DirectorySecurity AdvisoriesPricing
Sign in
Directory
community-grafana logoHELM

community-grafana

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:
Compare:

1
global:
2
# -- Overrides the Docker registry globally for all images
3
imageRegistry: null
4
# To help compatibility with other charts which use global.imagePullSecrets.
5
# Allow either an array of {name: pullSecret} maps (k8s-style), or an array of strings (more common helm-style).
6
# Can be templated.
7
# global:
8
# imagePullSecrets:
9
# - name: pullSecret1
10
# - name: pullSecret2
11
# or
12
# global:
13
# imagePullSecrets:
14
# - pullSecret1
15
# - pullSecret2
16
imagePullSecrets: []
17
rbac:
18
create: true
19
## Use an existing ClusterRole/Role (depending on rbac.namespaced false/true)
20
# useExistingRole: name-of-some-role
21
# useExistingClusterRole: name-of-some-clusterRole
22
pspEnabled: false
23
pspUseAppArmor: false
24
namespaced: false
25
# Only has an effect if namespaced: true is set
26
namespaces: []
27
extraRoleRules: []
28
# - apiGroups: []
29
# resources: []
30
# verbs: []
31
extraClusterRoleRules: []
32
# - apiGroups: []
33
# resources: []
34
# verbs: []
35
serviceAccount:
36
create: true
37
name: ""
38
nameTest: ""
39
## ServiceAccount labels.
40
labels: {}
41
## Service account annotations. Can be templated.
42
# annotations:
43
# eks.amazonaws.com/role-arn: arn:aws:iam::123456789000:role/iam-role-name-here
44
45
## autoMount is deprecated in favor of automountServiceAccountToken
46
# autoMount: false
47
automountServiceAccountToken: false
48
replicas: 1
49
## Create a headless service for the deployment
50
headlessService: false
51
## Should the service account be auto mounted on the pod
52
automountServiceAccountToken: true
53
## Create HorizontalPodAutoscaler object for deployment type
54
#
55
autoscaling:
56
enabled: false
57
minReplicas: 1
58
maxReplicas: 5
59
targetCPU: "60"
60
targetMemory: ""
61
behavior: {}
62
## See `kubectl explain poddisruptionbudget.spec` for more
63
## ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
64
podDisruptionBudget: {}
65
# apiVersion: ""
66
# minAvailable: 1
67
# maxUnavailable: 1
68
# unhealthyPodEvictionPolicy: IfHealthyBudget
69
70
## See `kubectl explain deployment.spec.strategy` for more
71
## ref: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#strategy
72
deploymentStrategy:
73
type: RollingUpdate
74
## The maximum time in seconds for a Deployment to make progress before it is considered to be failed.
75
## ref: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#progress-deadline-seconds
76
progressDeadlineSeconds: null
77
## Startup probe. Holds off the liveness and readiness probes until it succeeds, useful for slow starts.
78
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
79
startupProbe: {}
80
readinessProbe:
81
httpGet:
82
path: /api/health
83
port: grafana
84
livenessProbe:
85
httpGet:
86
path: /api/health
87
port: grafana
88
initialDelaySeconds: 60
89
timeoutSeconds: 30
90
failureThreshold: 10
91
## Use an alternate scheduler, e.g. "stork".
92
## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/
93
##
94
# schedulerName: "default-scheduler"
95
image:
96
# -- The Docker registry
97
registry: chainreg.biz
98
# -- Docker image repository
99
repository: chainguard-private/grafana
100
# Overrides the Grafana image tag whose default is the chart appVersion
101
tag: v13.2.3-r1
102
sha: sha256:04af70d1d3cb6635a0a4572a2eb3e7f115e10bd16fb0c0f8516ba4fbeb44aefd
103
pullPolicy: IfNotPresent
104
## Optionally specify an array of imagePullSecrets.
105
## Secrets must be manually created in the namespace.
106
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
107
## Can be templated.
108
##
109
pullSecrets: []
110
# - myRegistrKeySecretName
111
testFramework:
112
enabled: true
113
## The type of Helm hook used to run this test. Defaults to test.
114
## ref: https://helm.sh/docs/topics/charts_hooks/#the-available-hooks
115
##
116
# hookType: test
117
image:
118
# -- The Docker registry
119
registry: docker.io
120
repository: bats/bats
121
tag: "1.14.0"
122
imagePullPolicy: IfNotPresent
123
securityContext:
124
runAsNonRoot: true
125
runAsUser: 472
126
runAsGroup: 472
127
seccompProfile:
128
type: RuntimeDefault
129
containerSecurityContext:
130
allowPrivilegeEscalation: false
131
privileged: false
132
capabilities:
133
drop:
134
- ALL
135
seccompProfile:
136
type: RuntimeDefault
137
readOnlyRootFilesystem: true
138
resources: {}
139
# limits:
140
# cpu: 100m
141
# memory: 128Mi
142
# requests:
143
# cpu: 100m
144
# memory: 128Mi
145
# dns configuration for pod
146
dnsPolicy: ~
147
dnsConfig: {}
148
# nameservers:
149
# - 8.8.8.8
150
# options:
151
# - name: ndots
152
# value: "2"
153
# - name: edns0
154
155
hostUsers: ~
156
securityContext:
157
runAsNonRoot: true
158
runAsUser: 472
159
runAsGroup: 472
160
fsGroup: 472
161
containerSecurityContext:
162
allowPrivilegeEscalation: false
163
privileged: false
164
capabilities:
165
drop:
166
- ALL
167
seccompProfile:
168
type: RuntimeDefault
169
readOnlyRootFilesystem: true
170
# Enable creating the grafana configmap
171
createConfigmap: true
172
# Extra configmaps to mount in grafana pods
173
# Values are templated.
174
extraConfigmapMounts: []
175
# - name: certs-configmap
176
# mountPath: /etc/grafana/ssl/
177
# subPath: certificates.crt # (optional)
178
# configMap: certs-configmap
179
# readOnly: true
180
# optional: false
181
182
extraEmptyDirMounts: []
183
# - name: provisioning-notifiers
184
# mountPath: /etc/grafana/provisioning/notifiers
185
186
# Shadow `/usr/share/grafana/data/plugins-bundled` with an emptyDir so plugins
187
# listed under `plugins:` install cleanly into `/var/lib/grafana/plugins` instead
188
# of failing on the read-only bundled directory shipped in the Grafana image.
189
# Required for plugins moved out of core in Grafana 13 (e.g. `elasticsearch`,
190
# `cloudwatch`) when listed in `plugins:`. Side effect: any bundled plugin not
191
# explicitly listed in `plugins:` will not be available.
192
shadowBundledPlugins: false
193
# Apply extra labels to common labels.
194
extraLabels: {}
195
## Assign a PriorityClassName to pods if set
196
# priorityClassName:
197
downloadDashboardsImage:
198
# -- The Docker registry
199
registry: chainreg.biz
200
repository: chainguard-private/curl
201
tag: latest
202
sha: sha256:7a90b25baa95b606458f215c38535b39177295105ab4fbc3714f7533cc5b4366
203
pullPolicy: IfNotPresent
204
downloadDashboards:
205
env: {}
206
envFromSecret: ""
207
resources: {}
208
securityContext:
209
allowPrivilegeEscalation: false
210
capabilities:
211
drop:
212
- ALL
213
seccompProfile:
214
type: RuntimeDefault
215
readOnlyRootFilesystem: true
216
envValueFrom: {}
217
# ENV_NAME:
218
# configMapKeyRef:
219
# name: configmap-name
220
# key: value_key
221
## Pod Annotations
222
# podAnnotations: {}
223
224
## ConfigMap Annotations
225
# configMapAnnotations: {}
226
# argocd.argoproj.io/sync-options: Replace=true
227
228
## Pod Labels
229
# podLabels: {}
230
podPortName: grafana
231
gossipPortName: gossip
232
## Deployment annotations
233
# annotations: {}
234
235
## Expose the grafana service to be accessed from outside the cluster (LoadBalancer service).
236
## or access it from within the cluster (ClusterIP service). Set the service type and the port to serve it.
237
## ref: http://kubernetes.io/docs/user-guide/services/
238
##
239
service:
240
enabled: true
241
type: ClusterIP
242
# Set the ip family policy to configure dual-stack see [Configure dual-stack](https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services)
243
ipFamilyPolicy: ""
244
# Sets the families that should be supported and the order in which they should be applied to ClusterIP as well. Can be IPv4 and/or IPv6.
