1# Default values for coredns.
2# This is a YAML-formatted file.
3# Declare variables to be passed into your templates.
6 repository: chainreg.biz/chainguard-private/coredns
7 # Overrides the image tag whose default is the chart appVersion.
8 tag: 1.14.7-r6@sha256:8b9542f4cb711770cbe6a4232e990fef56e48009b7175e882481a67f5bebf496
9 pullPolicy: IfNotPresent
10 ## Optionally specify an array of imagePullSecrets.
11 ## Secrets must be manually created in the namespace.
12 ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
16 # - name: myRegistryKeySecretName
28terminationGracePeriodSeconds: 30
30# cluster-autoscaler.kubernetes.io/safe-to-evict: "false"
33serviceType: "ClusterIP"
38 prometheus.io/scrape: "true"
39 prometheus.io/port: "9153"
57 # loadBalancerClass: ""
59 # externalTrafficPolicy: ""
61 # trafficDistribution: PreferClose
62 # The name of the Service
63 # If not set, a name is generated using the fullname template
70 # The name of the ServiceAccount to use
71 # If not set and create is true, a name is generated using the fullname template
75 # If true, create & use RBAC resources
78 # By default a name is generated using the fullname template.
79 # Override here if desired:
81# isClusterService specifies whether chart should be deployed as cluster-service or normal k8s app.
83# Optional priority class to be used for the coredns pods. Used for autoscaler if autoscaler.priorityClassName not set.
85# Configure the pod level securityContext.
87# Configure SecurityContext for the CoreDNS container.
88# The defaults satisfy the `restricted` Pod Security Standard, so the chart
89# installs into a namespace that enforces it.
90# Ensure that required linux capability to bind port number below 1024 is assigned (`CAP_NET_BIND_SERVICE`).
91# The CoreDNS image runs as the distroless `nonroot` user (uid/gid 65532) since
92# 1.11.0. The numeric ids are set here because images before 1.14.7 declare the
93# user by name, which the kubelet cannot verify when `runAsNonRoot` is true.
95 allowPrivilegeEscalation: false
101 readOnlyRootFilesystem: true
107# Default zone is what Kubernetes recommends:
108# https://kubernetes.io/docs/tasks/administer-cluster/dns-custom-nameservers/#coredns-configmap-options
114 # -- expose the service on a different port
116 # If serviceType is nodePort you can specify nodePort here
121 # Serves a /health endpoint on :8080, required for livenessProbe
125 # Serves a /ready endpoint on :8181, required for readinessProbe
127 # Required to query kubernetes API for data
129 parameters: cluster.local in-addr.arpa ip6.arpa
132 fallthrough in-addr.arpa ip6.arpa
134 # Serves a /metrics endpoint on :9153, required for serviceMonitor
136 parameters: 0.0.0.0:9153
138 parameters: . /etc/resolv.conf
144# Complete example with all the options:
145# - zones: # the `zones` block can be left out entirely, defaults to "."
146# - zone: hello.world. # optional, defaults to "."
147# scheme: tls:// # optional, defaults to "" (which equals "dns://" in CoreDNS)
150# use_tcp: true # set this parameter to optionally expose the port on tcp as well as udp for the DNS protocol
151# # Note that this will not work if you are also exposing tls or grpc on the same server
152# port: 12345 # optional, defaults to "" (which equals 53 in CoreDNS)
153# plugins: # the plugins to use for this server block
154# - name: kubernetes # name of plugin, if used multiple times ensure that the plugin supports it!
155# parameters: foo bar # list of parameters after the plugin
156# configBlock: |- # if the plugin supports extra block style config, supply it here
160# Extra configuration that is applied outside of the default zone block.
161# Example to include additional config files, which may come from extraVolumes:
164# parameters: /opt/coredns/*.conf
166# To use the livenessProbe, the health plugin needs to be enabled in CoreDNS' server config
169 initialDelaySeconds: 60
174# To use the readinessProbe, the ready plugin needs to be enabled in CoreDNS' server config
177 initialDelaySeconds: 30
182# expects input structure as per specification https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.11/#affinity-v1-core
186# requiredDuringSchedulingIgnoredDuringExecution:
189# - key: foo.bar.com/role
194# expects input structure as per specification https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.21/#topologyspreadconstraint-v1-core
195# and supports Helm templating.
197# topologySpreadConstraints:
200# app.kubernetes.io/name: '{{ template "coredns.name" . }}'
201# app.kubernetes.io/instance: '{{ .Release.Name }}'
202# topologyKey: topology.kubernetes.io/zone
204# whenUnsatisfiable: ScheduleAnyway
207# app.kubernetes.io/name: '{{ template "coredns.name" . }}'
208# app.kubernetes.io/instance: '{{ .Release.Name }}'
209# topologyKey: kubernetes.io/hostname
211# whenUnsatisfiable: ScheduleAnyway
212topologySpreadConstraints: []
213# Node labels for pod assignment
214# Ref: https://kubernetes.io/docs/user-guide/node-selection/
216# expects input structure as per specification https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.11/#toleration-v1-core
219# - key: foo.bar.com/role
224# https://kubernetes.io/docs/tasks/run-application/configure-pdb/#specifying-a-poddisruptionbudget
225podDisruptionBudget: {}
226# configure custom zone files as per https://coredns.io/2017/05/08/custom-dns-entries-for-kubernetes/
228# - filename: example.db
231# example.com. IN SOA sns.dns.icann.com. noc.dns.icann.com. 2015082541 7200 3600 1209600 3600
232# example.com. IN NS b.iana-servers.net.
