global.nodeSelector)
2258 # -- [Tolerations] for use with node taints
2259 # @default -- `[]` (defaults to global.tolerations)
2261 # -- Assign custom [affinity] rules to the deployment
2262 # @default -- `{}` (defaults to global.affinity preset)
2264 # -- Assign custom [TopologySpreadConstraints] rules to the Argo CD server
2265 # @default -- `[]` (defaults to global.topologySpreadConstraints)
2266 ## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
2267 ## If labelSelector is left out, it will default to the labelSelector configuration of the deployment
2268 topologySpreadConstraints: []
2270 # topologyKey: topology.kubernetes.io/zone
2271 # whenUnsatisfiable: DoNotSchedule
2273 # -- Deployment strategy to be added to the server Deployment
2274 deploymentStrategy: {}
2275 # type: RollingUpdate
2278 # maxUnavailable: 25%
2280 # TLS certificate configuration via cert-manager
2281 ## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/tls/#tls-certificates-used-by-argocd-server
2283 # -- Deploy a Certificate resource (requires cert-manager)
2285 # -- Certificate primary domain (commonName)
2286 # @default -- `""` (defaults to global.domain)
2288 # -- Certificate Subject Alternate Names (SANs)
2290 # -- The requested 'duration' (i.e. lifetime) of the certificate.
2291 # @default -- `""` (defaults to 2160h = 90d if not specified)
2292 ## Ref: https://cert-manager.io/docs/usage/certificate/#renewal
2294 # -- How long before the expiry a certificate should be renewed.
2295 # @default -- `""` (defaults to 360h = 15d if not specified)
2296 ## Ref: https://cert-manager.io/docs/usage/certificate/#renewal
2298 # Certificate issuer
2299 ## Ref: https://cert-manager.io/docs/concepts/issuer
2301 # -- Certificate issuer group. Set if using an external issuer. Eg. `cert-manager.io`
2303 # -- Certificate issuer kind. Either `Issuer` or `ClusterIssuer`
2305 # -- Certificate issuer name. Eg. `letsencrypt`
2307 # Private key of the certificate
2309 # -- Rotation policy of private key when certificate is re-issued. Either: `Never` or `Always`
2310 rotationPolicy: Never
2311 # -- The private key cryptography standards (PKCS) encoding for private key. Either: `PCKS1` or `PKCS8`
2313 # -- Algorithm used to generate certificate private key. One of: `RSA`, `Ed25519` or `ECDSA`
2315 # -- Key bit size of the private key. If algorithm is set to `Ed25519`, size is ignored.
2317 # -- Annotations to be applied to the Server Certificate
2319 # -- Usages for the certificate
2320 ### Ref: https://cert-manager.io/docs/reference/api-docs/#cert-manager.io/v1.KeyUsage
2322 # -- Annotations that allow the certificate to be composed from data residing in existing Kubernetes Resources
2323 secretTemplateAnnotations: {}
2324 # TLS certificate configuration via Secret
2325 ## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/tls/#tls-certificates-used-by-argocd-server
2327 # -- Create argocd-server-tls secret
2329 # -- Annotations to be added to argocd-server-tls secret
2331 # -- Labels to be added to argocd-server-tls secret
2333 # -- Private Key of the certificate
2335 # -- Certificate data
2337 ## Server service configuration
2339 # -- Server service annotations
2341 # -- Server service labels
2343 # -- Server service type
2345 # -- Server service http port for NodePort service type (only if `server.service.type` is set to "NodePort")
2347 # -- (int) Server service http2 port for NodePort service type (only if `server.service.servicePortHttp2` is set and `server.service.type` is set to "NodePort")
2348 # @default -- `nil` (a random node port is assigned)
2350 # -- Server service https port for NodePort service type (only if `server.service.type` is set to "NodePort")
2351 nodePortHttps: 30443
2352 # -- Server service http port
2354 # -- (int) Server service cleartext http2 (h2c) port, targeting the same container port as `servicePortHttp`
2355 # @default -- `nil` (disabled)
2356 ## The Argo CD server serves the web UI (HTTP/1.1) and gRPC (HTTP/2) on a single container port, and
2357 ## `appProtocol` is single-valued per service port. Set this to expose a second port advertising the
2358 ## h2c backend protocol, for Gateway API implementations that do not infer it from the route type.
2359 ## Leave empty to disable. Only rendered when `configs.params."server.insecure"` is `true`, since
2360 ## h2c is not applicable to a TLS backend.
2362 # -- Server service https port
2363 servicePortHttps: 443
2364 # -- Server service http port name, can be used to route traffic via istio
2365 servicePortHttpName: http
2366 # -- Server service http2 port name, can be used to route traffic via istio
2367 servicePortHttp2Name: http2
2368 # -- Server service https port name, can be used to route traffic via istio
2369 servicePortHttpsName: https
2370 # -- Server service http2 port appProtocol, e.g. `kubernetes.io/h2c`. Implementations that select the
2371 # protocol from the port name instead do not need it
2372 ## Ref: https://kubernetes.io/docs/concepts/services-networking/service/#application-protocol
2373 servicePortHttp2AppProtocol: ""
2374 # -- Server service https port appProtocol
2375 ## Ref: https://kubernetes.io/docs/concepts/services-networking/service/#application-protocol
2376 servicePortHttpsAppProtocol: ""
2377 # -- The class of the load balancer implementation
2378 loadBalancerClass: ""
2379 # -- LoadBalancer will get created with the IP specified in this field
2381 # -- Source IP ranges to allow access to service from
2382 ## EKS Ref: https://repost.aws/knowledge-center/eks-cidr-ip-address-loadbalancer
2383 ## GKE Ref: https://cloud.google.com/kubernetes-engine/docs/concepts/network-overview#limit-connectivity-ext-lb
2384 loadBalancerSourceRanges: []
2385 # -- Server service external IPs
2387 # -- Denotes if this Service desires to route external traffic to node-local or cluster-wide endpoints
2388 ## Ref: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip
2389 externalTrafficPolicy: Cluster
2390 # -- Used to maintain session affinity. Supports `ClientIP` and `None`
2391 ## Ref: https://kubernetes.io/docs/concepts/services-networking/service/#virtual-ips-and-service-proxies
2392 sessionAffinity: None
2393 ## Server metrics service configuration
2395 # -- Deploy metrics service
2398 # -- Metrics service type
2400 # -- Metrics service clusterIP. `None` makes a "headless service" (no virtual IP)
2402 # -- Metrics service annotations
2404 # -- Metrics service labels
2406 # -- Metrics service port
2408 # -- Metrics service port name
2409 portName: http-metrics
2411 # -- Enable a prometheus ServiceMonitor
2413 # -- Prometheus ServiceMonitor interval
2415 # -- Prometheus ServiceMonitor scrapeTimeout. If empty, Prometheus uses the global scrape timeout unless it is less than the target's scrape interval value in which the latter is used.
2417 # -- When true, honorLabels preserves the metric’s labels when they collide with the target’s labels.
2419 # -- Prometheus [RelabelConfigs] to apply to samples before scraping
2421 # -- Prometheus [MetricRelabelConfigs] to apply to samples before ingestion
2422 metricRelabelings: []
2423 # -- Prometheus ServiceMonitor selector
2425 # prometheus: kube-prometheus
2427 # -- Prometheus ServiceMonitor scheme
2429 # -- Prometheus ServiceMonitor tlsConfig
2431 # -- Prometheus ServiceMonitor namespace
2432 namespace: "" # monitoring
2433 # -- Prometheus ServiceMonitor labels
2434 additionalLabels: {}
2435 # -- Prometheus ServiceMonitor annotations
2437 # -- Automount API credentials for the Service Account into the pod.
2438 automountServiceAccountToken: true
2440 # -- Create server service account
2442 # -- Server service account name
2444 # -- Annotations applied to created service account
2446 # -- Labels applied to created service account
2448 # -- Automount API credentials for the Service Account
2449 automountServiceAccountToken: true
2450 # Argo CD server ingress configuration
2452 # -- Enable an ingress resource for the Argo CD server
2454 # -- Specific implementation for ingress controller. One of `generic`, `aws` or `gke`
2455 ## Additional configuration might be required in related configuration sections
2457 # -- Additional ingress labels
2459 # -- Additional ingress annotations
2460 ## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/ingress/#option-1-ssl-passthrough
2462 # nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
2463 # nginx.ingress.kubernetes.io/ssl-passthrough: "true"
2465 # -- Defines which ingress controller will implement the resource
2466 ingressClassName: ""
2467 # -- Argo CD server hostname
2468 # @default -- `""` (defaults to global.domain)
2470 # -- The path to Argo CD server
2472 # -- Ingress path type. One of `Exact`, `Prefix` or `ImplementationSpecific`
2474 # -- Enable TLS configuration for the hostname defined at `server.ingress.hostname`
2475 ## TLS certificate will be retrieved from a TLS secret `argocd-server-tls`
2476 ## You can create this secret via `certificate` or `certificateSecret` option
2478 # -- The list of additional hostnames to be covered by ingress record
2479 # @default -- `[]` (See [values.yaml])
2481 # - name: argocd.example.com
2484 # -- Additional ingress paths
2485 # @default -- `[]` (See [values.yaml])
2486 ## Note: Supports use of custom Helm templates
2492 # name: ssl-redirect
2494 # name: use-annotation
2496 # -- Additional ingress rules
2497 # @default -- `[]` (See [values.yaml])
2498 ## Note: Supports use of custom Helm templates
2506 # name: '{{ include "argo-cd.server.fullname" . }}'
2508 # name: '{{ .Values.server.service.servicePortHttpsName }}'
2510 # -- Additional TLS configuration
2511 # @default -- `[]` (See [values.yaml])
2514 # - argocd.example.com
2515 # secretName: your-certificate-name
2517 # AWS specific options for Application Load Balancer
2518 # Applies only when `serv.ingress.controller` is set to `aws`
2519 ## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/ingress/#aws-application-load-balancers-albs-and-classic-elb-http-mode
2521 # -- Backend protocol version for the AWS ALB gRPC service
2522 ## This tells AWS to send traffic from the ALB using gRPC.