245
ipFamilies: []
246
loadBalancerIP: ""
247
loadBalancerClass: ""
248
loadBalancerSourceRanges: []
249
port: 80
250
targetPort: 3000
251
# targetPort: 4181 To be used with a proxy extraContainer
252
## Service annotations. Can be templated.
253
annotations: {}
254
labels: {}
255
portName: service
256
# Adds the appProtocol field to the service. This allows to work with istio protocol selection. Ex: "http" or "tcp"
257
appProtocol: ""
258
sessionAffinity: ""
259
# trafficDistribution allows specifying how traffic is distributed to Service endpoints.
260
# Valid values: "" (default - standard load balancing),"PreferSameZone" (K8s 1.34+), "PreferSameNode" (K8s 1.35+), "PreferClose" (deprecated, use PreferSameZone),
261
trafficDistribution: ""
262
serviceMonitor:
263
## If true, a ServiceMonitor CR is created for a prometheus operator
264
## https://github.com/coreos/prometheus-operator
265
##
266
enabled: false
267
path: /metrics
268
# namespace: monitoring (defaults to use the namespace this chart is deployed to)
269
labels: {}
270
# Set these to override the Prometheus global scrape interval/timeout.
271
# interval: 30s
272
# scrapeTimeout: 30s
273
scheme: http
274
tlsConfig: {}
275
relabelings: []
276
metricRelabelings: []
277
basicAuth: {}
278
targetLabels: []
279
extraExposePorts: []
280
# - name: keycloak
281
# port: 8080
282
# targetPort: 8080
283
284
# overrides pod.spec.hostAliases in the grafana deployment's pods
285
hostAliases: []
286
# - ip: "1.2.3.4"
287
# hostnames:
288
# - "my.host.com"
289
290
ingress:
291
enabled: false
292
# ingressClassName: nginx
293
# Values can be templated
294
annotations: {}
295
# kubernetes.io/ingress.class: nginx
296
# kubernetes.io/tls-acme: "true"
297
labels: {}
298
path: /
299
pathType: Prefix
300
hosts:
301
- chart-example.local
302
## Extra paths to prepend to every host configuration. This is useful when working with annotation based services.
303
extraPaths: []
304
# - path: /*
305
# pathType: Prefix
306
# backend:
307
# service:
308
# name: ssl-redirect
309
# port:
310
# name: use-annotation
311
312
tls: []
313
# - secretName: chart-example-tls
314
# hosts:
315
# - chart-example.local
316
# -- BETA: Configure the gateway routes for the chart here.
317
# More routes can be added by adding a dictionary key like the 'main' route.
318
# Be aware that this is an early beta of this feature,
319
# kube-prometheus-stack does not guarantee this works and is subject to change.
320
# Being BETA this can/will change in the future without notice, do not use unless you want to take that risk
321
# [[ref]](https://gateway-api.sigs.k8s.io/references/spec/#gateway.networking.k8s.io%2fv1alpha2)
322
route:
323
main:
324
# -- Enables or disables the route
325
enabled: false
326
# -- Set the route apiVersion, e.g. gateway.networking.k8s.io/v1 or gateway.networking.k8s.io/v1alpha2
327
apiVersion: gateway.networking.k8s.io/v1
328
# -- Set the route kind
329
# Valid options are GRPCRoute, HTTPRoute, TCPRoute, TLSRoute, UDPRoute
330
kind: HTTPRoute
331
annotations: {}
332
labels: {}
333
hostnames: []
334
# - my-filter.example.com
335
parentRefs: []
336
# - name: acme-gw
337
338
matches:
339
- path:
340
type: PathPrefix
341
value: /
342
## Timeouts define the timeouts that can be configured for an HTTP request.
343
## Ref. https://gateway-api.sigs.k8s.io/api-types/httproute/#timeouts-optional
344
timeouts: {}
345
# request: 10s
346
# backendRequest: 5s
347
348
## SessionPersistence defines and configures session persistence for the route rule.
349
## Ref. https://gateway-api.sigs.k8s.io/geps/gep-1619/
350
sessionPersistence: {}
351
# sessionName: grafana-session
352
# type: Cookie
353
# absoluteTimeout: 48h
354
# cookieConfig:
355
# lifetimeType: Permanent
356
357
## Filters define the filters that are applied to requests that match this rule.
358
filters: []
359
## Additional custom rules that can be added to the route
360
additionalRules: []
361
## httpsRedirect adds a filter for redirecting to https (HTTP 301 Moved Permanently).
362
## To redirect HTTP traffic to HTTPS, you need to have a Gateway with both HTTP and HTTPS listeners.
363
## Matches and filters do not take effect if enabled.
364
## Ref. https://gateway-api.sigs.k8s.io/guides/http-redirect-rewrite/
365
httpsRedirect: false
366
# -- BETA: Configure Gateway API ListenerSet resources for the chart here.
367
# ListenerSet allows attaching additional listeners to an existing Gateway.
368
# More listener sets can be added by adding a dictionary key like the 'main' entry.
369
# Being BETA this can/will change in the future without notice, do not use unless you want to take that risk
370
# [[ref]](https://gateway-api.sigs.k8s.io/reference/api-spec/main/spec/#listenerset)
371
listenerSet:
372
main:
373
# -- Enables or disables the listener set
374
enabled: false
375
# -- Set the ListenerSet apiVersion, e.g. gateway.networking.k8s.io/v1
376
apiVersion: gateway.networking.k8s.io/v1
377
annotations: {}
378
labels: {}
379
# -- Reference to the parent Gateway this ListenerSet attaches to
380
parentRef: {}
381
# name: my-gateway
382
# namespace: default
383
# group: gateway.networking.k8s.io
384
# kind: Gateway
385
386
# -- List of listeners to attach to the parent Gateway
387
listeners: []
388
# - name: https
389
# port: 443
390
# protocol: HTTPS
391
# hostname: grafana.example.com
392
# tls:
393
# mode: Terminate
394
# certificateRefs:
395
# - name: grafana-tls
396
# allowedRoutes:
397
# namespaces:
398
# from: Same
399
resources: {}
400
# limits:
401
# cpu: 100m
402
# memory: 128Mi
403
# requests:
404
# cpu: 100m
405
# memory: 128Mi
406
407
## Configure the GOMEMLIMIT environment variable.
408
## When enabled and resources.limits.memory is set, GOMEMLIMIT is injected
409
## as a computed value (factor × memory limit) unless the user has already
410
## defined GOMEMLIMIT via env or envValueFrom.
411
goMemLimit:
412
# -- Enable automatic GOMEMLIMIT injection.
413
enabled: true
414
# -- Fraction of resources.limits.memory to use as GOMEMLIMIT (e.g. 0.9 = 90 %).
415
factor: 0.9
416
## Node labels for pod assignment
417
## ref: https://kubernetes.io/docs/user-guide/node-selection/
418
#
419
nodeSelector: {}
420
## Tolerations for pod assignment
421
## ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/
422
##
423
tolerations: []
424
## Affinity for pod assignment (evaluated as template)
425
## ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity
426
##
427
affinity: {}
428
## Topology Spread Constraints
429
## ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
430
##
431
topologySpreadConstraints: []
432
## Additional init containers (evaluated as template)
433
## ref: https://kubernetes.io/docs/concepts/workloads/pods/init-containers/
434
##
435
extraInitContainers: []
436
## Enable an Specify container in extraContainers. This is meant to allow adding an authentication proxy to a grafana pod
437
extraContainers: ""
438
# extraContainers: |
439
# - name: proxy
440
# image: quay.io/gambol99/keycloak-proxy:latest
441
# args:
442
# - -provider=github
443
# - -client-id=
444
# - -client-secret=
445
# - -github-org=<ORG_NAME>
446
# - -email-domain=*
447
# - -cookie-secret=
448
# - -http-address=http://0.0.0.0:4181
449
# - -upstream-url=http://127.0.0.1:3000
450
# ports:
451
# - name: proxy-web
452
# containerPort: 4181
453
454
## Volumes that can be used in init containers that will not be mounted to deployment pods
455
extraContainerVolumes: []
456
# - name: volume-from-secret
457
# secret:
458
# secretName: secret-to-mount
459
# - name: empty-dir-volume
460
# emptyDir: {}
461
462
## Enable persistence using Persistent Volume Claims
463
## ref: https://kubernetes.io/docs/concepts/storage/persistent-volumes/
464
##
465
persistence:
466
type: pvc
467
enabled: false
468
# storageClassName: default
469
## (Optional) Use this to bind the claim to an existing PersistentVolume (PV) by name.
470
volumeName: ""
471
accessModes:
472
- ReadWriteOnce
473
size: 10Gi
474
# annotations: {}
475
finalizers:
476
- kubernetes.io/pvc-protection
477
# selectorLabels: {}
478
## Sub-directory of the PV to mount. Can be templated.
479
# subPath: ""
480
## Name of an existing PVC. Can be templated.
481
# existingClaim:
482
## Extra labels to apply to a PVC.
483
extraPvcLabels: {}
484
disableWarning: false
485
## Configure StatefulSet persistent volume claim retention policy.
486
## This is ignored when Grafana is configured to use a Deployment with a PVC.
487
## By default, Kubernetes uses Retain for both whenDeleted and whenScaled.
488
persistentVolumeClaimRetentionPolicy: {}
489
# whenDeleted: Retain
490
# whenScaled: Retain
491
492
## If persistence is not enabled, this allows to mount the
493
## local storage in-memory to improve performance
494
##
495
inMemory:
