1# Default values for aws-vpc-cni.
2# This is a YAML-formatted file.
3# Declare variables to be passed into your templates.
5# This default name override is to maintain backwards compatability with
10 tag: 1.23.2-r0@sha256:3f6c4c0f0579963d562004f2fe9b6036d4a2ae88003b6e07b2104c5a79d6482c
14 account: "602401143452"
15 pullPolicy: IfNotPresent
16 # Set to use custom image
18 # overrideRepository: "repo/org/image"
20 # override: "repo/org/image:tag"
21 repository: chainreg.biz/chainguard-private/amazon-k8s-cni-init
23 DISABLE_TCP_EARLY_DEMUX: "false"
31 tag: 1.4.3-r0@sha256:03dc0e3ab27fd9bd18b67da17511ebf7292fa7b9547517825f227fdabb9cd868
35 account: "602401143452"
36 pullPolicy: IfNotPresent
37 # Set to use custom image
39 # overrideRepository: "repo/org/image"
41 # override: "repo/org/image:tag"
42 repository: chainreg.biz/chainguard-private/aws-network-policy-agent
48 enableCloudWatchLogs: "false"
49 enablePolicyEventLogs: "false"
50 networkPolicyAgentLogFileLocation: "/var/log/aws-routed-eni/network-policy-agent.log"
52 metricsBindAddr: "8162"
53 healthProbeBindAddr: "8163"
54 conntrackCacheCleanupPeriod: 300
55 conntrackCacheTableSize: 524288
59 tag: 1.23.2-r0@sha256:e9ed9289a49584d297d74bbc54472c0701876fc91f4956bc9f336f01a8403504
63 account: "602401143452"
64 pullPolicy: IfNotPresent
65 # Set to use custom image
67 # overrideRepository: "repo/org/image"
69 # override: "repo/org/image:tag"
70 repository: chainreg.biz/chainguard-private/amazon-k8s-cni
71# The CNI supports a number of environment variable settings
72# See https://github.com/aws/amazon-vpc-cni-k8s#cni-configuration-variables
74 ADDITIONAL_ENI_TAGS: "{}"
75 AWS_VPC_CNI_NODE_PORT_SUPPORT: "true"
76 AWS_VPC_ENI_MTU: "9001"
77 AWS_VPC_K8S_CNI_CUSTOM_NETWORK_CFG: "false"
78 AWS_VPC_K8S_CNI_EXTERNALSNAT: "false"
79 AWS_VPC_K8S_CNI_LOG_FILE: "/host/var/log/aws-routed-eni/ipamd.log"
80 AWS_VPC_K8S_CNI_LOGLEVEL: DEBUG
81 AWS_VPC_K8S_CNI_RANDOMIZESNAT: "prng"
82 AWS_VPC_K8S_CNI_VETHPREFIX: eni
83 AWS_VPC_K8S_PLUGIN_LOG_FILE: "/var/log/aws-routed-eni/plugin.log"
84 AWS_VPC_K8S_PLUGIN_LOG_LEVEL: DEBUG
85 DISABLE_INTROSPECTION: "false"
86 DISABLE_METRICS: "false"
87 ENABLE_POD_ENI: "false"
88 ENABLE_PREFIX_DELEGATION: "false"
90 WARM_PREFIX_TARGET: "1"
91 DISABLE_NETWORK_RESOURCE_PROVISIONING: "false"
94 ENABLE_SUBNET_DISCOVERY: "true"
95 VPC_CNI_VERSION: "v1.22.4"
96 NETWORK_POLICY_ENFORCING_MODE: "standard"
97 ENABLE_IMDS_ONLY_MODE: "false"
98 ENABLE_MULTI_NIC: "false"
99# Add env from configMap or from secrets
103# name: example-config
108# name: example-config
113# name: example-secret
116# this flag enables you to use the match label that was present in the original daemonset deployed by EKS
117# You can then annotate and label the original aws-node resources and 'adopt' them into a helm release
118originalMatchLabels: false
119# Settings for aws-vpc-cni ConfigMap
120# - Network Policy settings
121enableNetworkPolicy: "false"
123enableWindowsIpam: "false"
124# - Windows Prefix Delegation settings
125enableWindowsPrefixDelegation: "false"
126warmWindowsPrefixTarget: 0
127warmWindowsIPTarget: 1
128minimumWindowsIPTarget: 3
129# - Security Groups for Pods settings
135fullnameOverride: "aws-node"
136priorityClassName: system-node-critical
137podSecurityContext: {}
146 # Specifies whether a service account should be created
148 # The name of the service account to use.
149 # If not set and create is true, a name is generated using the fullname template
152 # To set annotations - serviceAccount.annotations."eks\.amazonaws\.com/role-arn"=arn:aws:iam::<AWS_ACCOUNT_ID>:<IAM_ROLE_NAME>
156 - /app/grpc-health-probe
158 - '-connect-timeout=5s'
160 initialDelaySeconds: 60
161livenessProbeTimeoutSeconds: 10
165 - /app/grpc-health-probe
167 - '-connect-timeout=5s'
169 initialDelaySeconds: 1
170readinessProbeTimeoutSeconds: 10
177 maxUnavailable: "10%"
183 requiredDuringSchedulingIgnoredDuringExecution:
186 - key: "kubernetes.io/os"
190 - key: "kubernetes.io/arch"
195 - key: "eks.amazonaws.com/compute-type"
202 # Specifies whether ENIConfigs should be created
206 # Key identifies the AZ
207 # Value contains the subnet ID and security group IDs within that AZ
221 # Create Prometheus podMonitor
223 # Annotations to add to the Prometheus podMonitor
225 # Labels to add to the Prometheus podMonitor
227 # The interval to scrape metrics.
229 # The timeout before a metrics scrape fails.
231 # relabelings to apply to the podMonitor