2523 ## For more information: https://docs.aws.amazon.com/elasticloadbalancing/latest/application/target-group-health-checks.html#health-check-settings
2524 backendProtocolVersion: GRPC
2525 # -- Service type for the AWS ALB gRPC service
2526 ## Can be of type NodePort or ClusterIP depending on which mode you are running.
2527 ## Instance mode needs type NodePort, IP mode needs type ClusterIP
2528 ## Ref: https://kubernetes-sigs.github.io/aws-load-balancer-controller/v2.2/how-it-works/#ingress-traffic
2529 serviceType: NodePort
2530 # -- Annotations for the AWS ALB gRPC service
2531 ## Allows adding custom annotations to the gRPC service for integrations like DataDog, Prometheus, etc.
2532 serviceAnnotations: {}
2533 # Google specific options for Google Application Load Balancer
2534 # Applies only when `server.ingress.controller` is set to `gke`
2535 ## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/ingress/#google-cloud-load-balancers-with-kubernetes-ingress
2537 # -- Google [BackendConfig] resource, for use with the GKE Ingress Controller
2538 # @default -- `{}` (See [values.yaml])
2539 ## Ref: https://cloud.google.com/kubernetes-engine/docs/how-to/ingress-features#configuring_ingress_features_through_frontendconfig_parameters
2543 # oauthclientCredentials:
2544 # secretName: argocd-secret
2546 # -- Google [FrontendConfig] resource, for use with the GKE Ingress Controller
2547 # @default -- `{}` (See [values.yaml])
2548 ## Ref: https://cloud.google.com/kubernetes-engine/docs/how-to/ingress-features#configuring_ingress_features_through_frontendconfig_parameters
2552 # responseCodeName: RESPONSE_CODE
2554 # Managed GKE certificate for ingress hostname
2556 # -- Create ManagedCertificate resource and annotations for Google Load balancer
2557 ## Ref: https://cloud.google.com/kubernetes-engine/docs/how-to/managed-certs
2559 # -- Additional domains for ManagedCertificate resource
2561 # - argocd.example.com
2562 # Dedicated gRPC ingress for ingress controllers that supports only single backend protocol per Ingress resource
2563 # Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/ingress/#option-2-multiple-ingress-objects-and-hosts
2565 # -- Enable an ingress resource for the Argo CD server for dedicated [gRPC-ingress]
2567 # -- Additional ingress annotations for dedicated [gRPC-ingress]
2569 # -- Additional ingress labels for dedicated [gRPC-ingress]
2571 # -- Defines which ingress controller will implement the resource [gRPC-ingress]
2572 ingressClassName: ""
2573 # -- Argo CD server hostname for dedicated [gRPC-ingress]
2574 # @default -- `""` (defaults to grpc.`server.ingress.hostname`)
2576 # -- Argo CD server ingress path for dedicated [gRPC-ingress]
2578 # -- Ingress path type for dedicated [gRPC-ingress]. One of `Exact`, `Prefix` or `ImplementationSpecific`
2580 # -- Enable TLS configuration for the hostname defined at `server.ingressGrpc.hostname`
2581 ## TLS certificate will be retrieved from a TLS secret with name: `argocd-server-grpc-tls`
2583 # -- The list of additional hostnames to be covered by ingress record
2584 # @default -- `[]` (See [values.yaml])
2586 # - name: grpc.argocd.example.com
2589 # -- Additional ingress paths for dedicated [gRPC-ingress]
2590 # @default -- `[]` (See [values.yaml])
2591 ## Note: Supports use of custom Helm templates
2597 # name: ssl-redirect
2599 # name: use-annotation
2601 # -- Additional ingress rules
2602 # @default -- `[]` (See [values.yaml])
2603 ## Note: Supports use of custom Helm templates
2611 # name: '{{ include "argo-cd.server.fullname" . }}'
2613 # name: '{{ .Values.server.service.servicePortHttpName }}'
2615 # -- Additional TLS configuration for dedicated [gRPC-ingress]
2616 # @default -- `[]` (See [values.yaml])
2618 # - secretName: your-certificate-name
2620 # - argocd.example.com
2621 # Create a OpenShift Route with SSL passthrough for UI and CLI
2622 # Consider setting 'hostname' e.g. https://argocd.apps-crc.testing/ using your Default Ingress Controller Domain
2623 # Find your domain with: kubectl describe --namespace=openshift-ingress-operator ingresscontroller/default | grep Domain:
2624 # If 'hostname' is an empty string "" OpenShift will create a hostname for you.
2626 # -- Enable an OpenShift Route for the Argo CD server
2628 # -- Openshift Route annotations
2630 # -- Hostname of OpenShift Route
2632 # -- Termination type of Openshift Route
2633 termination_type: passthrough
2634 # -- Termination policy of Openshift Route
2635 termination_policy: None
2636 # Gateway API HTTPRoute configuration
2637 # NOTE: Gateway API support is in EXPERIMENTAL status
2638 # Support depends on your Gateway controller implementation
2639 # Some controllers may require additional configuration (e.g., BackendTLSPolicy for HTTPS backends)
2640 # Refer to https://gateway-api.sigs.k8s.io/implementations/ for controller-specific details
2642 # -- Enable HTTPRoute resource for Argo CD server (Gateway API)
2644 # -- Additional HTTPRoute labels
2646 # -- Additional HTTPRoute annotations
2648 # -- Gateway API parentRefs for the HTTPRoute
2649 ## Must reference an existing Gateway
2650 # @default -- `[]` (See [values.yaml])
2652 # - name: example-gateway
2653 # namespace: example-gateway-namespace
2654 # sectionName: https
2655 # -- List of hostnames for the HTTPRoute
2656 # @default -- `[]` (See [values.yaml])
2658 # - argocd.example.com
2659 # -- HTTPRoute rules configuration
2660 # @default -- `[]` (See [values.yaml])
2667 # - type: RequestHeaderModifier
2668 # requestHeaderModifier:
2670 # - name: X-Custom-Header
2671 # value: custom-value
2674 # backendRequest: 2s
2675 # Gateway API GRPCRoute configuration
2676 # NOTE: Gateway API support is in EXPERIMENTAL status
2677 # Support depends on your Gateway controller implementation
2678 # Refer to https://gateway-api.sigs.k8s.io/implementations/ for controller-specific details
2680 # -- Enable GRPCRoute resource for Argo CD server (Gateway API)
2682 # -- Additional GRPCRoute labels
2684 # -- Additional GRPCRoute annotations
2686 # -- Gateway API parentRefs for the GRPCRoute
2687 ## Must reference an existing Gateway
2688 # @default -- `[]` (See [values.yaml])
2690 # - name: example-gateway
2691 # namespace: example-gateway-namespace
2693 # -- List of hostnames for the GRPCRoute
2694 # @default -- `[]` (See [values.yaml])
2696 # - grpc.argocd.example.com
2697 # -- GRPCRoute rules configuration
2698 # @default -- `[]` (See [values.yaml])
2704 # - type: RequestHeaderModifier
2705 # requestHeaderModifier:
2707 # - name: X-Custom-Header
2708 # value: custom-value
2709 # Gateway API BackendTLSPolicy configuration
2710 # NOTE: BackendTLSPolicy support is in EXPERIMENTAL status
2711 # Required for HTTPS backends when using Gateway API
2712 # Not all Gateway controllers support this resource (e.g., Cilium does not support it yet)
2714 # -- Enable BackendTLSPolicy resource for Argo CD server (Gateway API)
2716 # -- Additional BackendTLSPolicy labels
2718 # -- Additional BackendTLSPolicy annotations
2720 # -- Target references for the BackendTLSPolicy
2721 # @default -- `[]` (See [values.yaml])
2725 # name: argocd-server
2726 # sectionName: https
2727 # -- TLS validation configuration
2728 # @default -- `{}` (See [values.yaml])
2730 # hostname: argocd-server.argocd.svc.cluster.local
2731 # caCertificateRefs:
2732 # - name: example-ca-cert
2735 # wellKnownCACertificates: System
2736 # Gateway API ListenerSet configuration
2737 # NOTE: Gateway API support is in EXPERIMENTAL status
2738 # ListenerSet allows attaching additional listeners to an existing Gateway
2739 # Requires Gateway API v1alpha2 and a controller that supports ListenerSet
2740 # Refer to https://gateway-api.sigs.k8s.io/reference/spec/#gateway.networking.k8s.io/v1alpha2.ListenerSet
2742 # -- Enable ListenerSet resource for Argo CD server (Gateway API)
2744 # -- Additional ListenerSet labels
2746 # -- Additional ListenerSet annotations
2748 # -- Gateway API parentRef for the ListenerSet
2749 ## Must reference an existing Gateway. Unlike HTTPRoute, ListenerSet accepts exactly one parentRef.