496
enabled: false
497
## The maximum usage on memory medium EmptyDir would be
498
## the minimum value between the SizeLimit specified
499
## here and the sum of memory limits of all containers in a pod
500
##
501
# sizeLimit: 300Mi
502
## If 'lookupVolumeName' is set to true, Helm will attempt to retrieve
503
## the current value of 'spec.volumeName' and incorporate it into the template.
504
lookupVolumeName: true
505
initChownData:
506
## If false, data ownership will not be reset at startup
507
## This allows the grafana-server to be run with an arbitrary user
508
##
509
enabled: true
510
## initChownData container image
511
##
512
image:
513
# -- The Docker registry
514
registry: chainreg.biz
515
repository: chainguard-private/busybox
516
tag: glibc-1.38.0-r2
517
sha: sha256:7a438bd8593293ec90b6249fd8a51259874dadc11c3a9976bbcc0b935ce4cb51
518
pullPolicy: IfNotPresent
519
## initChownData resource requests and limits
520
## Ref: http://kubernetes.io/docs/user-guide/compute-resources/
521
##
522
resources: {}
523
# limits:
524
# cpu: 100m
525
# memory: 128Mi
526
# requests:
527
# cpu: 100m
528
# memory: 128Mi
529
securityContext:
530
readOnlyRootFilesystem: false
531
runAsNonRoot: false
532
runAsUser: 0
533
seccompProfile:
534
type: RuntimeDefault
535
capabilities:
536
add:
537
- CHOWN
538
- DAC_OVERRIDE
539
drop:
540
- ALL
541
# Administrator credentials when not using an existing secret (see below)
542
adminUser: admin
543
# adminPassword: strongpassword
544
545
# Use an existing secret for the admin user.
546
admin:
547
## Name of the secret. Can be templated.
548
existingSecret: ""
549
userKey: admin-user
550
passwordKey: admin-password
551
## Define command to be executed at startup by grafana container
552
## Needed if using `vault-env` to manage secrets (ref: https://banzaicloud.com/blog/inject-secrets-into-pods-vault/)
553
## The default distroless image starts Grafana directly and does not contain a shell or `/run.sh`.
554
# command:
555
# - "/path/to/your/entrypoint"
556
557
## Optionally define args if command is used
558
## Needed if using `hashicorp/envconsul` to manage secrets
559
## By default no arguments are set
560
# args:
561
# - "-secret"
562
# - "secret/grafana"
563
# - "./grafana"
564
565
## Extra environment variables that will be pass onto deployment pods
566
##
567
## to provide grafana with access to CloudWatch on AWS EKS:
568
## 1. create an iam role of type "Web identity" with provider oidc.eks.* (note the provider for later)
569
## 2. edit the "Trust relationships" of the role, add a line inside the StringEquals clause using the
570
## same oidc eks provider as noted before (same as the existing line)
571
## also, replace NAMESPACE and prometheus-operator-grafana with the service account namespace and name
572
##
573
## "oidc.eks.us-east-1.amazonaws.com/id/XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX:sub": "system:serviceaccount:NAMESPACE:prometheus-operator-grafana",
574
##
575
## 3. attach a policy to the role, you can use a built in policy called CloudWatchReadOnlyAccess
576
## 4. use the following env: (replace 123456789000 and iam-role-name-here with your aws account number and role name)
577
##
578
## env:
579
## AWS_ROLE_ARN: arn:aws:iam::123456789000:role/iam-role-name-here
580
## AWS_WEB_IDENTITY_TOKEN_FILE: /var/run/secrets/eks.amazonaws.com/serviceaccount/token
581
## AWS_REGION: us-east-1
582
##
583
## 5. uncomment the EKS section in extraSecretMounts: below
584
## 6. uncomment the annotation section in the serviceAccount: above
585
## make sure to replace arn:aws:iam::123456789000:role/iam-role-name-here with your role arn
586
env: {}
587
## "valueFrom" environment variable references that will be added to deployment pods. Name is templated.
588
## ref: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.19/#envvarsource-v1-core
589
## Renders in container spec as:
590
## env:
591
## ...
592
## - name: <key>
593
## valueFrom:
594
## <value rendered as YAML>
595
envValueFrom: {}
596
# ENV_NAME:
597
# configMapKeyRef:
598
# name: configmap-name
599
# key: value_key
600
601
## The name of a secret in the same kubernetes namespace which contain values to be added to the environment
602
## This can be useful for auth tokens, etc. Value is templated.
603
envFromSecret: ""
604
## Sensible environment variables that will be rendered as new secret object
605
## This can be useful for auth tokens, etc.
606
## If the secret values contains "{{", they'll need to be properly escaped so that they are not interpreted by Helm
607
## ref: https://helm.sh/docs/howto/charts_tips_and_tricks/#using-the-tpl-function
608
envRenderSecret: {}
609
## The names of secrets in the same kubernetes namespace which contain values to be added to the environment
610
## Each entry should contain a name key, and can optionally specify whether the secret must be defined with an optional key.
611
## Name is templated.
612
envFromSecrets: []
613
## - name: secret-name
614
## prefix: prefix
615
## optional: true
616
617
## The names of configmaps in the same kubernetes namespace which contain values to be added to the environment
618
## Each entry should contain a name key, and can optionally specify whether the configmap must be defined with an optional key.
619
## Name is templated.
620
## ref: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.23/#configmapenvsource-v1-core
621
envFromConfigMaps: []
622
## - name: configmap-name
623
## prefix: prefix
624
## optional: true
625
626
# Inject Kubernetes services as environment variables.
627
# See https://kubernetes.io/docs/concepts/services-networking/connect-applications-service/#environment-variables
628
enableServiceLinks: true
629
## Additional grafana server secret mounts
630
# Defines additional mounts with secrets. Secrets must be manually created in the namespace.
631
extraSecretMounts: []
632
# - name: secret-files
633
# mountPath: /etc/secrets
634
# secretName: grafana-secret-files
635
# readOnly: true
636
# optional: false
637
# subPath: ""
638
#
639
# for AWS EKS (cloudwatch) use the following (see also instruction in env: above)
640
# - name: aws-iam-token
641
# mountPath: /var/run/secrets/eks.amazonaws.com/serviceaccount
642
# readOnly: true
643
# projected:
644
# defaultMode: 420
645
# sources:
646
# - serviceAccountToken:
647
# audience: sts.amazonaws.com
648
# expirationSeconds: 86400
649
# path: token
650
#
651
# for CSI e.g. Azure Key Vault use the following
652
# - name: secrets-store-inline
653
# mountPath: /run/secrets/vault.azure.com
654
# readOnly: true
655
# csi:
656
# driver: secrets-store.csi.k8s.io
657
# readOnly: true
658
# volumeAttributes:
659
# secretProviderClass: "akv-grafana-spc"
660
# nodePublishSecretRef: # Only required when using service principal mode
661
# name: grafana-akv-creds # Only required when using service principal mode
662
663
## Additional grafana server volume mounts
664
# Defines additional volume mounts.
665
extraVolumeMounts: []
666
# - name: extra-volume-0
667
# mountPath: /mnt/volume0
668
# readOnly: true
669
# - name: extra-volume-1
670
# mountPath: /mnt/volume1
671
# readOnly: true
672
# - name: grafana-secrets
673
# mountPath: /mnt/volume2
674
675
## Additional Grafana server volumes
676
extraVolumes: []
677
# - name: extra-volume-0
678
# existingClaim: volume-claim
679
# - name: extra-volume-1
680
# hostPath:
681
# path: /usr/shared/
682
# type: ""
683
# - name: grafana-secrets
684
# csi:
685
# driver: secrets-store.csi.k8s.io
686
# readOnly: true
687
# volumeAttributes:
688
# secretProviderClass: "grafana-env-spc"
689
690
## Container Lifecycle Hooks. Execute a specific bash command or make an HTTP request
691
lifecycleHooks: {}
692
# postStart:
693
# exec:
694
# command: []
695
696
## Pass the plugins you want installed as a list.
697
##
698
plugins: []
699
# - digrich-bubblechart-panel
700
# - grafana-clock-panel
701
## You can also use other plugin download URL, as long as they are valid zip files,
702
## and specify the name of the plugin as prefix, with an version. Like this:
703
# - marcusolsson-json-datasource@1.3.24@https://grafana.com/api/plugins/marcusolsson-json-datasource/versions/1.3.24/download