233# example.com. IN NS a.iana-servers.net.
234# example.com. IN A 192.168.99.102
235# *.example.com. IN A 192.168.99.102
237# optional array of sidecar containers
239# - name: some-container-name
240# image: some-image:latest
241# imagePullPolicy: Always
242# optional array of extra volumes to create
244# - name: some-volume-name
246# optional array of mount points for extraVolumes
248# - name: some-volume-name
249# mountPath: /etc/wherever
251# optional array of secrets to mount inside coredns container
252# possible usecase: need for secure connection with etcd backend
254# - name: etcd-client-certs
255# mountPath: /etc/coredns/tls/etcd
257# - name: some-fancy-secret
258# mountPath: /etc/wherever
261# optional array of environment variables for coredns container
262# possible usecase: provides username and password for etcd user authentications
264# - name: WHATEVER_ENV
266# - name: SOME_SECRET_ENV
269# name: some-secret-name
272# To support legacy deployments using CoreDNS with the "k8s-app: kube-dns" label selectors.
273# See https://github.com/coredns/helm/blob/master/charts/coredns/README.md#adopting-existing-coredns-resources
274# k8sAppLabelOverride: "kube-dns"
276# Custom labels to apply to Deployment, Pod, Configmap, Service, ServiceMonitor.
277# Also applied to the autoscaler when autoscaler.inheritCustomLabels is true.
279# Custom annotations to apply to Deployment, Pod, Configmap, Service, ServiceMonitor. Including autoscaler if enabled.
281## Alternative configuration for HPA deployment if wanted
282## Create HorizontalPodAutoscaler object.
295# averageUtilization: 60
301# averageUtilization: 60
307## Configue a cluster-proportional-autoscaler for coredns
308# See https://github.com/kubernetes-incubator/cluster-proportional-autoscaler
310 # Enabled the cluster-proportional-autoscaler
312 # Number of autoscaler pods. null omits replicas (Kubernetes defaults to one).
313 # Multiple replicas run independent scaling loops without leader election.
315 # Optional PodDisruptionBudget for autoscaler pods, e.g. {maxUnavailable: 1}.
316 # Use multiple replicas to retain availability during voluntary disruptions.
317 podDisruptionBudget: {}
318 # Number of cores in the cluster per coredns replica
320 # Number of nodes in the cluster per coredns replica
322 # Min size of replicaCount
324 # Max size of replicaCount (default of 0 is no max)
326 # Whether to include unschedulable nodes in the nodes/cores calculations - this requires version 1.8.0+ of the autoscaler
327 includeUnschedulableNodes: false
328 # If true does not allow single points of failure to form
329 preventSinglePointFailure: true
330 # Annotations for the coredns proportional autoscaler pods
332 # When true, top-level customLabels are also applied to the autoscaler Deployment/pods.
333 inheritCustomLabels: true
334 # Extra labels for the autoscaler Deployment and pods. Independent of customLabels
335 # when inheritCustomLabels is false.
337 # Extra labels applied only to autoscaler pods.
339 # Optional pod selector override for the autoscaler Deployment.
340 # If set, pod template labels must match this selector.
342 podSecurityContext: {}
344 allowPrivilegeEscalation: false
345 readOnlyRootFilesystem: true
347 ## Optionally specify some extra flags to pass to cluster-proprtional-autoscaler.
348 ## Useful for e.g. the nodelabels flag.
350 # - --nodelabels=topology.kubernetes.io/zone=us-east-1a
352 repository: chainreg.biz/chainguard-private/cluster-proportional-autoscaler
353 tag: 1.11.0-r1@sha256:af49733d6fd5b556f9f28b7f02843c4a408fb855639a810fc7a86b100a56b319
354 pullPolicy: IfNotPresent
355 ## Optionally specify an array of imagePullSecrets.
356 ## Secrets must be manually created in the namespace.
357 ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
361 # - name: myRegistryKeySecretName
362 # Optional priority class to be used for the autoscaler pods. priorityClassName used if not set.
363 priorityClassName: ""
364 # expects input structure as per specification https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.11/#affinity-v1-core
366 # Node labels for pod assignment
367 # Ref: https://kubernetes.io/docs/user-guide/node-selection/
369 # expects input structure as per specification https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.11/#toleration-v1-core
371 # resources for autoscaler pod
379 # Options for autoscaler configmap
381 ## Annotations for the coredns-autoscaler configmap
382 # i.e. strategy.spinnaker.io/versioned: "false" to ensure configmap isn't renamed
384 # Enables the livenessProbe for cluster-proportional-autoscaler - this requires version 1.8.0+ of the autoscaler
387 initialDelaySeconds: 10
392 # optional array of sidecar containers
394 # - name: some-container-name
395 # image: some-image:latest
396 # imagePullPolicy: Always
401 ## Annotations for the coredns deployment
405 # dnsPolicy determines how DNS resolution is handled for the pod.
406 # When isClusterService is true, this defaults to "Default" to avoid circular DNS resolution.
407 # Options: Default, ClusterFirst, ClusterFirstWithHostNet, None
408 # If set to "None", you must provide dnsConfig.
410 # dnsConfig allows fine-grained DNS configuration for the pod.
411 # Only used when dnsPolicy is set to "None" or when custom DNS settings are needed.
417 # - my.dns.search.suffix
422# Configures initcontainers for the coredns deployment.