2750 # @default -- `{}` (See [values.yaml])
2752 # name: example-gateway
2753 # namespace: example-gateway-namespace
2754 # -- Hostname for the synthesized listener. Defaults to global.domain when empty.
2756 # -- Name of the synthesized listener. Also used as sectionName in auto-derived httproute parentRefs.
2758 # -- Port for the synthesized listener
2760 # -- Protocol for the synthesized listener
2762 # -- TLS configuration for the synthesized listener
2764 # -- Enable TLS on the synthesized listener
2766 # -- TLS termination mode
2768 # -- Secret name for TLS certificate. Defaults to `argocd-server-tls` when empty.
2770 # -- allowedRoutes for the synthesized listener
2774 # -- Listeners to attach to the parent Gateway. When non-empty, used verbatim and all synthesized listener fields above are ignored.
2775 # @default -- `[]` (See [values.yaml])
2780 # hostname: argocd.example.com
2786 # name: argocd-server-tls
2790 ## Enable this and set the rules: to whatever custom rules you want for the Cluster Role resource.
2793 # -- Enable custom rules for the server's ClusterRole resource
2795 # -- List of custom rules for the server's ClusterRole resource
2797 # Default ArgoCD Server's network policy
2799 # -- Default network policy rules used by ArgoCD Server
2800 # @default -- `false` (defaults to global.networkPolicy.create)
2804 # -- Repo server name
2806 # -- The number of repo server pods to run
2808 # -- Runtime class name for the repo server
2809 # @default -- `""` (defaults to global.runtimeClassName)
2810 runtimeClassName: ""
2811 ## Repo server Horizontal Pod Autoscaler
2813 # -- Enable Horizontal Pod Autoscaler ([HPA]) for the repo server
2815 # -- Minimum number of replicas for the repo server [HPA]
2817 # -- Maximum number of replicas for the repo server [HPA]
2819 # -- Average CPU utilization percentage for the repo server [HPA]
2820 targetCPUUtilizationPercentage: 50
2821 # -- Average memory utilization percentage for the repo server [HPA]
2822 targetMemoryUtilizationPercentage: 50
2823 # -- Configures the scaling behavior of the target in both Up and Down directions.
2826 # stabilizationWindowSeconds: 300
2830 # periodSeconds: 180
2832 # stabilizationWindowSeconds: 300
2837 # -- Configures custom HPA metrics for the Argo CD repo server
2838 # Ref: https://kubernetes.io/docs/tasks/run-application/horizontal-pod-autoscale/
2840 ## Repo server Pod Disruption Budget
2841 ## Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
2843 # -- Deploy a [PodDisruptionBudget] for the repo server
2845 # -- Labels to be added to repo server pdb
2847 # -- Annotations to be added to repo server pdb
2849 # -- Number of pods that are available after eviction as number or percentage (eg.: 50%)
2850 # @default -- `""` (defaults to 0 if not specified)
2852 # -- Number of pods that are unavailable after eviction as number or percentage (eg.: 50%).
2853 ## Has higher precedence over `repoServer.pdb.minAvailable`
2855 # -- Policy for evicting unhealthy (not ready) pods, either `IfHealthyBudget` or `AlwaysAllow`
2856 ## Defaults to `IfHealthyBudget` if not set
2857 unhealthyPodEvictionPolicy: ""
2858 ## Repo server Vertical Pod Autoscaler
2859 ## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/
2861 # -- Deploy a [VerticalPodAutoscaler](https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/) for the repo server
2863 # -- Labels to be added to repo server vpa
2865 # -- Annotations to be added to repo server vpa
2867 # -- One of the VPA operation modes
2868 ## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically
2869 ## Note: Recreate update mode requires more than one replica unless the min-replicas VPA controller flag is overridden
2871 # -- Controls how VPA computes the recommended resources for repo server container
2872 ## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/examples/hamster.yaml
2874 # controlledResources: ["cpu", "memory"]
2881 # -- The recommenders that will provide recommendations for vertical scaling. Only relevant if a named VPA recommender (e.g. one started with a custom recommender name) is in use; leave unset to use the cluster's default recommender
2882 ## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/docs/api.md#verticalpodautoscalerspec
2883 ## NOTE: specify only zero or one recommender as of VPA 1.7.1
2885 # -- Configures a startup resource boost for faster cold-start (application boot) resource allocation. NOTE: startupBoost is currently a GKE-specific extension to the VPA API and is only honored on GKE clusters; it is rendered only when set
2886 ## Ref: https://cloud.google.com/kubernetes-engine/docs/how-to/boost-application-startup
2891 # durationSeconds: 10
2892 ## Repo server image
2894 # -- Repository to use for the repo server
2895 # @default -- `""` (defaults to global.image.repository)
2897 # -- Tag to use for the repo server
2898 # @default -- `""` (defaults to global.image.tag)
2900 # -- Image pull policy for the repo server
2901 # @default -- `""` (defaults to global.image.imagePullPolicy)
2903 # -- Secrets with credentials to pull images from a private registry
2904 # @default -- `[]` (defaults to global.imagePullSecrets)
2905 imagePullSecrets: []
2906 # -- Additional command line arguments to pass to repo server
2908 # -- Environment variables to pass to repo server
2910 # -- envFrom to pass to repo server
2911 # @default -- `[]` (See [values.yaml])
2914 # name: config-map-name
2918 # -- Specify postStart and preStop lifecycle hooks for your argo-repo-server container
2920 # -- Additional containers to be added to the repo server pod
2921 ## Ref: https://argo-cd.readthedocs.io/en/stable/user-guide/config-management-plugins/
2922 ## Note: Supports use of custom Helm templates
2924 # - name: cmp-my-plugin
2926 # - "/var/run/argocd/argocd-cmp-server"
2929 # runAsNonRoot: true
2932 # - mountPath: /var/run/argocd
2934 # - mountPath: /home/argocd/cmp-server/plugins
2936 # # Remove this volumeMount if you've chosen to bake the config file into the sidecar image.
2937 # - mountPath: /home/argocd/cmp-server/config/plugin.yaml
2938 # subPath: my-plugin.yaml
2939 # name: argocd-cmp-cm
2940 # # Starting with v2.4, do NOT mount the same tmp volume as the repo-server container. The filesystem separation helps
2941 # # mitigate path traversal attacks.
2944 # - name: cmp-my-plugin2
2946 # - "/var/run/argocd/argocd-cmp-server"
2949 # runAsNonRoot: true
2952 # - mountPath: /var/run/argocd
2954 # # Remove this volumeMount if you've chosen to bake the config file into the sidecar image.
2955 # - mountPath: /home/argocd/cmp-server/plugins
2957 # - mountPath: /home/argocd/cmp-server/config/plugin.yaml
2958 # subPath: my-plugin2.yaml
2959 # name: argocd-cmp-cm
2960 # # Starting with v2.4, do NOT mount the same tmp volume as the repo-server container. The filesystem separation helps
2961 # # mitigate path traversal attacks.