704
705
## Configure grafana datasources
706
## ref: http://docs.grafana.org/administration/provisioning/#datasources
707
##
708
datasources: {}
709
# datasources.yaml:
710
# apiVersion: 1
711
# datasources:
712
# - name: Prometheus
713
# type: prometheus
714
# url: http://prometheus-prometheus-server
715
# access: proxy
716
# isDefault: true
717
# - name: CloudWatch
718
# type: cloudwatch
719
# access: proxy
720
# uid: cloudwatch
721
# editable: false
722
# jsonData:
723
# authType: default
724
# defaultRegion: us-east-1
725
# deleteDatasources: []
726
# - name: Prometheus
727
728
## Configure grafana alerting (can be templated)
729
## ref: https://docs.grafana.com/alerting/set-up/provision-alerting-resources/file-provisioning/
730
##
731
alerting: {}
732
# policies.yaml:
733
# apiVersion: 1
734
# policies:
735
# - orgId: 1
736
# receiver: first_uid
737
#
738
# rules.yaml:
739
# apiVersion: 1
740
# groups:
741
# - orgId: 1
742
# name: '{{ .Chart.Name }}_my_rule_group'
743
# folder: my_first_folder
744
# interval: 60s
745
# rules:
746
# - uid: my_id_1
747
# title: my_first_rule
748
# condition: A
749
# data:
750
# - refId: A
751
# datasourceUid: '-100'
752
# model:
753
# conditions:
754
# - evaluator:
755
# params:
756
# - 3
757
# type: gt
758
# operator:
759
# type: and
760
# query:
761
# params:
762
# - A
763
# reducer:
764
# type: last
765
# type: query
766
# datasource:
767
# type: __expr__
768
# uid: '-100'
769
# expression: 1==0
770
# intervalMs: 1000
771
# maxDataPoints: 43200
772
# refId: A
773
# type: math
774
# dashboardUid: my_dashboard
775
# panelId: 123
776
# noDataState: Alerting
777
# for: 60s
778
# annotations:
779
# some_key: some_value
780
# labels:
781
# team: sre_team_1
782
#
783
# contactpoints.yaml:
784
# secret:
785
# apiVersion: 1
786
# contactPoints:
787
# - orgId: 1
788
# name: cp_1
789
# receivers:
790
# - uid: first_uid
791
# type: pagerduty
792
# settings:
793
# integrationKey: XXX
794
# severity: critical
795
# class: ping failure
796
# component: Grafana
797
# group: app-stack
798
# summary: |
799
# {{ `{{ include "default.message" . }}` }}
800
#
801
# templates.yaml:
802
# apiVersion: 1
803
# templates:
804
# - orgId: 1
805
# name: my_first_template
806
# template: |
807
# {{ `
808
# {{ define "my_first_template" }}
809
# Custom notification message
810
# {{ end }}
811
# ` }}
812
#
813
# mutetimes.yaml
814
# apiVersion: 1
815
# muteTimes:
816
# - orgId: 1
817
# name: mti_1
818
# # refer to https://prometheus.io/docs/alerting/latest/configuration/#time_interval-0
819
# time_intervals: {}
820
821
## Configure notifiers
822
## ref: http://docs.grafana.org/administration/provisioning/#alert-notification-channels
823
##
824
notifiers: {}
825
# notifiers.yaml:
826
# notifiers:
827
# - name: email-notifier
828
# type: email
829
# uid: email1
830
# # either:
831
# org_id: 1
832
# # or
833
# org_name: Main Org.
834
# is_default: true
835
# settings:
836
# addresses: an_email_address@example.com
837
# delete_notifiers:
838
839
## Configure grafana dashboard providers
840
## ref: http://docs.grafana.org/administration/provisioning/#dashboards
841
##
842
## `path` must be /var/lib/grafana/dashboards/<provider_name>
843
##
844
dashboardProviders: {}
845
# dashboardproviders.yaml:
846
# apiVersion: 1
847
# providers:
848
# - name: 'default'
849
# orgId: 1
850
# folder: ''
851
# type: file
852
# disableDeletion: false
853
# editable: true
854
# options:
855
# path: /var/lib/grafana/dashboards/default
856
857
## Configure how curl fetches remote dashboards. The beginning dash is required.
858
## NOTE: This sets the default short flags for all dashboards, but these
859
## defaults can be overridden individually for each dashboard by setting
860
## curlOptions. See the example dashboards section below.
861
##
862
## -s - silent mode
863
## -k - allow insecure (eg: non-TLS) connections
864
## -f - fail fast
865
## See the curl documentation for additional options
866
##
867
defaultCurlOptions: "-skf"
868
## Configure shell options for downloading dashboards. The beginning dash is added automatically.
869
## Add `x` to enable command tracing. This can expose sensitive values in logs.
870
##
871
defaultShellOptions: "eufo pipefail"
872
## Configure grafana dashboard to import
873
## NOTE: To use dashboards you must also enable/configure dashboardProviders
874
## ref: https://grafana.com/dashboards
875
##
876
## dashboards per provider, use provider name as key.
877
## For dashboards downloaded via gnetId or url, the optional "title" key overrides
878
## the dashboard title in the downloaded JSON so the UI displays your custom title.
879
##
880
dashboards: {}
881
# default:
882
# some-dashboard:
883
# json: |
884
# $RAW_JSON
885
# custom-dashboard:
886
# file: dashboards/custom-dashboard.json
887
# prometheus-stats:
888
# title: My Custom Dashboard Title # optional; overrides the dashboard title in the downloaded JSON
889
# gnetId: 2
890
# revision: 2
891
# datasource: Prometheus
892
# local-dashboard:
893
# url: https://example.com/repository/test.json
894
# curlOptions: "-sLf"
895
# token: ''
896
# local-dashboard-base64:
897
# url: https://example.com/repository/test-b64.json
898
# token: ''
899
# b64content: true
900
# local-dashboard-gitlab:
901
# url: https://example.com/repository/test-gitlab.json
902
# gitlabToken: ''
903
# local-dashboard-bitbucket:
904
# url: https://example.com/repository/test-bitbucket.json
905
# bearerToken: ''
906
# local-dashboard-azure:
907
# url: https://example.com/repository/test-azure.json
908
# basic: ''
909
# acceptHeader: '*/*'
910
911
## Reference to external ConfigMap per provider. Use provider name as key and ConfigMap name as value.
912
## A provider dashboards must be defined either by external ConfigMaps or in values.yaml, not in both.
913
## ConfigMap data example:
914
##
915
## data:
916
## example-dashboard.json: |
917
## RAW_JSON
918
##
919
dashboardsConfigMaps: {}
920
# default: ""
921
922
## Grafana's primary configuration
923
## NOTE: values in map will be converted to ini format
924
## ref: http://docs.grafana.org/installation/configuration/
925
##
926
grafana.ini:
927
paths:
928
data: /var/lib/grafana/
929
logs: /var/log/grafana
930
plugins: /var/lib/grafana/plugins
931
provisioning: /etc/grafana/provisioning
932
analytics:
933
check_for_updates: true
934
plugins:
935
preinstall_auto_update: "false"
936
log:
937
mode: console
938
server:
939
domain: "{{ if (and .Values.ingress.enabled .Values.ingress.hosts) }}{{ tpl (.Values.ingress.hosts | first) . }}{{ else if (and .Values.route.main.enabled .Values.route.main.hostnames) }}{{ tpl (.Values.route.main.hostnames | first) . }}{{ else }}''{{ end }}"
940
unified_storage:
941
index_path: /var/lib/grafana-search/bleve
942
## grafana Authentication can be enabled with the following values on grafana.ini
943
# server:
944
# The full public facing url you use in browser, used for redirects and emails
945
# root_url:
946
# https://grafana.com/docs/grafana/latest/auth/github/#enable-github-in-grafana
947
# auth.github:
948
# enabled: false
949
# allow_sign_up: false
950
# scopes: user:email,read:org
951
# auth_url: https://github.com/login/oauth/authorize
952
# token_url: https://github.com/login/oauth/access_token
953
# api_url: https://api.github.com/user
954
# team_ids:
955
# allowed_organizations:
956
# client_id:
957
# client_secret:
958
## LDAP Authentication can be enabled with the following values on grafana.ini
959
## NOTE: Grafana will fail to start if the value for ldap.toml is invalid
960
# auth.ldap:
961
# enabled: true
962
# allow_sign_up: true
963
# config_file: /etc/grafana/ldap.toml
964
## Grafana's alerting configuration
965
# unified_alerting:
966
# enabled: true
967
# rule_version_record_limit: "5"
968
969
## Grafana's LDAP configuration
970
## Templated by the template in _helpers.tpl
971
## NOTE: To enable the grafana.ini must be configured with auth.ldap.enabled
972
## ref: http://docs.grafana.org/installation/configuration/#auth-ldap
973
## ref: http://docs.grafana.org/installation/ldap/#configuration
974
ldap:
975
enabled: false
976
# `existingSecret` is a reference to an existing secret containing the ldap configuration
977
# for Grafana in a key `ldap-toml`.
978
existingSecret: ""
979
# `config` is the content of `ldap.toml` that will be stored in the created secret
980
config: ""
981
# config: |-
982
# verbose_logging = true
983
# [[servers]]
984
# host = "my-ldap-server"
985
# port = 636
986
# use_ssl = true
987
# start_tls = false
988
# ssl_skip_verify = false
989
# bind_dn = "uid=%s,ou=users,dc=myorg,dc=com"
990
991
# When process namespace sharing is enabled, processes in a container are visible to all other containers in the same pod
992
# This parameter is added because the ldap reload api is not working https://grafana.com/docs/grafana/latest/developers/http_api/admin/#reload-ldap-configuration
993
# To allow an extraContainer to restart the Grafana container
994
shareProcessNamespace: false
995
## Grafana's SMTP configuration
996
## NOTE: To enable, grafana.ini must be configured with smtp.enabled
997
## ref: http://docs.grafana.org/installation/configuration/#smtp
998
smtp:
999
# `existingSecret` is a reference to an existing secret containing the smtp configuration
1000
# for Grafana.
1001
existingSecret: ""
1002
userKey: "user"
1003
passwordKey: "password"
1004
## Sidecars that collect the configmaps with specified label and stores the included files them into the respective folders
1005
## Requires at least Grafana 5 to work and can't be used together with parameters dashboardProviders, datasources and dashboards
1006
sidecar:
1007
image:
1008
# -- The Docker registry
1009
registry: chainreg.biz
1010
repository: chainguard-private/k8s-sidecar
1011
tag: 2.11.2-r4
1012
sha: sha256:0371520c8bd8cada53d682b88aa3d7c10637934e74d266baaa0e30c0a1ac2f1a
1013
imagePullPolicy: IfNotPresent
1014
resources: {}
1015
# limits:
1016
# cpu: 100m
1017
# memory: 100Mi
1018
# requests:
1019
# cpu: 50m
1020
# memory: 50Mi
1021
securityContext:
1022
allowPrivilegeEscalation: false
1023
capabilities:
1024
drop:
1025
- ALL
1026
seccompProfile:
1027
type: RuntimeDefault
1028
readOnlyRootFilesystem: true
1029
# Set to true to skip tls verification for kube api calls. Can be overridden per sidecar
1030
# skipTlsVerify: true
1031
enableUniqueFilenames: false
1032
readinessProbe: {}
1033
livenessProbe: {}
1034
# Log level default for all sidecars. Can be one of: DEBUG, INFO, WARN, ERROR, CRITICAL. Defaults to INFO
1035
# logLevel: INFO
1036
alerts:
