DirectorySecurity AdvisoriesPricing
Sign in
Directory
coredns logoHELM

coredns

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:
Compare:

1
# Default values for coredns.
2
# This is a YAML-formatted file.
3
# Declare variables to be passed into your templates.
4
5
image:
6
repository: chainreg.biz/chainguard-private/coredns
7
# Overrides the image tag whose default is the chart appVersion.
8
tag: 1.14.7-r6@sha256:8b9542f4cb711770cbe6a4232e990fef56e48009b7175e882481a67f5bebf496
9
pullPolicy: IfNotPresent
10
## Optionally specify an array of imagePullSecrets.
11
## Secrets must be manually created in the namespace.
12
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
13
##
14
pullSecrets: []
15
# pullSecrets:
16
# - name: myRegistryKeySecretName
17
replicaCount: 1
18
resources:
19
limits:
20
cpu: 100m
21
memory: 128Mi
22
requests:
23
cpu: 100m
24
memory: 128Mi
25
rollingUpdate:
26
maxUnavailable: 1
27
maxSurge: 25%
28
terminationGracePeriodSeconds: 30
29
podAnnotations: {}
30
# cluster-autoscaler.kubernetes.io/safe-to-evict: "false"
31
32
podLabels: {}
33
serviceType: "ClusterIP"
34
prometheus:
35
service:
36
enabled: false
37
annotations:
38
prometheus.io/scrape: "true"
39
prometheus.io/port: "9153"
40
selector: {}
41
monitor:
42
enabled: false
43
additionalLabels: {}
44
namespace: ""
45
interval: ""
46
scrapeTimeout: ""
47
scheme: ""
48
honorLabels: false
49
tlsConfig: {}
50
relabelings: []
51
metricRelabelings: []
52
selector: {}
53
service:
54
# clusterIP: ""
55
# clusterIPs: []
56
# loadBalancerIP: ""
57
# loadBalancerClass: ""
58
# externalIPs: []
59
# externalTrafficPolicy: ""
60
# ipFamilyPolicy: ""
61
# trafficDistribution: PreferClose
62
# The name of the Service
63
# If not set, a name is generated using the fullname template
64
name: "kube-dns"
65
annotations: {}
66
# Pod selector
67
selector: {}
68
serviceAccount:
69
create: false
70
# The name of the ServiceAccount to use
71
# If not set and create is true, a name is generated using the fullname template
72
name: ""
73
annotations: {}
74
rbac:
75
# If true, create & use RBAC resources
76
create: true
77
clusterRole:
78
# By default a name is generated using the fullname template.
79
# Override here if desired:
80
nameOverride: ""
81
# isClusterService specifies whether chart should be deployed as cluster-service or normal k8s app.
82
isClusterService: true
83
# Optional priority class to be used for the coredns pods. Used for autoscaler if autoscaler.priorityClassName not set.
84
priorityClassName: ""
85
# Configure the pod level securityContext.
86
podSecurityContext: {}
87
# Configure SecurityContext for the CoreDNS container.
88
# The defaults satisfy the `restricted` Pod Security Standard, so the chart
89
# installs into a namespace that enforces it.
90
# Ensure that required linux capability to bind port number below 1024 is assigned (`CAP_NET_BIND_SERVICE`).
91
# The CoreDNS image runs as the distroless `nonroot` user (uid/gid 65532) since
92
# 1.11.0. The numeric ids are set here because images before 1.14.7 declare the
93
# user by name, which the kubelet cannot verify when `runAsNonRoot` is true.
94
securityContext:
95
allowPrivilegeEscalation: false
96
capabilities:
97
add:
98
- NET_BIND_SERVICE
99
drop:
100
- ALL
101
readOnlyRootFilesystem: true
102
runAsNonRoot: true
103
runAsUser: 65532
104
runAsGroup: 65532
105
seccompProfile:
106
type: RuntimeDefault
107
# Default zone is what Kubernetes recommends:
108
# https://kubernetes.io/docs/tasks/administer-cluster/dns-custom-nameservers/#coredns-configmap-options
109
servers:
110
- zones:
111
- zone: .
112
use_tcp: true
113
port: 53
114
# -- expose the service on a different port
115
# servicePort: 5353
116
# If serviceType is nodePort you can specify nodePort here
117
# nodePort: 30053
118
# hostPort: 53
119
plugins:
120
- name: errors
121
# Serves a /health endpoint on :8080, required for livenessProbe
122
- name: health
123
configBlock: |-
124
lameduck 10s
125
# Serves a /ready endpoint on :8181, required for readinessProbe
126
- name: ready
127
# Required to query kubernetes API for data
128
- name: kubernetes
129
parameters: cluster.local in-addr.arpa ip6.arpa
130
configBlock: |-
131
pods insecure
132
fallthrough in-addr.arpa ip6.arpa
133
ttl 30
134