2965 # -- Init containers to add to the repo server pods
2968 # -- Extra arguments for the cp command in the repo server copyutil initContainer
2969 # @default -- `"--update=none"`
2970 extraArgs: "--update=none"
2971 # -- Resource limits and requests for the repo server copyutil initContainer
2979 # -- Additional volumeMounts to the repo server main container
2981 # -- Additional volumes to the repo server pod
2983 # - name: argocd-cmp-cm
2985 # name: argocd-cmp-cm
2989 # -- Volumes to be used in replacement of emptydir on default volumes
2992 # persistentVolumeClaim:
2993 # claimName: pvc-argocd-repo-server-keyring
2995 # persistentVolumeClaim:
2996 # claimName: pvc-argocd-repo-server-workdir
2998 # persistentVolumeClaim:
2999 # claimName: pvc-argocd-repo-server-tmp
3001 # persistentVolumeClaim:
3002 # claimName: pvc-argocd-repo-server-varfiles
3004 # persistentVolumeClaim:
3005 # claimName: pvc-argocd-repo-server-plugins
3007 ## RepoServer emptyDir volumes
3009 # -- EmptyDir size limit for repo server
3010 # @default -- `""` (defaults not set if not specified i.e. no size limit)
3013 # -- Toggle the usage of a ephemeral Helm working directory
3014 useEphemeralHelmWorkingDir: true
3015 # -- Annotations to be added to repo server Deployment
3016 deploymentAnnotations: {}
3017 # -- Labels for the repo server Deployment
3018 deploymentLabels: {}
3019 # -- Annotations to be added to repo server pods
3021 # -- Labels to be added to repo server pods
3023 # -- Resource limits and requests for the repo server pods
3032 # Repo server container ports
3034 # -- Repo server container port
3036 # -- Metrics container port
3038 # -- Host Network for Repo server pods
3040 # -- [DNS configuration]
3042 # -- Alternative DNS policy for Repo server pods
3043 dnsPolicy: "ClusterFirst"
3044 # -- Repo server container-level security context
3045 # @default -- See [values.yaml]
3046 containerSecurityContext:
3048 readOnlyRootFilesystem: true
3049 allowPrivilegeEscalation: false
3051 type: RuntimeDefault
3055 ## Readiness and liveness probes for Repo Server
3056 ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
3058 # -- Enable Kubernetes readiness probe for Repo Server
3060 # -- Http path to use for the readiness probe
3062 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
3064 # -- Number of seconds after the container has started before [probe] is initiated
3065 initialDelaySeconds: 10
3066 # -- How often (in seconds) to perform the [probe]
3068 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
3070 # -- Number of seconds after which the [probe] times out
3073 # -- Enable Kubernetes liveness probe for Repo Server
3075 # -- Http path to use for the liveness probe
3076 httpPath: /healthz?full=true
3077 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
3079 # -- Number of seconds after the container has started before [probe] is initiated
3080 initialDelaySeconds: 10
3081 # -- How often (in seconds) to perform the [probe]
3083 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
3085 # -- Number of seconds after which the [probe] times out
3087 ## Startup probe for Repo Server (optional)
3088 ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
3090 # -- Enable Kubernetes startup probe for Repo Server
3092 # -- Http path to use for the startup probe
3094 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
3095 failureThreshold: 20
3096 # -- Number of seconds after the container has started before [probe] is initiated
3097 initialDelaySeconds: 10
3098 # -- How often (in seconds) to perform the [probe]
3100 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
3102 # -- Number of seconds after which the [probe] times out
3104 # -- terminationGracePeriodSeconds for container lifecycle hook
3105 terminationGracePeriodSeconds: 30
3106 # -- [Node selector]
3107 # @default -- `{}` (defaults to global.nodeSelector)
3109 # -- [Tolerations] for use with node taints
3110 # @default -- `[]` (defaults to global.tolerations)
3112 # -- Assign custom [affinity] rules to the deployment
3113 # @default -- `{}` (defaults to global.affinity preset)
3115 # -- Assign custom [TopologySpreadConstraints] rules to the repo server
3116 # @default -- `[]` (defaults to global.topologySpreadConstraints)
3117 ## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
3118 ## If labelSelector is left out, it will default to the labelSelector configuration of the deployment
3119 topologySpreadConstraints: []
3121 # topologyKey: topology.kubernetes.io/zone
3122 # whenUnsatisfiable: DoNotSchedule
3124 # -- Deployment strategy to be added to the repo server Deployment
3125 deploymentStrategy: {}
3126 # type: RollingUpdate
3129 # maxUnavailable: 25%
3131 # -- Priority class for the repo server pods
3132 # @default -- `""` (defaults to global.priorityClassName)
3133 priorityClassName: ""
3134 # TLS certificate configuration via Secret
3135 ## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/tls/#configuring-tls-to-argocd-repo-server
3136 ## Note: Issuing certificates via cert-manager in not supported right now because it's not possible to restart repo server automatically without extra controllers.
3138 # -- Create argocd-repo-server-tls secret
3140 # -- Annotations to be added to argocd-repo-server-tls secret
3142 # -- Labels to be added to argocd-repo-server-tls secret
3144 # -- Certificate authority. Required for self-signed certificates.
3146 # -- Certificate private key
3148 # -- Certificate data. Must contain SANs of Repo service (ie: argocd-repo-server, argocd-repo-server.argo-cd.svc)
3150 ## Repo server service configuration
3152 # -- Repo server service annotations
3154 # -- Repo server service labels
3156 # -- Repo server service port
3158 # -- Repo server service port name
3159 portName: tcp-repo-server
3160 # -- Traffic distribution preference for the repo server service. If the field is not set, the implementation will apply its default routing strategy.
3161 trafficDistribution: ""
3162 ## Repo server metrics service configuration
3164 # -- Deploy metrics service
3167 # -- Metrics service type
3169 # -- Metrics service clusterIP. `None` makes a "headless service" (no virtual IP)
3171 # -- Metrics service annotations
3173 # -- Metrics service labels
3175 # -- Metrics service port
3177 # -- Metrics service port name
3178 portName: http-metrics
3180 # -- Enable a prometheus ServiceMonitor
3182 # -- Prometheus ServiceMonitor interval
3184 # -- Prometheus ServiceMonitor scrapeTimeout. If empty, Prometheus uses the global scrape timeout unless it is less than the target's scrape interval value in which the latter is used.
3186 # -- When true, honorLabels preserves the metric’s labels when they collide with the target’s labels.
3188 # -- Prometheus [RelabelConfigs] to apply to samples before scraping
3190 # -- Prometheus [MetricRelabelConfigs] to apply to samples before ingestion
3191 metricRelabelings: []
3192 # -- Prometheus ServiceMonitor selector
3194 # prometheus: kube-prometheus
3196 # -- Prometheus ServiceMonitor scheme
3198 # -- Prometheus ServiceMonitor tlsConfig
3200 # -- Prometheus ServiceMonitor namespace
3201 namespace: "" # "monitoring"
3202 # -- Prometheus ServiceMonitor labels
3203 additionalLabels: {}
3204 # -- Prometheus ServiceMonitor annotations
3206 ## Enable Custom Rules for the Repo server's Cluster Role resource
3207 ## Enable this and set the rules: to whatever custom rules you want for the Cluster Role resource.
3210 # -- Enable custom rules for the Repo server's Cluster Role resource
3212 # -- List of custom rules for the Repo server's Cluster Role resource
3214 # -- Automount API credentials for the Service Account into the pod.
3215 automountServiceAccountToken: true
3216 ## Repo server service account
3217 ## If create is set to true, make sure to uncomment the name and update the rbac section below
3219 # -- Create repo server service account
3221 # -- Repo server service account name
3222 name: "" # "argocd-repo-server"
3223 # -- Annotations applied to created service account
3225 # -- Labels applied to created service account
3227 # -- Automount API credentials for the Service Account
3228 automountServiceAccountToken: true
3229 # -- Repo server rbac rules
3240 # Default repo server's network policy
3242 # -- Default network policy rules used by repo server
3243 # @default -- `false` (defaults to global.networkPolicy.create)
3245## ApplicationSet controller
3247 # -- ApplicationSet controller name string
3248 name: applicationset-controller
3249 # -- The number of ApplicationSet controller pods to run
3251 # -- Runtime class name for the ApplicationSet controller
3252 # @default -- `""` (defaults to global.runtimeClassName)
3253 runtimeClassName: ""
3254 ## ApplicationSet controller Pod Disruption Budget
3255 ## Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
3257 # -- Deploy a [PodDisruptionBudget] for the ApplicationSet controller
3259 # -- Labels to be added to ApplicationSet controller pdb
3261 # -- Annotations to be added to ApplicationSet controller pdb
3263 # -- Number of pods that are available after eviction as number or percentage (eg.: 50%)
3264 # @default -- `""` (defaults to 0 if not specified)
3266 # -- Number of pods that are unavailable after eviction as number or percentage (eg.: 50%).
3267 ## Has higher precedence over `applicationSet.pdb.minAvailable`
3269 # -- Policy for evicting unhealthy (not ready) pods, either `IfHealthyBudget` or `AlwaysAllow`
3270 ## Defaults to `IfHealthyBudget` if not set
3271 unhealthyPodEvictionPolicy: ""
3272 ## ApplicationSet controller Vertical Pod Autoscaler
3273 ## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/
3275 # -- Deploy a [VerticalPodAutoscaler](https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/) for the ApplicationSet controller
3277 # -- Labels to be added to ApplicationSet controller vpa
3279 # -- Annotations to be added to ApplicationSet controller vpa
3281 # -- One of the VPA operation modes
3282 ## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically
3283 ## Note: Recreate update mode requires more than one replica unless the min-replicas VPA controller flag is overridden
3285 # -- Controls how VPA computes the recommended resources for ApplicationSet controller container
3286 ## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/examples/hamster.yaml
3288 # controlledResources: ["cpu", "memory"]
3295 # -- The recommenders that will provide recommendations for vertical scaling. Only relevant if a named VPA recommender (e.g. one started with a custom recommender name) is in use; leave unset to use the cluster's default recommender
3296 ## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/docs/api.md#verticalpodautoscalerspec
3297 ## NOTE: specify only zero or one recommender as of VPA 1.7.1
3299 # -- Configures a startup resource boost for faster cold-start (application boot) resource allocation. NOTE: startupBoost is currently a GKE-specific extension to the VPA API and is only honored on GKE clusters; it is rendered only when set
3300 ## Ref: https://cloud.google.com/kubernetes-engine/docs/how-to/boost-application-startup
3305 # durationSeconds: 10
3306 ## ApplicationSet controller image
3308 # -- Repository to use for the ApplicationSet controller
3309 # @default -- `""` (defaults to global.image.repository)
3311 # -- Tag to use for the ApplicationSet controller
3312 # @default -- `""` (defaults to global.image.tag)
3314 # -- Image pull policy for the ApplicationSet controller
3315 # @default -- `""` (defaults to global.image.imagePullPolicy)
3317 # -- If defined, uses a Secret to pull an image from a private Docker registry or repository.