1037
enabled: false
1038
# Additional environment variables for the alerts sidecar
1039
env: {}
1040
## "valueFrom" environment variable references that will be added to deployment pods. Name is templated.
1041
## ref: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.19/#envvarsource-v1-core
1042
## Renders in container spec as:
1043
## env:
1044
## ...
1045
## - name: <key>
1046
## valueFrom:
1047
## <value rendered as YAML>
1048
envValueFrom: {}
1049
# ENV_NAME:
1050
# configMapKeyRef:
1051
# name: configmap-name
1052
# key: value_key
1053
# Do not reprocess already processed unchanged resources on k8s API reconnect.
1054
# ignoreAlreadyProcessed: true
1055
# Set to true to skip tls verification for kube api calls. Overrides sidecar.skipTlsVerify
1056
# skipTlsVerify: true
1057
# label that the configmaps with alert are marked with (can be templated)
1058
label: grafana_alert
1059
# value of label that the configmaps with alert are set to (can be templated)
1060
labelValue: ""
1061
# Log level. Can be one of: DEBUG, INFO, WARN, ERROR, CRITICAL.
1062
# logLevel: INFO
1063
# If specified, the sidecar will search for alert config-maps inside this namespace.
1064
# Otherwise the namespace in which the sidecar is running will be used.
1065
# It's also possible to specify ALL to search in all namespaces
1066
searchNamespace: null
1067
# Method to use to detect ConfigMap changes. With WATCH the sidecar will do a WATCH requests, with SLEEP it will list all ConfigMaps, then sleep for 60 seconds.
1068
watchMethod: WATCH
1069
# search in configmap, secret or both
1070
resource: both
1071
#
1072
# resourceName: comma separated list of resource names to be fetched/checked by this sidecar.
1073
# per default all resources of the type defined in {{ .Values.sidecar.alerts.resource }} will be checked.
1074
# This e.g. allows stricter RBAC rules which are limited to the resources meant for the sidecars.
1075
# resourceName: "secret/alerts-1,configmap/alerts-0"
1076
resourceName: ""
1077
#
1078
# watchServerTimeout: request to the server, asking it to cleanly close the connection after that.
1079
# defaults to 60sec; much higher values like 3600 seconds (1h) are feasible for non-Azure K8S
1080
# watchServerTimeout: 3600
1081
#
1082
# watchClientTimeout: is a client-side timeout, configuring your local socket.
1083
# If you have a network outage dropping all packets with no RST/FIN,
1084
# this is how long your client waits before realizing & dropping the connection.
1085
# defaults to 66sec (sic!)
1086
# watchClientTimeout: 60
1087
#
1088
# maxTotalRetries: Total number of retries to allow for any http request.
1089
# Takes precedence over other counts. Applies to all requests to reloadURL and k8s api requests.
1090
# Set to 0 to fail on the first retry.
1091
# maxTotalRetries: 5
1092
#
1093
# maxConnectRetries: How many connection-related errors to retry on for any http request.
1094
# These are errors raised before the request is sent to the remote server, which we assume has not triggered the server to process the request.
1095
# Applies to all requests to reloadURL and k8s api requests.
1096
# Set to 0 to fail on the first retry of this type.
1097
# maxConnectRetries: 10
1098
#
1099
# maxReadRetries: How many times to retry on read errors for any http request
1100
# These errors are raised after the request was sent to the server, so the request may have side-effects.
1101
# Applies to all requests to reloadURL and k8s api requests.
1102
# Set to 0 to fail on the first retry of this type.
1103
# maxReadRetries: 5
1104
#
1105
# Endpoint to send request to reload alerts
1106
reloadURL: "http://localhost:3000/api/admin/provisioning/alerting/reload"
1107
# Absolute path to a script to execute after a configmap got reloaded.
1108
# It runs before calls to REQ_URI. If the file is not executable it will be passed to sh.
1109
# Otherwise, it's executed as is. Shebangs known to work are #!/bin/sh and #!/usr/bin/env python
1110
script: null
1111
skipReload: false
1112
# This is needed if skipReload is true, to load any alerts defined at startup time.
1113
# Deploy the alert sidecar as an initContainer.
1114
initAlerts: false
1115
# Use native sidecar https://kubernetes.io/docs/concepts/workloads/pods/sidecar-containers/
1116
# restartPolicy: Always
1117
# # only applies to native sidecars
1118
# startupProbe:
1119
# httpGet:
1120
# path: /healthz
1121
# port: 8080
1122
# initialDelaySeconds: 5
1123
# periodSeconds: 5
1124
# failureThreshold: 60 # 5 minutes
1125
# Additional alerts sidecar volume mounts
1126
extraMounts: []
1127
# Sets the size limit of the alert sidecar emptyDir volume
1128
sizeLimit: ""
1129
dashboards:
1130
enabled: false
1131
# Additional environment variables for the dashboards sidecar
1132
env: {}
1133
## "valueFrom" environment variable references that will be added to deployment pods. Name is templated.
1134
## ref: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.19/#envvarsource-v1-core
1135
## Renders in container spec as:
1136
## env:
1137
## ...
1138
## - name: <key>
1139
## valueFrom:
1140
## <value rendered as YAML>
1141
envValueFrom: {}
1142
# ENV_NAME:
1143
# configMapKeyRef:
1144
# name: configmap-name
1145
# key: value_key
1146
# Do not reprocess already processed unchanged resources on k8s API reconnect.
1147
# ignoreAlreadyProcessed: true
1148
# Set to true to skip tls verification for kube api calls. Overrides sidecar.skipTlsVerify
1149
# skipTlsVerify: true
1150
SCProvider: true
1151
# label that the configmaps with dashboards are marked with (can be templated)
1152
label: grafana_dashboard
1153
# value of label that the configmaps with dashboards are set to (can be templated)
1154
labelValue: ""
1155
# Log level. Can be one of: DEBUG, INFO, WARN, ERROR, CRITICAL.
1156
# logLevel: INFO
1157
# folder in the pod that should hold the collected dashboards (unless `defaultFolderName` is set)
1158
folder: /tmp/dashboards
1159
# The default folder name, it will create a subfolder under the `folder` and put dashboards in there instead
1160
defaultFolderName: null
1161
# Namespaces list. If specified, the sidecar will search for config-maps/secrets inside these namespaces.
1162
# Otherwise the namespace in which the sidecar is running will be used.
1163
# It's also possible to specify ALL to search in all namespaces.
1164
searchNamespace: null
1165
# Method to use to detect ConfigMap changes. With WATCH the sidecar will do a WATCH requests, with SLEEP it will list all ConfigMaps, then sleep for 60 seconds.
1166
watchMethod: WATCH
1167
# search in configmap, secret or both
1168
resource: both
1169
# If specified, the sidecar will look for annotation with this name to create folder and put graph here.
1170
# You can use this parameter together with `provider.foldersFromFilesStructure`to annotate configmaps and create folder structure.
1171
folderAnnotation: null
1172
#
1173
# resourceName: comma separated list of resource names to be fetched/checked by this sidecar.
1174
# per default all resources of the type defined in {{ .Values.sidecar.dashboards.resource }} will be checked.
1175
# This e.g. allows stricter RBAC rules which are limited to the resources meant for the sidecars.
1176
# resourceName: "secret/dashboards-0,configmap/dashboards-1"
1177
resourceName: ""
1178
#
1179
# maxTotalRetries: Total number of retries to allow for any http request.
1180
# Takes precedence over other counts. Applies to all requests to reloadURL and k8s api requests.
1181
# Set to 0 to fail on the first retry.
1182
# maxTotalRetries: 5
1183
#
1184
# maxConnectRetries: How many connection-related errors to retry on for any http request.
1185
# These are errors raised before the request is sent to the remote server, which we assume has not triggered the server to process the request.