3318 # @default -- `[]` (defaults to global.imagePullSecrets)
3319 imagePullSecrets: []
3320 # -- ApplicationSet controller command line flags
3322 # -- Environment variables to pass to the ApplicationSet controller
3327 # -- envFrom to pass to the ApplicationSet controller
3328 # @default -- `[]` (See [values.yaml])
3331 # name: config-map-name
3335 # -- Additional containers to be added to the ApplicationSet controller pod
3336 ## Note: Supports use of custom Helm templates
3338 # -- Init containers to add to the ApplicationSet controller pod
3339 ## Note: Supports use of custom Helm templates
3341 # -- List of extra mounts to add (normally used with extraVolumes)
3342 extraVolumeMounts: []
3343 # -- List of extra volumes to add
3345 ## ApplicationSet controller emptyDir volumes
3347 # -- EmptyDir size limit for applicationSet controller
3348 # @default -- `""` (defaults not set if not specified i.e. no size limit)
3351 ## Metrics service configuration
3353 # -- Deploy metrics service
3356 # -- Metrics service type
3358 # -- Metrics service clusterIP. `None` makes a "headless service" (no virtual IP)
3360 # -- Metrics service annotations
3362 # -- Metrics service labels
3364 # -- Metrics service port
3366 # -- Metrics service port name
3367 portName: http-metrics
3369 # -- Enable a prometheus ServiceMonitor
3371 # -- Prometheus ServiceMonitor interval
3373 # -- Prometheus ServiceMonitor scrapeTimeout. If empty, Prometheus uses the global scrape timeout unless it is less than the target's scrape interval value in which the latter is used.
3375 # -- When true, honorLabels preserves the metric’s labels when they collide with the target’s labels.
3377 # -- Prometheus [RelabelConfigs] to apply to samples before scraping
3379 # -- Prometheus [MetricRelabelConfigs] to apply to samples before ingestion
3380 metricRelabelings: []
3381 # -- Prometheus ServiceMonitor selector
3383 # prometheus: kube-prometheus
3385 # -- Prometheus ServiceMonitor scheme
3387 # -- Prometheus ServiceMonitor tlsConfig
3389 # -- Prometheus ServiceMonitor namespace
3390 namespace: "" # monitoring
3391 # -- Prometheus ServiceMonitor labels
3392 additionalLabels: {}
3393 # -- Prometheus ServiceMonitor annotations
3395 ## ApplicationSet service configuration
3397 # -- ApplicationSet service annotations
3399 # -- ApplicationSet service labels
3401 # -- ApplicationSet service type
3403 # -- ApplicationSet service port
3405 # -- ApplicationSet service port name
3406 portName: http-webhook
3407 # -- Automount API credentials for the Service Account into the pod.
3408 automountServiceAccountToken: true
3410 # -- Create ApplicationSet controller service account
3412 # -- ApplicationSet controller service account name
3413 name: argocd-applicationset-controller
3414 # -- Annotations applied to created service account
3416 # -- Labels applied to created service account
3418 # -- Automount API credentials for the Service Account
3419 automountServiceAccountToken: true
3420 # -- Annotations to be added to ApplicationSet controller Deployment
3421 deploymentAnnotations: {}
3422 # -- Labels for the ApplicationSet controller Deployment
3423 deploymentLabels: {}
3424 # -- Annotations for the ApplicationSet controller pods
3426 # -- Labels for the ApplicationSet controller pods
3428 # -- Resource limits and requests for the ApplicationSet controller pods.
3437 # ApplicationSet controller container ports
3439 # -- Metrics container port
3441 # -- Probe container port
3443 # -- Webhook container port
3445 # -- [DNS configuration]
3447 # -- Alternative DNS policy for ApplicationSet controller pods
3448 dnsPolicy: "ClusterFirst"
3449 # -- ApplicationSet controller container-level security context
3450 # @default -- See [values.yaml]
3451 containerSecurityContext:
3453 readOnlyRootFilesystem: true
3454 allowPrivilegeEscalation: false
3456 type: RuntimeDefault
3460 ## Probes for ApplicationSet controller (optional)
3461 ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
3463 # -- Enable Kubernetes liveness probe for ApplicationSet controller
3465 # -- Number of seconds after the container has started before [probe] is initiated
3466 initialDelaySeconds: 10
3467 # -- How often (in seconds) to perform the [probe]
3469 # -- Number of seconds after which the [probe] times out
3471 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
3473 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
3476 # -- Enable Kubernetes liveness probe for ApplicationSet controller
3478 # -- Number of seconds after the container has started before [probe] is initiated
3479 initialDelaySeconds: 10
3480 # -- How often (in seconds) to perform the [probe]
3482 # -- Number of seconds after which the [probe] times out
3484 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
3486 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
3488 ## Startup probe for ApplicationSet controller (optional)
3489 ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
3491 # -- Enable Kubernetes startup probe for ApplicationSet controller
3493 # -- Number of seconds after the container has started before [probe] is initiated
3494 initialDelaySeconds: 10
3495 # -- How often (in seconds) to perform the [probe]
3497 # -- Number of seconds after which the [probe] times out
3499 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
3501 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
3502 failureThreshold: 20
3503 # -- terminationGracePeriodSeconds for container lifecycle hook
3504 terminationGracePeriodSeconds: 30
3505 # -- [Node selector]
3506 # @default -- `{}` (defaults to global.nodeSelector)
3508 # -- [Tolerations] for use with node taints
3509 # @default -- `[]` (defaults to global.tolerations)
3511 # -- Assign custom [affinity] rules
3512 # @default -- `{}` (defaults to global.affinity preset)
3514 # -- Assign custom [TopologySpreadConstraints] rules to the ApplicationSet controller
3515 # @default -- `[]` (defaults to global.topologySpreadConstraints)
3516 ## Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
3517 ## If labelSelector is left out, it will default to the labelSelector configuration of the deployment
3518 topologySpreadConstraints: []
3520 # topologyKey: topology.kubernetes.io/zone
3521 # whenUnsatisfiable: DoNotSchedule
3523 # -- Deployment strategy to be added to the ApplicationSet controller Deployment
3524 deploymentStrategy: {}
3525 # type: RollingUpdate
3528 # maxUnavailable: 25%
3530 # -- Priority class for the ApplicationSet controller pods
3531 # @default -- `""` (defaults to global.priorityClassName)
3532 priorityClassName: ""
3533 # TLS certificate configuration via cert-manager
3534 ## Ref: https://argo-cd.readthedocs.io/en/stable/operator-manual/tls/#tls-configuration
3536 # -- Deploy a Certificate resource (requires cert-manager)
3538 # -- Certificate primary domain (commonName)
3539 # @default -- `""` (defaults to global.domain)
3541 # -- Certificate Subject Alternate Names (SANs)
3543 # -- The requested 'duration' (i.e. lifetime) of the certificate.
3544 # @default -- `""` (defaults to 2160h = 90d if not specified)
3545 ## Ref: https://cert-manager.io/docs/usage/certificate/#renewal
3547 # -- How long before the expiry a certificate should be renewed.
3548 # @default -- `""` (defaults to 360h = 15d if not specified)
3549 ## Ref: https://cert-manager.io/docs/usage/certificate/#renewal
3551 # Certificate issuer
3552 ## Ref: https://cert-manager.io/docs/concepts/issuer
3554 # -- Certificate issuer group. Set if using an external issuer. Eg. `cert-manager.io`
3556 # -- Certificate issuer kind. Either `Issuer` or `ClusterIssuer`
3558 # -- Certificate issuer name. Eg. `letsencrypt`
3560 # Private key of the certificate
3562 # -- Rotation policy of private key when certificate is re-issued. Either: `Never` or `Always`
3563 rotationPolicy: Never
3564 # -- The private key cryptography standards (PKCS) encoding for private key. Either: `PCKS1` or `PKCS8`
3566 # -- Algorithm used to generate certificate private key. One of: `RSA`, `Ed25519` or `ECDSA`
3568 # -- Key bit size of the private key. If algorithm is set to `Ed25519`, size is ignored.
3570 # -- Annotations to be applied to the ApplicationSet Certificate
3572 ## Ingress for the Git Generator webhook
3573 ## Ref: https://argocd-applicationset.readthedocs.io/en/master/Generators-Git/#webhook-configuration)
3575 # -- Enable an ingress resource for ApplicationSet webhook
3577 # -- Additional ingress labels
3579 # -- Additional ingress annotations
3581 # -- Defines which ingress ApplicationSet controller will implement the resource
3582 ingressClassName: ""
3583 # -- Argo CD ApplicationSet hostname
3584 # @default -- `""` (defaults to global.domain)
3586 # -- List of ingress paths
3588 # -- Ingress path type. One of `Exact`, `Prefix` or `ImplementationSpecific`
3590 # -- Enable TLS configuration for the hostname defined at `applicationSet.webhook.ingress.hostname`
3591 ## TLS certificate will be retrieved from a TLS secret with name:`argocd-applicationset-controller-tls`
3593 # -- The list of additional hostnames to be covered by ingress record
3594 # @default -- `[]` (See [values.yaml])
3596 # - name: argocd.example.com
3599 # -- Additional ingress paths
3600 # @default -- `[]` (See [values.yaml])
3606 # name: ssl-redirect
3608 # name: use-annotation
3610 # -- Additional ingress rules
3611 # @default -- `[]` (See [values.yaml])
3612 ## Note: Supports use of custom Helm templates
3616 # - path: /api/webhook
3620 # name: '{{ include "argo-cd.applicationSet.fullname" . }}'
3622 # name: '{{ .Values.applicationSet.service.portName }}'
3624 # -- Additional ingress TLS configuration
3625 # @default -- `[]` (See [values.yaml])
3627 # - secretName: argocd-applicationset-tls
3629 # - argocd-applicationset.example.com
3630 ## Gateway API HTTPRoute for the Git Generator webhook
3631 ## Ref: https://argocd-applicationset.readthedocs.io/en/master/Generators-Git/#webhook-configuration)
3632 # NOTE: Gateway API support is in EXPERIMENTAL status
3633 # Support depends on your Gateway controller implementation
3634 # Some controllers may require additional configuration (e.g., BackendTLSPolicy for HTTPS backends)
3635 # Refer to https://gateway-api.sigs.k8s.io/implementations/ for controller-specific details
3637 # -- Enable HTTPRoute resource for Argo CD Applicationset Webhook (Gateway API)
3639 # -- Additional HTTPRoute labels
3641 # -- Additional HTTPRoute annotations
3643 # -- Gateway API parentRefs for the HTTPRoute
3644 ## Must reference an existing Gateway
3645 # @default -- `[]` (See [values.yaml])
3647 # - name: example-gateway
3648 # namespace: example-gateway-namespace
3649 # sectionName: https
3650 # -- List of hostnames for the HTTPRoute
3651 # @default -- `[]` (See [values.yaml])
3653 # - argocd.example.com
3654 # -- HTTPRoute rules configuration
3655 # @default -- `[]` (See [values.yaml])
3662 # - type: RequestHeaderModifier
3663 # requestHeaderModifier:
3665 # - name: X-Custom-Header
3666 # value: custom-value
3667 # Gateway API ListenerSet configuration for the Git Generator webhook
3668 ## Ref: https://argocd-applicationset.readthedocs.io/en/master/Generators-Git/#webhook-configuration
3669 # NOTE: Gateway API support is in EXPERIMENTAL status
3670 # ListenerSet allows attaching additional listeners to an existing Gateway
3671 # Requires Gateway API v1alpha2 and a controller that supports ListenerSet
3672 # Refer to https://gateway-api.sigs.k8s.io/reference/spec/#gateway.networking.k8s.io/v1alpha2.ListenerSet
3674 # -- Enable ListenerSet resource for Argo CD ApplicationSet webhook (Gateway API)
3676 # -- Additional ListenerSet labels
3678 # -- Additional ListenerSet annotations
3680 # -- Gateway API parentRef for the ListenerSet
3681 ## Must reference an existing Gateway. Unlike HTTPRoute, ListenerSet accepts exactly one parentRef.