1186
# Applies to all requests to reloadURL and k8s api requests.
1187
# Set to 0 to fail on the first retry of this type.
1188
# maxConnectRetries: 10
1189
#
1190
# maxReadRetries: How many times to retry on read errors for any http request
1191
# These errors are raised after the request was sent to the server, so the request may have side-effects.
1192
# Applies to all requests to reloadURL and k8s api requests.
1193
# Set to 0 to fail on the first retry of this type.
1194
# maxReadRetries: 5
1195
#
1196
# Endpoint to send request to reload alerts
1197
reloadURL: "http://localhost:3000/api/admin/provisioning/dashboards/reload"
1198
# Absolute path to a script to execute after a configmap got reloaded.
1199
# It runs before calls to REQ_URI. If the file is not executable it will be passed to sh.
1200
# Otherwise, it's executed as is. Shebangs known to work are #!/bin/sh and #!/usr/bin/env python
1201
script: null
1202
skipReload: false
1203
# This is needed if skipReload is true, to load any dashboards defined at startup time.
1204
# Deploy the dashboard sidecar as an initContainer.
1205
initDashboards: false
1206
# Use native sidecar https://kubernetes.io/docs/concepts/workloads/pods/sidecar-containers/
1207
# restartPolicy: Always
1208
# # only applies to native sidecars
1209
# startupProbe:
1210
# httpGet:
1211
# path: /healthz
1212
# port: 8083
1213
# initialDelaySeconds: 5
1214
# periodSeconds: 5
1215
# failureThreshold: 60 # 5 minutes
1216
# watchServerTimeout: request to the server, asking it to cleanly close the connection after that.
1217
# defaults to 60sec; much higher values like 3600 seconds (1h) are feasible for non-Azure K8S
1218
# watchServerTimeout: 3600
1219
#
1220
# watchClientTimeout: is a client-side timeout, configuring your local socket.
1221
# If you have a network outage dropping all packets with no RST/FIN,
1222
# this is how long your client waits before realizing & dropping the connection.
1223
# defaults to 66sec (sic!)
1224
# watchClientTimeout: 60
1225
#
1226
# provider configuration that lets grafana manage the dashboards
1227
provider:
1228
# name of the provider, should be unique
1229
name: sidecarProvider
1230
# orgid as configured in grafana
1231
orgid: 1
1232
# folder in which the dashboards should be imported in grafana
1233
folder: ''
1234
# <string> folder UID. will be automatically generated if not specified
1235
folderUid: ''
1236
# type of the provider
1237
type: file
1238
# disableDelete to activate a import-only behaviour
1239
disableDelete: false
1240
# allow updating provisioned dashboards from the UI
1241
allowUiUpdates: false
1242
# allow Grafana to replicate dashboard structure from filesystem
1243
foldersFromFilesStructure: false
1244
# Additional dashboards sidecar volume mounts
1245
extraMounts: []
1246
# Sets the size limit of the dashboard sidecar emptyDir volume
1247
sizeLimit: ""
1248
datasources:
1249
enabled: false
1250
# Additional environment variables for the datasourcessidecar
1251
env: {}
1252
## "valueFrom" environment variable references that will be added to deployment pods. Name is templated.
1253
## ref: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.19/#envvarsource-v1-core
1254
## Renders in container spec as:
1255
## env:
1256
## ...
1257
## - name: <key>
1258
## valueFrom:
1259
## <value rendered as YAML>
1260
envValueFrom: {}
1261
# ENV_NAME:
1262
# configMapKeyRef:
1263
# name: configmap-name
1264
# key: value_key
1265
# Do not reprocess already processed unchanged resources on k8s API reconnect.
1266
# ignoreAlreadyProcessed: true
1267
# Set to true to skip tls verification for kube api calls. Overrides sidecar.skipTlsVerify
1268
# skipTlsVerify: true
1269
# label that the configmaps with datasources are marked with (can be templated)
1270
label: grafana_datasource
1271
# value of label that the configmaps with datasources are set to (can be templated)
1272
labelValue: ""
1273
# Log level. Can be one of: DEBUG, INFO, WARN, ERROR, CRITICAL.
1274
# logLevel: INFO
1275
# If specified, the sidecar will search for datasource config-maps inside this namespace.
1276
# Otherwise the namespace in which the sidecar is running will be used.
1277
# It's also possible to specify ALL to search in all namespaces
1278
searchNamespace: null
1279
# Method to use to detect ConfigMap changes. With WATCH the sidecar will do a WATCH requests, with SLEEP it will list all ConfigMaps, then sleep for 60 seconds.
1280
watchMethod: WATCH
1281
# search in configmap, secret or both
1282
resource: both
1283
#
1284
# resourceName: comma separated list of resource names to be fetched/checked by this sidecar.
1285
# per default all resources of the type defined in {{ .Values.sidecar.datasources.resource }} will be checked.
1286
# This e.g. allows stricter RBAC rules which are limited to the resources meant for the sidecars.
1287
# resourceName: "secret/datasources-0,configmap/datasources-15"
1288
resourceName: ""
1289
#
1290
# watchServerTimeout: request to the server, asking it to cleanly close the connection after that.
1291
# defaults to 60sec; much higher values like 3600 seconds (1h) are feasible for non-Azure K8S
1292
# watchServerTimeout: 3600
1293
#
1294
# watchClientTimeout: is a client-side timeout, configuring your local socket.
1295
# If you have a network outage dropping all packets with no RST/FIN,
1296
# this is how long your client waits before realizing & dropping the connection.
1297
# defaults to 66sec (sic!)
1298
# watchClientTimeout: 60
1299
#
1300
# maxTotalRetries: Total number of retries to allow for any http request.
1301
# Takes precedence over other counts. Applies to all requests to reloadURL and k8s api requests.
1302
# Set to 0 to fail on the first retry.
1303
# maxTotalRetries: 5
1304
#
1305
# maxConnectRetries: How many connection-related errors to retry on for any http request.
1306
# These are errors raised before the request is sent to the remote server, which we assume has not triggered the server to process the request.
1307
# Applies to all requests to reloadURL and k8s api requests.
1308
# Set to 0 to fail on the first retry of this type.
1309
# maxConnectRetries: 10
1310
#
1311
# maxReadRetries: How many times to retry on read errors for any http request
1312
# These errors are raised after the request was sent to the server, so the request may have side-effects.
1313
# Applies to all requests to reloadURL and k8s api requests.
1314
# Set to 0 to fail on the first retry of this type.
1315
# maxReadRetries: 5
1316
#
1317
# Endpoint to send request to reload datasources
1318
reloadURL: "http://localhost:3000/api/admin/provisioning/datasources/reload"
1319
# Absolute path to a script to execute after a configmap got reloaded.
1320
# It runs before calls to REQ_URI. If the file is not executable it will be passed to sh.
1321
# Otherwise, it's executed as is. Shebangs known to work are #!/bin/sh and #!/usr/bin/env python
1322
script: null
1323
skipReload: false
1324
# This is needed if skipReload is true, to load any datasources defined at startup time.
1325
# Deploy the datasources sidecar as an initContainer.
1326
initDatasources: false
1327
# Use native sidecar https://kubernetes.io/docs/concepts/workloads/pods/sidecar-containers/
1328
# restartPolicy: Always
1329
# # only applies to native sidecars
1330
# startupProbe:
1331
# httpGet:
1332
# path: /healthz
1333
# port: 8081
1334
# initialDelaySeconds: 5
1335
# periodSeconds: 5
1336
# failureThreshold: 60 # 5 minutes
1337
# Additional datasources sidecar volume mounts
1338
extraMounts: []
1339
# Sets the size limit of the datasource sidecar emptyDir volume
1340
sizeLimit: ""
1341
plugins:
1342
enabled: false
1343
# Additional environment variables for the plugins sidecar
1344
env: {}
1345
# Do not reprocess already processed unchanged resources on k8s API reconnect.
1346
# ignoreAlreadyProcessed: true
1347
# Set to true to skip tls verification for kube api calls. Overrides sidecar.skipTlsVerify
1348
# skipTlsVerify: true
1349
# label that the configmaps with plugins are marked with (can be templated)
1350
label: grafana_plugin
1351
# value of label that the configmaps with plugins are set to (can be templated)
1352
labelValue: ""
1353
# Log level. Can be one of: DEBUG, INFO, WARN, ERROR, CRITICAL.
1354
# logLevel: INFO
1355
# If specified, the sidecar will search for plugin config-maps inside this namespace.
1356
# Otherwise the namespace in which the sidecar is running will be used.
1357
# It's also possible to specify ALL to search in all namespaces
1358
searchNamespace: null
1359
# Method to use to detect ConfigMap changes. With WATCH the sidecar will do a WATCH requests, with SLEEP it will list all ConfigMaps, then sleep for 60 seconds.
1360
watchMethod: WATCH
1361
# search in configmap, secret or both
1362
resource: both
1363
#
1364
# resourceName: comma separated list of resource names to be fetched/checked by this sidecar.
1365
# per default all resources of the type defined in {{ .Values.sidecar.plugins.resource }} will be checked.
1366
# This e.g. allows stricter RBAC rules which are limited to the resources meant for the sidecars.
1367
# resourceName: "secret/plugins-0,configmap/plugins-1"
1368
resourceName: ""
1369
#
1370
# watchServerTimeout: request to the server, asking it to cleanly close the connection after that.
1371
# defaults to 60sec; much higher values like 3600 seconds (1h) are feasible for non-Azure K8S
1372
# watchServerTimeout: 3600
1373
#
1374
# watchClientTimeout: is a client-side timeout, configuring your local socket.
1375
# If you have a network outage dropping all packets with no RST/FIN,
1376
# this is how long your client waits before realizing & dropping the connection.
1377
# defaults to 66sec (sic!)
1378
# watchClientTimeout: 60
1379
#
1380
# maxTotalRetries: Total number of retries to allow for any http request.
1381
# Takes precedence over other counts. Applies to all requests to reloadURL and k8s api requests.
1382
# Set to 0 to fail on the first retry.
1383
# maxTotalRetries: 5
1384
#
1385
# maxConnectRetries: How many connection-related errors to retry on for any http request.
1386
# These are errors raised before the request is sent to the remote server, which we assume has not triggered the server to process the request.