3682 # @default -- `{}` (See [values.yaml])
3684 # name: example-gateway
3685 # namespace: example-gateway-namespace
3686 # -- Hostname for the synthesized listener. Defaults to global.domain when empty.
3688 # -- Name of the synthesized listener. Also used as sectionName in auto-derived httproute parentRefs.
3690 # -- Port for the synthesized listener
3692 # -- Protocol for the synthesized listener
3694 # -- TLS configuration for the synthesized listener
3696 # -- Enable TLS on the synthesized listener
3698 # -- TLS termination mode
3700 # -- Secret name for TLS certificate. Defaults to `argocd-applicationset-controller-tls` when empty.
3702 # -- allowedRoutes for the synthesized listener
3706 # -- Listeners to attach to the parent Gateway. When non-empty, used verbatim and all synthesized listener fields above are ignored.
3707 # @default -- `[]` (See [values.yaml])
3712 # hostname: argocd.example.com
3718 # name: argocd-applicationset-controller-tls
3722 # -- Enable ApplicationSet in any namespace feature
3723 allowAnyNamespace: false
3724 # Default ApplicationSet controller's network policy
3726 # -- Default network policy rules used by ApplicationSet controller
3727 # @default -- `false` (defaults to global.networkPolicy.create)
3729## Notifications controller
3731 # -- Enable notifications controller
3733 # -- Notifications controller name string
3734 name: notifications-controller
3735 # -- Argo CD dashboard url; used in place of {{.context.argocdUrl}} in templates
3736 # @default -- `""` (defaults to https://`global.domain`)
3738 # -- Runtime class name for the notifications controller
3739 # @default -- `""` (defaults to global.runtimeClassName)
3740 runtimeClassName: ""
3741 ## Notifications controller Pod Disruption Budget
3742 ## Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
3744 # -- Deploy a [PodDisruptionBudget] for the notifications controller
3746 # -- Labels to be added to notifications controller pdb
3748 # -- Annotations to be added to notifications controller pdb
3750 # -- Number of pods that are available after eviction as number or percentage (eg.: 50%)
3751 # @default -- `""` (defaults to 0 if not specified)
3753 # -- Number of pods that are unavailable after eviction as number or percentage (eg.: 50%).
3754 ## Has higher precedence over `notifications.pdb.minAvailable`
3756 # -- Policy for evicting unhealthy (not ready) pods, either `IfHealthyBudget` or `AlwaysAllow`
3757 ## Defaults to `IfHealthyBudget` if not set
3758 unhealthyPodEvictionPolicy: ""
3759 ## Notifications controller Vertical Pod Autoscaler
3760 ## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/
3762 # -- Deploy a [VerticalPodAutoscaler](https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/) for the notifications controller
3764 # -- Labels to be added to notifications controller vpa
3766 # -- Annotations to be added to notifications controller vpa
3768 # -- One of the VPA operation modes
3769 ## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically
3770 ## Note: Recreate update mode requires more than one replica unless the min-replicas VPA controller flag is overridden
3772 # -- Controls how VPA computes the recommended resources for notifications controller container
3773 ## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/examples/hamster.yaml
3775 # controlledResources: ["cpu", "memory"]
3782 # -- The recommenders that will provide recommendations for vertical scaling. Only relevant if a named VPA recommender (e.g. one started with a custom recommender name) is in use; leave unset to use the cluster's default recommender
3783 ## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/docs/api.md#verticalpodautoscalerspec
3784 ## NOTE: specify only zero or one recommender as of VPA 1.7.1
3786 # -- Configures a startup resource boost for faster cold-start (application boot) resource allocation. NOTE: startupBoost is currently a GKE-specific extension to the VPA API and is only honored on GKE clusters; it is rendered only when set
3787 ## Ref: https://cloud.google.com/kubernetes-engine/docs/how-to/boost-application-startup
3792 # durationSeconds: 10
3793 ## Notifications controller image
3795 # -- Repository to use for the notifications controller
3796 # @default -- `""` (defaults to global.image.repository)
3798 # -- Tag to use for the notifications controller
3799 # @default -- `""` (defaults to global.image.tag)
3801 # -- Image pull policy for the notifications controller
3802 # @default -- `""` (defaults to global.image.imagePullPolicy)
3804 # -- Secrets with credentials to pull images from a private registry
3805 # @default -- `[]` (defaults to global.imagePullSecrets)
3806 imagePullSecrets: []
3807 # DEPRECATED - Use configs.params to override
3808 # -- Notifications controller log format. Either `text` or `json`
3809 # @default -- `""` (defaults to global.logging.format)
3811 # -- Notifications controller log level. One of: `debug`, `info`, `warn`, `error`
3812 # @default -- `""` (defaults to global.logging.level)
3815 # -- Extra arguments to provide to the notifications controller
3817 # -- Additional container environment variables
3819 # -- envFrom to pass to the notifications controller
3820 # @default -- `[]` (See [values.yaml])
3823 # name: config-map-name
3827 # -- Additional containers to be added to the notifications controller pod
3828 ## Note: Supports use of custom Helm templates
3830 # -- Init containers to add to the notifications controller pod
3831 ## Note: Supports use of custom Helm templates
3833 # -- List of extra mounts to add (normally used with extraVolumes)
3834 extraVolumeMounts: []
3835 # -- List of extra volumes to add
3837 # -- Define user-defined context
3838 ## For more information: https://argo-cd.readthedocs.io/en/stable/operator-manual/notifications/templates/#defining-user-defined-context
3841 # environmentName: staging
3844 # -- Whether helm chart creates notifications controller secret
3845 ## If true, will create a secret with the name below. Otherwise, will assume existence of a secret with that name.
3847 # -- notifications controller Secret name
3848 name: "argocd-notifications-secret"
3849 # -- key:value pairs of annotations to be added to the secret
3851 # -- key:value pairs of labels to be added to the secret
3853 # -- Generic key:value pairs to be inserted into the secret
3854 ## Can be used for templates, notification services etc. Some examples given below.
3855 ## For more information: https://argo-cd.readthedocs.io/en/stable/operator-manual/notifications/services/overview/
3858 # # For more information: https://argo-cd.readthedocs.io/en/stable/operator-manual/notifications/services/slack/
3860 # # For more information: https://argo-cd.readthedocs.io/en/stable/operator-manual/notifications/services/grafana/
3862 # webhooks-github-token:
3866 # For more information: https://argo-cd.readthedocs.io/en/stable/operator-manual/notifications/services/email/
3869 # -- Enables prometheus metrics server
3874 # -- Metrics service type
3876 # -- Metrics service clusterIP. `None` makes a "headless service" (no virtual IP)
3878 # -- Metrics service annotations
3880 # -- Metrics service labels
3882 # -- Metrics service port name
3883 portName: http-metrics
3885 # -- Enable a prometheus ServiceMonitor
3887 # -- Prometheus ServiceMonitor selector
3889 # prometheus: kube-prometheus
3890 # -- Prometheus ServiceMonitor labels
3891 additionalLabels: {}
3892 # -- Prometheus ServiceMonitor annotations
3894 # namespace: monitoring
3896 # scrapeTimeout: 10s
3897 # -- Prometheus ServiceMonitor scheme
3899 # -- Prometheus ServiceMonitor tlsConfig
3901 # -- When true, honorLabels preserves the metric’s labels when they collide with the target’s labels.