1387
# Applies to all requests to reloadURL and k8s api requests.
1388
# Set to 0 to fail on the first retry of this type.
1389
# maxConnectRetries: 10
1390
#
1391
# maxReadRetries: How many times to retry on read errors for any http request
1392
# These errors are raised after the request was sent to the server, so the request may have side-effects.
1393
# Applies to all requests to reloadURL and k8s api requests.
1394
# Set to 0 to fail on the first retry of this type.
1395
# maxReadRetries: 5
1396
#
1397
# Endpoint to send request to reload plugins
1398
reloadURL: "http://localhost:3000/api/admin/provisioning/plugins/reload"
1399
# Absolute path to a script to execute after a configmap got reloaded.
1400
# It runs before calls to REQ_URI. If the file is not executable it will be passed to sh.
1401
# Otherwise, it's executed as is. Shebangs known to work are #!/bin/sh and #!/usr/bin/env python
1402
script: null
1403
skipReload: false
1404
# Deploy the datasource sidecar as an initContainer in addition to a container.
1405
# This is needed if skipReload is true, to load any plugins defined at startup time.
1406
initPlugins: false
1407
# Additional plugins sidecar volume mounts
1408
extraMounts: []
1409
# Sets the size limit of the plugin sidecar emptyDir volume
1410
sizeLimit: ""
1411
notifiers:
1412
enabled: false
1413
# Additional environment variables for the notifierssidecar
1414
env: {}
1415
# Do not reprocess already processed unchanged resources on k8s API reconnect.
1416
# ignoreAlreadyProcessed: true
1417
# Set to true to skip tls verification for kube api calls. Overrides sidecar.skipTlsVerify
1418
# skipTlsVerify: true
1419
# label that the configmaps with notifiers are marked with (can be templated)
1420
label: grafana_notifier
1421
# value of label that the configmaps with notifiers are set to (can be templated)
1422
labelValue: ""
1423
# Log level. Can be one of: DEBUG, INFO, WARN, ERROR, CRITICAL.
1424
# logLevel: INFO
1425
# If specified, the sidecar will search for notifier config-maps inside this namespace.
1426
# Otherwise the namespace in which the sidecar is running will be used.
1427
# It's also possible to specify ALL to search in all namespaces
1428
searchNamespace: null
1429
# Method to use to detect ConfigMap changes. With WATCH the sidecar will do a WATCH requests, with SLEEP it will list all ConfigMaps, then sleep for 60 seconds.
1430
watchMethod: WATCH
1431
# search in configmap, secret or both
1432
resource: both
1433
#
1434
# resourceName: comma separated list of resource names to be fetched/checked by this sidecar.
1435
# per default all resources of the type defined in {{ .Values.sidecar.notifiers.resource }} will be checked.
1436
# This e.g. allows stricter RBAC rules which are limited to the resources meant for the sidecars.
1437
# resourceName: "secret/notifiers-2,configmap/notifiers-1"
1438
resourceName: ""
1439
#
1440
# watchServerTimeout: request to the server, asking it to cleanly close the connection after that.
1441
# defaults to 60sec; much higher values like 3600 seconds (1h) are feasible for non-Azure K8S
1442
# watchServerTimeout: 3600
1443
#
1444
# watchClientTimeout: is a client-side timeout, configuring your local socket.
1445
# If you have a network outage dropping all packets with no RST/FIN,
1446
# this is how long your client waits before realizing & dropping the connection.
1447
# defaults to 66sec (sic!)
1448
# watchClientTimeout: 60
1449
#
1450
# maxTotalRetries: Total number of retries to allow for any http request.
1451
# Takes precedence over other counts. Applies to all requests to reloadURL and k8s api requests.
1452
# Set to 0 to fail on the first retry.
1453
# maxTotalRetries: 5
1454
#
1455
# maxConnectRetries: How many connection-related errors to retry on for any http request.
1456
# These are errors raised before the request is sent to the remote server, which we assume has not triggered the server to process the request.
1457
# Applies to all requests to reloadURL and k8s api requests.
1458
# Set to 0 to fail on the first retry of this type.
1459
# maxConnectRetries: 10
1460
#
1461
# maxReadRetries: How many times to retry on read errors for any http request
1462
# These errors are raised after the request was sent to the server, so the request may have side-effects.
1463
# Applies to all requests to reloadURL and k8s api requests.
1464
# Set to 0 to fail on the first retry of this type.
1465
# maxReadRetries: 5
1466
#
1467
# Endpoint to send request to reload notifiers
1468
reloadURL: "http://localhost:3000/api/admin/provisioning/notifications/reload"
1469
# Absolute path to a script to execute after a configmap got reloaded.
1470
# It runs before calls to REQ_URI. If the file is not executable it will be passed to sh.
1471
# Otherwise, it's executed as is. Shebangs known to work are #!/bin/sh and #!/usr/bin/env python
1472
script: null
1473
skipReload: false
1474
# Deploy the notifier sidecar as an initContainer in addition to a container.
1475
# This is needed if skipReload is true, to load any notifiers defined at startup time.
1476
initNotifiers: false
1477
# Use native sidecar https://kubernetes.io/docs/concepts/workloads/pods/sidecar-containers/
1478
# restartPolicy: Always
1479
# # only applies to native sidecars
1480
# startupProbe:
1481
# httpGet:
1482
# path: /healthz
1483
# port: 8082
1484
# initialDelaySeconds: 5
1485
# periodSeconds: 5
1486
# failureThreshold: 60 # 5 minutes
1487
# Additional notifiers sidecar volume mounts
1488
extraMounts: []
1489
# Sets the size limit of the notifier sidecar emptyDir volume
1490
sizeLimit: ""
1491
## Override the deployment namespace
1492
##
1493
namespaceOverride: ""
1494
## Number of old ReplicaSets to retain
1495
##
1496
revisionHistoryLimit: 10
1497
## Add a separate remote image renderer deployment/service
1498
imageRenderer:
1499
deploymentStrategy: {}
1500
## The maximum time in seconds for the image renderer Deployment to make progress before it is
1501
## considered to be failed.
1502
## ref: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#progress-deadline-seconds
1503
progressDeadlineSeconds: null
1504
# Enable the image-renderer deployment & service
1505
enabled: false
1506
replicas: 1
1507
autoscaling:
1508
enabled: false
1509
minReplicas: 1
1510
maxReplicas: 5
1511
targetCPU: "60"
1512
targetMemory: ""
1513
behavior: {}
1514
# The url of remote image renderer if it is not in the same namespace with the grafana instance
1515
serverURL: ""
1516
# The callback url of grafana instances if it is not in the same namespace with the remote image renderer
1517
renderingCallbackURL: ""
1518
# Token used for authentication between Grafana and the remote image renderer.
1519
token: ""
1520
# Use an existing secret for the image renderer token. Must contain a key named "token".
1521
existingSecret: ""
1522
image:
1523
# -- The Docker registry
1524
registry: chainreg.biz
1525
# image-renderer Image repository
1526
repository: chainguard-private/grafana-image-renderer
1527
# image-renderer Image tag
1528
tag: 5.12.5-r0
1529
# image-renderer Image sha (optional)
1530
sha: sha256:a2fc4cf4fd92caeb2058ef24863f9adc17ebbc2666a63ceb240cea92ce4b8eb0
1531
# image-renderer Image pull secrets (optional)
1532
pullSecrets: []
1533
# image-renderer ImagePullPolicy
1534
pullPolicy: Always
1535
dnsPolicy: ~
1536
dnsConfig: {}
1537
# nameservers:
1538
# - 8.8.8.8
1539
# options:
1540
# - name: ndots
1541
# value: "2"
1542
# - name: edns0
1543
# extra environment variables
1544
env:
1545
HTTP_HOST: "0.0.0.0"
1546
# Fixes "Error: Failed to launch the browser process!\nchrome_crashpad_handler: --database is required"
1547
XDG_CONFIG_HOME: /tmp/.chromium
1548
XDG_CACHE_HOME: /tmp/.chromium
1549
# RENDERING_ARGS: --no-sandbox,--disable-gpu,--window-size=1280x758
1550
# RENDERING_MODE: clustered
1551
# IGNORE_HTTPS_ERRORS: true
1552
## "valueFrom" environment variable references that will be added to deployment pods. Name is templated.
1553
## ref: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.19/#envvarsource-v1-core
1554
## Renders in container spec as:
1555
## env:
1556
## ...
1557
## - name: <key>
1558
## valueFrom:
1559
## <value rendered as YAML>
1560
envValueFrom: {}
1561
# ENV_NAME:
1562
# configMapKeyRef:
1563
# name: configmap-name
1564
# key: value_key
1565
1566
# image-renderer deployment serviceAccount
1567
serviceAccountName: ""
1568
automountServiceAccountToken: false
1569
# image-renderer deployment hostUsers
1570
hostUsers: ~
1571
# image-renderer deployment securityContext
1572
securityContext:
1573
runAsNonRoot: true
1574
runAsUser: 1000
1575
runAsGroup: 1000
1576
seccompProfile:
1577
type: RuntimeDefault
1578
# image-renderer deployment container securityContext
1579
containerSecurityContext:
1580
runAsNonRoot: true
1581
seccompProfile:
1582
type: RuntimeDefault
1583
capabilities:
1584
drop: ['ALL']
1585
allowPrivilegeEscalation: false
1586
privileged: false
1587
readOnlyRootFilesystem: true
1588
## image-renderer pod annotation
1589
podAnnotations: {}
1590
# image-renderer deployment Host Aliases
1591
hostAliases: []
1592
# image-renderer deployment priority class
1593
priorityClassName: ''
1594
# Path to the healthcheck endpoint. On Image Renderer v5.0.0 or newer, this is '/healthz'. Older versions use '/'.
1595
healthcheckPath: '/healthz'
1596
service:
1597
# Enable the image-renderer service
1598
enabled: true
1599
# image-renderer service port name
1600
portName: 'http'
1601
# image-renderer service port used by both service and deployment
1602
port: 8081
1603
targetPort: 8081
1604
# Adds the appProtocol field to the image-renderer service. This allows to work with istio protocol selection. Ex: "http" or "tcp"
1605
appProtocol: ""
1606
serviceMonitor:
1607
## If true, a ServiceMonitor CRD is created for a prometheus operator
1608
## https://github.com/coreos/prometheus-operator
1609
##
1610
enabled: false
1611
path: /metrics
1612
# namespace: monitoring (defaults to use the namespace this chart is deployed to)
1613
labels: {}
1614
# Set these to override the Prometheus global scrape interval/timeout.
1615
# interval: 1m
1616
# scrapeTimeout: 30s
1617
scheme: http
1618
tlsConfig: {}
1619
relabelings: []
1620
# See: https://doc.crds.dev/github.com/prometheus-operator/kube-prometheus/monitoring.coreos.com/ServiceMonitor/v1@v0.11.0#spec-targetLabels
1621
targetLabels: []
1622
# - targetLabel1
1623
# - targetLabel2
1624
# If https is enabled in Grafana, this needs to be set as 'https' to correctly configure the callback used in Grafana
1625
grafanaProtocol: http
1626
# In case a sub_path is used this needs to be added to the image renderer callback
1627
grafanaSubPath: ""
1628
# name of the image-renderer port on the pod
1629
podPortName: http
1630
# number of image-renderer replica sets to keep
1631
revisionHistoryLimit: 10
1632
networkPolicy:
1633
# Enable a NetworkPolicy to limit inbound traffic to only the created grafana pods
1634
limitIngress: true
1635
# Enable a NetworkPolicy to limit outbound traffic to only the created grafana pods
1636
limitEgress: false
1637
# Allow additional services to access image-renderer (eg. Prometheus operator when ServiceMonitor is enabled)
1638
extraIngressSelectors: []
1639
resources: {}
1640
# limits:
1641
# cpu: 100m
1642
# memory: 100Mi
1643
# requests:
1644
# cpu: 50m
1645
# memory: 50Mi
1646
## Node labels for pod assignment
1647
## ref: https://kubernetes.io/docs/user-guide/node-selection/
1648
#
1649
nodeSelector: {}
1650
## Tolerations for pod assignment
1651
## ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/
1652
##
1653
tolerations: []
1654
## Affinity for pod assignment (evaluated as template)
1655
## ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity
1656
##
1657
affinity: {}
1658
## Use an alternate scheduler, e.g. "stork".
1659
## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/
1660
##
1661
# schedulerName: "default-scheduler"
1662
1663
# Extra configmaps to mount in image-renderer pods
1664
extraConfigmapMounts: []
1665
# Extra secrets to mount in image-renderer pods
1666
extraSecretMounts: []
1667
# Extra volumes to mount in image-renderer pods
1668
extraVolumeMounts: []
1669
# Extra volumes for image-renderer pods
1670
extraVolumes: []
1671
networkPolicy:
1672
# -- networkPolicy.enabled Enable creation of NetworkPolicy resources. Only Ingress traffic is filtered for now.
1673
enabled: false
1674
# --networkPolicy.allowExternal Don't require client label for connections
1675
# The Policy model to apply. When set to false, only pods with the correct
1676
# client label will have network access to grafana port defined.
1677
# When true, grafana will accept connections from any source
1678
# (with the correct destination port).
1679
#
1680
ingress: true
1681
# -- networkPolicy.ingress When true enables the creation
1682
# an ingress network policy
1683
allowExternal: true
1684
# -- networkPolicy.explicitNamespacesSelector A Kubernetes LabelSelector to explicitly select namespaces from which traffic could be allowed
1685
# If explicitNamespacesSelector is missing or set to {}, only client Pods that are in the networkPolicy's namespace
1686
# and that match other criteria, the ones that have the good label, can reach the grafana.
1687
# But sometimes, we want the grafana to be accessible to clients from other namespaces, in this case, we can use this
1688
# LabelSelector to select these namespaces, note that the networkPolicy's namespace should also be explicitly added.
1689
# </br>
1690
#
1691
# Example:
1692
#
1693
# ```
1694
# explicitNamespacesSelector:
1695
# matchLabels:
1696
# role: frontend
1697
# matchExpressions:
1698
# - {key: role, operator: In, values: [frontend]}
1699
# ```
1700
explicitNamespacesSelector: {}
1701
# -- networkPolicy.explicitIpBlocks List of CIDR blocks allowed as ingress sources.
1702
# Each entry must be a valid CIDR notation string (e.g. 10.0.0.0/8).
1703
# When defined, the specified CIDR ranges are added to the ingress `from` rules
1704
# using `ipBlock` entries and complement the other configured ingress sources.
1705
# </br>
1706
#
1707
# Example:
1708
#
1709
# ```
1710
# explicitIpBlocks:
1711
# - 35.191.0.0/16
1712
# - 130.211.0.0/22
1713
# ```
1714
#
1715
explicitIpBlocks: []
1716
egress:
1717
# -- networkPolicy.egress.enabled When enabled, an egress network policy will be
1718
# created allowing grafana to connect to external data sources from kubernetes cluster.
1719
enabled: false
1720
# -- networkPolicy.egress.blockDNSResolution When enabled, DNS resolution will be blocked
1721
# for all pods in the grafana namespace.
1722
blockDNSResolution: false
1723
# -- networkPolicy.egress.ports Add individual ports to be allowed by the egress
1724
ports: []
1725
# Add ports to the egress by specifying - port: <port number>
1726
# E.X.
1727
# - port: 80
1728
# - port: 443
1729
#
1730
# -- networkPolicy.egress.to Allow egress traffic to specific destinations
1731
to: []
1732
# -- destinations to the egress by specifying - ipBlock: <CIDR>
1733
# E.X.
1734
# to:
1735
# - namespaceSelector:
1736
# matchExpressions:
1737
# - {key: role, operator: In, values: [grafana]}
1738
# Enable backward compatibility of kubernetes where version below 1.13 doesn't have the enableServiceLinks option
1739
enableKubeBackwardCompatibility: false
1740
useStatefulSet: false
1741
# extraObjects could be utilized to add dynamic manifests via values
1742
extraObjects: []
1743
# Examples:
1744
# extraObjects:
1745
# - apiVersion: kubernetes-client.io/v1
1746
# kind: ExternalSecret
1747
# metadata:
1748
# name: grafana-secrets-{{ .Release.Name }}
1749
# spec:
1750
# backendType: gcpSecretsManager
1751
# data:
1752
# - key: grafana-admin-password
1753
# name: adminPassword
1754
# Alternatively, you can use strings, which lets you use additional templating features:
1755
# extraObjects:
1756
# - |
1757
# apiVersion: kubernetes-client.io/v1
1758
# kind: ExternalSecret
1759
# metadata:
1760
# name: grafana-secrets-{{ .Release.Name }}
1761
# spec:
1762
# backendType: gcpSecretsManager
1763
# data:
1764
# - key: grafana-admin-password
1765
# name: {{ include "some-other-template" }}
1766
1767
# assertNoLeakedSecrets is a helper function defined in _helpers.tpl that checks if secret
1768
# values are not exposed in the rendered grafana.ini configmap. It is enabled by default.
1769
#
1770
# To pass values into grafana.ini without exposing them in a configmap, use variable expansion:
1771
# https://grafana.com/docs/grafana/latest/setup-grafana/configure-grafana/#variable-expansion
1772
#
1773
# Alternatively, if you wish to allow secret values to be exposed in the rendered grafana.ini configmap,
1774
# you can disable this check by setting assertNoLeakedSecrets to false.
1775
assertNoLeakedSecrets: true
1776
# updateMode options are:
1777
# Off: n the Off update mode, the VPA recommender still analyzes resource usage and generates recommendations, but these recommendations are not automatically applied to Pods. The recommendations are only stored in the VPA object's .status field.
1778
# Initial: In Initial mode, VPA only sets resource requests when Pods are first created. It does not update resources for already running Pods, even if recommendations change over time. The recommendations apply only during Pod creation.
1779
# Recreate: In Recreate mode, VPA actively manages Pod resources by evicting Pods when their current resource requests differ significantly from recommendations. When a Pod is evicted, the workload controller (managing a Deployment, StatefulSet, etc) creates a replacement Pod, and the VPA admission controller applies the updated resource requests to the new Pod.
1780
# InPlaceOrRecreate: In Recreate mode, VPA actively manages Pod resources by evicting Pods when their current resource requests differ significantly from recommendations. When a Pod is evicted, the workload controller (managing a Deployment, StatefulSet, etc) creates a replacement Pod, and the VPA admission controller applies the updated resource requests to the new Pod.
1781
# Auto (deprecated): The Auto update mode is deprecated since VPA version 1.4.0. Use Recreate for eviction-based updates, or InPlaceOrRecreate for in-place updates with eviction fallback.
1782
verticalPodAutoscaler:
1783
enabled: false
1784
updateMode: "Off"
1785
controlledResources:
1786
cpu: true
1787
memory: true
1788
# Default safety bounds
1789
minAllowed:
1790
cpu: "25m"
1791
memory: "128Mi"
1792
maxAllowed:
1793
cpu: "1000m"
1794
memory: "1Gi"
1795

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.