3903 # -- Prometheus [RelabelConfigs] to apply to samples before scraping
3905 # -- Prometheus [MetricRelabelConfigs] to apply to samples before ingestion
3906 metricRelabelings: []
3907 # -- Configures notification services such as slack, email or custom webhook
3908 # @default -- See [values.yaml]
3909 ## For more information: https://argo-cd.readthedocs.io/en/stable/operator-manual/notifications/services/overview/
3912 # token: $slack-token
3914 # -- Annotations to be applied to the notifications controller Deployment
3915 deploymentAnnotations: {}
3916 # -- Labels for the notifications controller Deployment
3917 deploymentLabels: {}
3918 # -- Annotations to be applied to the notifications controller Pods
3920 # -- Labels to be applied to the notifications controller Pods
3922 # -- Resource limits and requests for the notifications controller
3931 # Notification controller container ports
3933 # -- Metrics container port
3935 # -- [DNS configuration]
3937 # -- Alternative DNS policy for notifications controller Pods
3938 dnsPolicy: "ClusterFirst"
3939 # -- Notification controller container-level security Context
3940 # @default -- See [values.yaml]
3941 containerSecurityContext:
3943 readOnlyRootFilesystem: true
3944 allowPrivilegeEscalation: false
3946 type: RuntimeDefault
3950 ## Probes for notifications controller Pods (optional)
3951 ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
3953 # -- Enable Kubernetes liveness probe for notifications controller Pods
3955 # -- Number of seconds after the container has started before [probe] is initiated
3956 initialDelaySeconds: 10
3957 # -- How often (in seconds) to perform the [probe]
3959 # -- Number of seconds after which the [probe] times out
3961 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
3963 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
3966 # -- Enable Kubernetes liveness probe for notifications controller Pods
3968 # -- Number of seconds after the container has started before [probe] is initiated
3969 initialDelaySeconds: 10
3970 # -- How often (in seconds) to perform the [probe]
3972 # -- Number of seconds after which the [probe] times out
3974 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
3976 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
3978 ## Startup probe for notifications controller Pods (optional)
3979 ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
3981 # -- Enable Kubernetes startup probe for notifications controller Pods
3983 # -- Number of seconds after the container has started before [probe] is initiated
3984 initialDelaySeconds: 10
3985 # -- How often (in seconds) to perform the [probe]
3987 # -- Number of seconds after which the [probe] times out
3989 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
3991 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
3992 failureThreshold: 20
3993 # -- terminationGracePeriodSeconds for container lifecycle hook
3994 terminationGracePeriodSeconds: 30
3995 # -- [Node selector]
3996 # @default -- `{}` (defaults to global.nodeSelector)
3998 # -- [Tolerations] for use with node taints
3999 # @default -- `[]` (defaults to global.tolerations)
4001 # -- Assign custom [affinity] rules
4002 # @default -- `{}` (defaults to global.affinity preset)
4004 # -- Assign custom [TopologySpreadConstraints] rules to the application controller
4005 # @default -- `[]` (defaults to global.topologySpreadConstraints)
4006 ## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
4007 ## If labelSelector is left out, it will default to the labelSelector configuration of the deployment
4008 topologySpreadConstraints: []
4010 # topologyKey: topology.kubernetes.io/zone
4011 # whenUnsatisfiable: DoNotSchedule
4013 # -- Deployment strategy to be added to the notifications controller Deployment
4016 # -- Priority class for the notifications controller pods
4017 # @default -- `""` (defaults to global.priorityClassName)
4018 priorityClassName: ""
4019 # -- Automount API credentials for the Service Account into the pod.
4020 automountServiceAccountToken: true
4022 # -- Create notifications controller service account
4024 # -- Notification controller service account name
4025 name: argocd-notifications-controller
4026 # -- Annotations applied to created service account
4028 # -- Labels applied to created service account
4030 # -- Automount API credentials for the Service Account
4031 automountServiceAccountToken: true
4033 # -- Whether helm chart creates notifications controller config map
4035 ## Enable this and set the rules: to whatever custom rules you want for the Cluster Role resource.
4038 # -- List of custom rules for the notifications controller's ClusterRole resource
4040 # -- Contains centrally managed global application subscriptions
4041 ## For more information: https://argo-cd.readthedocs.io/en/stable/operator-manual/notifications/subscriptions/
4043 # # subscription for on-sync-status-unknown trigger notifications
4046 # - email:test@gmail.com
4048 # - on-sync-status-unknown
4049 # # subscription restricted to applications with matching labels only
4052 # selector: test=true
4054 # - on-sync-status-unknown
4056 # -- The notification template is used to generate the notification content
4057 ## For more information: https://argo-cd.readthedocs.io/en/stable/operator-manual/notifications/templates/
4059 # template.app-deployed: |
4061 # subject: New version of an application {{.app.metadata.name}} is up and running.
4063 # {{if eq .serviceType "slack"}}:white_check_mark:{{end}} Application {{.app.metadata.name}} is now running new version of deployments manifests.
4067 # "title": "{{ .app.metadata.name}}",
4068 # "title_link":"{{.context.argocdUrl}}/applications/{{.app.metadata.name}}",
4069 # "color": "#18be52",
4072 # "title": "Sync Status",
4073 # "value": "{{.app.status.sync.status}}",
4077 # "title": "Repository",
4078 # "value": "{{.app.spec.source.repoURL}}",
4082 # "title": "Revision",
4083 # "value": "{{.app.status.sync.revision}}",
4086 # {{range $index, $c := .app.status.conditions}}
4087 # {{if not $index}},{{end}}
4088 # {{if $index}},{{end}}
4090 # "title": "{{$c.type}}",
4091 # "value": "{{$c.message}}",
4097 # template.app-health-degraded: |
4099 # subject: Application {{.app.metadata.name}} has degraded.
4101 # {{if eq .serviceType "slack"}}:exclamation:{{end}} Application {{.app.metadata.name}} has degraded.
4102 # Application details: {{.context.argocdUrl}}/applications/{{.app.metadata.name}}.
4106 # "title": "{{ .app.metadata.name}}",
4107 # "title_link": "{{.context.argocdUrl}}/applications/{{.app.metadata.name}}",
4108 # "color": "#f4c030",
4111 # "title": "Sync Status",
4112 # "value": "{{.app.status.sync.status}}",
4116 # "title": "Repository",
4117 # "value": "{{.app.spec.source.repoURL}}",
4120 # {{range $index, $c := .app.status.conditions}}
4121 # {{if not $index}},{{end}}
4122 # {{if $index}},{{end}}
4124 # "title": "{{$c.type}}",
4125 # "value": "{{$c.message}}",
4131 # template.app-sync-failed: |
4133 # subject: Failed to sync application {{.app.metadata.name}}.
4135 # {{if eq .serviceType "slack"}}:exclamation:{{end}} The sync operation of application {{.app.metadata.name}} has failed at {{.app.status.operationState.finishedAt}} with the following error: {{.app.status.operationState.message}}
4136 # Sync operation details are available at: {{.context.argocdUrl}}/applications/{{.app.metadata.name}}?operation=true .
4140 # "title": "{{ .app.metadata.name}}",
4141 # "title_link":"{{.context.argocdUrl}}/applications/{{.app.metadata.name}}",
4142 # "color": "#E96D76",
4145 # "title": "Sync Status",
4146 # "value": "{{.app.status.sync.status}}",
4150 # "title": "Repository",
4151 # "value": "{{.app.spec.source.repoURL}}",
4154 # {{range $index, $c := .app.status.conditions}}
4155 # {{if not $index}},{{end}}
4156 # {{if $index}},{{end}}
4158 # "title": "{{$c.type}}",
4159 # "value": "{{$c.message}}",
4165 # template.app-sync-running: |
4167 # subject: Start syncing application {{.app.metadata.name}}.
4169 # The sync operation of application {{.app.metadata.name}} has started at {{.app.status.operationState.startedAt}}.
4170 # Sync operation details are available at: {{.context.argocdUrl}}/applications/{{.app.metadata.name}}?operation=true .
4174 # "title": "{{ .app.metadata.name}}",
4175 # "title_link":"{{.context.argocdUrl}}/applications/{{.app.metadata.name}}",
4176 # "color": "#0DADEA",
4179 # "title": "Sync Status",
4180 # "value": "{{.app.status.sync.status}}",
4184 # "title": "Repository",
4185 # "value": "{{.app.spec.source.repoURL}}",
4188 # {{range $index, $c := .app.status.conditions}}
4189 # {{if not $index}},{{end}}
4190 # {{if $index}},{{end}}
4192 # "title": "{{$c.type}}",
4193 # "value": "{{$c.message}}",
4199 # template.app-sync-status-unknown: |
4201 # subject: Application {{.app.metadata.name}} sync status is 'Unknown'
4203 # {{if eq .serviceType "slack"}}:exclamation:{{end}} Application {{.app.metadata.name}} sync is 'Unknown'.
4204 # Application details: {{.context.argocdUrl}}/applications/{{.app.metadata.name}}.
4205 # {{if ne .serviceType "slack"}}
4206 # {{range $c := .app.status.conditions}}
4213 # "title": "{{ .app.metadata.name}}",
4214 # "title_link":"{{.context.argocdUrl}}/applications/{{.app.metadata.name}}",
4215 # "color": "#E96D76",
4218 # "title": "Sync Status",
4219 # "value": "{{.app.status.sync.status}}",
4223 # "title": "Repository",
4224 # "value": "{{.app.spec.source.repoURL}}",
4227 # {{range $index, $c := .app.status.conditions}}
4228 # {{if not $index}},{{end}}
4229 # {{if $index}},{{end}}
4231 # "title": "{{$c.type}}",
4232 # "value": "{{$c.message}}",
4238 # template.app-sync-succeeded: |
4240 # subject: Application {{.app.metadata.name}} has been successfully synced.
4242 # {{if eq .serviceType "slack"}}:white_check_mark:{{end}} Application {{.app.metadata.name}} has been successfully synced at {{.app.status.operationState.finishedAt}}.
4243 # Sync operation details are available at: {{.context.argocdUrl}}/applications/{{.app.metadata.name}}?operation=true .
4247 # "title": "{{ .app.metadata.name}}",
4248 # "title_link":"{{.context.argocdUrl}}/applications/{{.app.metadata.name}}",
4249 # "color": "#18be52",
4252 # "title": "Sync Status",
4253 # "value": "{{.app.status.sync.status}}",
4257 # "title": "Repository",
4258 # "value": "{{.app.spec.source.repoURL}}",
4261 # {{range $index, $c := .app.status.conditions}}
4262 # {{if not $index}},{{end}}
4263 # {{if $index}},{{end}}
4265 # "title": "{{$c.type}}",
4266 # "value": "{{$c.message}}",
4273 # -- The trigger defines the condition when the notification should be sent
4274 ## For more information: https://argo-cd.readthedocs.io/en/stable/operator-manual/notifications/triggers/
4276 # trigger.on-deployed: |
4277 # - description: Application is synced and healthy. Triggered once per commit.
4278 # oncePer: app.status.sync.revision
4281 # when: app.status.operationState.phase in ['Succeeded'] and app.status.health.status == 'Healthy'
4282 # trigger.on-health-degraded: |
4283 # - description: Application has degraded
4285 # - app-health-degraded
4286 # when: app.status.health.status == 'Degraded'
4287 # trigger.on-sync-failed: |
4288 # - description: Application syncing has failed
4291 # when: app.status.operationState.phase in ['Error', 'Failed']
4292 # trigger.on-sync-running: |
4293 # - description: Application is being synced
4295 # - app-sync-running
4296 # when: app.status.operationState.phase in ['Running']
4297 # trigger.on-sync-status-unknown: |
4298 # - description: Application status is 'Unknown'
4300 # - app-sync-status-unknown
4301 # when: app.status.sync.status == 'Unknown'
4302 # trigger.on-sync-succeeded: |
4303 # - description: Application syncing has succeeded
4305 # - app-sync-succeeded
4306 # when: app.status.operationState.phase in ['Succeeded']
4308 # For more information: https://argo-cd.readthedocs.io/en/stable/operator-manual/notifications/triggers/#default-triggers
4309 # defaultTriggers: |
4310 # - on-sync-status-unknown
4312 # Default notifications controller's network policy
4314 # -- Default network policy rules used by notifications controller
4315 # @default -- `false` (defaults to global.networkPolicy.create)
4318 # -- Enable commit server
4320 # -- Commit server name
4322 # -- Runtime class name for the commit server
4323 # @default -- `""` (defaults to global.runtimeClassName)
4324 runtimeClassName: ""
4325 ## commit server controller image
4327 # -- Repository to use for the commit server
4328 # @default -- `""` (defaults to global.image.repository)
4330 # -- Tag to use for the commit server
4331 # @default -- `""` (defaults to global.image.tag)
4333 # -- Image pull policy for the commit server
4334 # @default -- `""` (defaults to global.image.imagePullPolicy)
4336 # -- commit server command line flags
4338 # -- Environment variables to pass to the commit server
4343 # -- envFrom to pass to the commit server
4344 # @default -- `[]` (See [values.yaml])
4347 # name: config-map-name
4351 # -- List of extra mounts to add (normally used with extraVolumes)
4352 extraVolumeMounts: []
4353 # -- List of extra volumes to add
4356 # -- Enables prometheus metrics server
4359 # -- Metrics service type
4361 # -- Metrics service clusterIP. `None` makes a "headless service" (no virtual IP)
4363 # -- Metrics service annotations
4365 # -- Metrics service labels
4367 # -- Metrics service port
4369 # -- Metrics service port name
4371 ## commit server service configuration
4373 # -- commit server service annotations
4375 # -- commit server service labels
4377 # -- commit server service port
4379 # -- commit server service port name
4381 # -- Automount API credentials for the Service Account into the pod.
4382 automountServiceAccountToken: false
4384 # -- Create commit server service account
4386 # -- commit server service account name
4387 name: argocd-commit-server
4388 # -- Annotations applied to created service account
4390 # -- Labels applied to created service account
4392 # -- Automount API credentials for the Service Account
4393 automountServiceAccountToken: true
4394 # -- Annotations to be added to commit server Deployment
4395 deploymentAnnotations: {}
4396 # -- Labels for the commit server Deployment
4397 deploymentLabels: {}
4398 # -- Annotations for the commit server pods
4400 # -- Labels for the commit server pods
4402 # -- Resource limits and requests for the commit server pods.
4411 # -- [DNS configuration]
4413 # -- Alternative DNS policy for commit server pods
4414 dnsPolicy: "ClusterFirst"
4415 # -- commit server container-level security context
4416 # @default -- See [values.yaml]
4417 containerSecurityContext:
4419 readOnlyRootFilesystem: true
4420 allowPrivilegeEscalation: false
4425 type: RuntimeDefault
4426 ## Probes for commit server (optional)
4427 ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
4429 # -- Enable Kubernetes liveness probe for commit server
4431 # -- Http path to use for the readiness probe
4433 # -- Number of seconds after the container has started before [probe] is initiated
4434 initialDelaySeconds: 5
4435 # -- How often (in seconds) to perform the [probe]
4437 # -- Number of seconds after which the [probe] times out
4439 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
4442 # -- Enable Kubernetes liveness probe for commit server
4444 # -- Http path to use for the liveness probe
4445 httpPath: /healthz?full=true
4446 # -- Number of seconds after the container has started before [probe] is initiated
4447 initialDelaySeconds: 30
4448 # -- How often (in seconds) to perform the [probe]
4450 # -- Number of seconds after which the [probe] times out
4452 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
4454 ## Startup probe for commit server (optional)
4455 ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
4457 # -- Enable Kubernetes startup probe for commit server
4459 # -- Http path to use for the startup probe
4461 # -- Number of seconds after the container has started before [probe] is initiated
4462 initialDelaySeconds: 10
4463 # -- How often (in seconds) to perform the [probe]
4465 # -- Number of seconds after which the [probe] times out
4467 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
4468 failureThreshold: 20
4469 # -- terminationGracePeriodSeconds for container lifecycle hook
4470 terminationGracePeriodSeconds: 30
4471 # -- [Node selector]
4472 # @default -- `{}` (defaults to global.nodeSelector)
4474 # -- [Tolerations] for use with node taints
4475 # @default -- `[]` (defaults to global.tolerations)
4477 # -- Assign custom [affinity] rules
4478 # @default -- `{}` (defaults to global.affinity preset)
4480 # -- Assign custom [TopologySpreadConstraints] rules to the commit server
4481 # @default -- `[]` (defaults to global.topologySpreadConstraints)
4482 ## Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
4483 ## If labelSelector is left out, it will default to the labelSelector configuration of the deployment
4484 topologySpreadConstraints: []
4486 # topologyKey: topology.kubernetes.io/zone
4487 # whenUnsatisfiable: DoNotSchedule
4489 # -- Deployment strategy to be added to the commit server Deployment
4490 deploymentStrategy: {}
4491 # type: RollingUpdate
4494 # maxUnavailable: 25%
4496 # -- Priority class for the commit server pods
4497 # @default -- `""` (defaults to global.priorityClassName)
4498 priorityClassName: ""
4499 # Default commit server's network policy
4501 # -- Default network policy rules used by commit server
4502 # @default -- `false` (defaults to global.networkPolicy.create)
4504 ## Commit server Vertical Pod Autoscaler
4505 ## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/
4507 # -- Deploy a [VerticalPodAutoscaler](https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically/) for the commit server
4509 # -- Labels to be added to commit server vpa
4511 # -- Annotations to be added to commit server vpa
4513 # -- One of the VPA operation modes
4514 ## Ref: https://kubernetes.io/docs/concepts/workloads/autoscaling/#scaling-workloads-vertically
4515 ## Note: Recreate update mode requires more than one replica unless the min-replicas VPA controller flag is overridden
4517 # -- Controls how VPA computes the recommended resources for commit server container
4518 ## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/examples/hamster.yaml
4520 # controlledResources: ["cpu", "memory"]
4527 # -- The recommenders that will provide recommendations for vertical scaling. Only relevant if a named VPA recommender (e.g. one started with a custom recommender name) is in use; leave unset to use the cluster's default recommender
4528 ## Ref: https://github.com/kubernetes/autoscaler/blob/master/vertical-pod-autoscaler/docs/api.md#verticalpodautoscalerspec
4529 ## NOTE: specify only zero or one recommender as of VPA 1.7.1
4531 # -- Configures a startup resource boost for faster cold-start (application boot) resource allocation. NOTE: startupBoost is currently a GKE-specific extension to the VPA API and is only honored on GKE clusters; it is rendered only when set
4532 ## Ref: https://cloud.google.com/kubernetes-engine/docs/how-to/boost-application-startup
4537 # durationSeconds: 10