# Serves a /metrics endpoint on :9153, required for serviceMonitor
135
- name: prometheus
136
parameters: 0.0.0.0:9153
137
- name: forward
138
parameters: . /etc/resolv.conf
139
- name: cache
140
parameters: 30
141
- name: loop
142
- name: reload
143
- name: loadbalance
144
# Complete example with all the options:
145
# - zones: # the `zones` block can be left out entirely, defaults to "."
146
# - zone: hello.world. # optional, defaults to "."
147
# scheme: tls:// # optional, defaults to "" (which equals "dns://" in CoreDNS)
148
# - zone: foo.bar.
149
# scheme: dns://
150
# use_tcp: true # set this parameter to optionally expose the port on tcp as well as udp for the DNS protocol
151
# # Note that this will not work if you are also exposing tls or grpc on the same server
152
# port: 12345 # optional, defaults to "" (which equals 53 in CoreDNS)
153
# plugins: # the plugins to use for this server block
154
# - name: kubernetes # name of plugin, if used multiple times ensure that the plugin supports it!
155
# parameters: foo bar # list of parameters after the plugin
156
# configBlock: |- # if the plugin supports extra block style config, supply it here
157
# hello world
158
# foo bar
159
160
# Extra configuration that is applied outside of the default zone block.
161
# Example to include additional config files, which may come from extraVolumes:
162
# extraConfig:
163
# import:
164
# parameters: /opt/coredns/*.conf
165
extraConfig: {}
166
# To use the livenessProbe, the health plugin needs to be enabled in CoreDNS' server config
167
livenessProbe:
168
enabled: true
169
initialDelaySeconds: 60
170
periodSeconds: 10
171
timeoutSeconds: 5
172
failureThreshold: 5
173
successThreshold: 1
174
# To use the readinessProbe, the ready plugin needs to be enabled in CoreDNS' server config
175
readinessProbe:
176
enabled: true
177
initialDelaySeconds: 30
178
periodSeconds: 5
179
timeoutSeconds: 5
180
failureThreshold: 1
181
successThreshold: 1
182
# expects input structure as per specification https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.11/#affinity-v1-core
183
# for example:
184
# affinity:
185
# nodeAffinity:
186
# requiredDuringSchedulingIgnoredDuringExecution:
187
# nodeSelectorTerms:
188
# - matchExpressions:
189
# - key: foo.bar.com/role
190
# operator: In
191
# values:
192
# - master
193
affinity: {}
194
# expects input structure as per specification https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.21/#topologyspreadconstraint-v1-core
195
# and supports Helm templating.
196
# For example:
197
# topologySpreadConstraints:
198
# - labelSelector:
199
# matchLabels:
200
# app.kubernetes.io/name: '{{ template "coredns.name" . }}'
201
# app.kubernetes.io/instance: '{{ .Release.Name }}'
202
# topologyKey: topology.kubernetes.io/zone
203
# maxSkew: 1
204
# whenUnsatisfiable: ScheduleAnyway
205
# - labelSelector:
206
# matchLabels:
207
# app.kubernetes.io/name: '{{ template "coredns.name" . }}'
208
# app.kubernetes.io/instance: '{{ .Release.Name }}'
209
# topologyKey: kubernetes.io/hostname
210
# maxSkew: 1
211
# whenUnsatisfiable: ScheduleAnyway
212
topologySpreadConstraints: []
213
# Node labels for pod assignment
214
# Ref: https://kubernetes.io/docs/user-guide/node-selection/
215
nodeSelector: {}
216
# expects input structure as per specification https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.11/#toleration-v1-core
217
# for example:
218
# tolerations:
219
# - key: foo.bar.com/role
220
# operator: Equal
221
# value: master
222
# effect: NoSchedule
223
tolerations: []
224
# https://kubernetes.io/docs/tasks/run-application/configure-pdb/#specifying-a-poddisruptionbudget
225
podDisruptionBudget: {}
226
# configure custom zone files as per https://coredns.io/2017/05/08/custom-dns-entries-for-kubernetes/
227
zoneFiles: []
228
# - filename: example.db
229
# domain: example.com
230
# contents: |
231
# example.com. IN SOA sns.dns.icann.com. noc.dns.icann.com. 2015082541 7200 3600 1209600 3600
232
# example.com. IN NS b.iana-servers.net.
233
# example.com. IN NS a.iana-servers.net.
234
# example.com. IN A 192.168.99.102
235
# *.example.com. IN A 192.168.99.102
236
237
# optional array of sidecar containers
238
extraContainers: []
239
# - name: some-container-name
240
# image: some-image:latest
241
# imagePullPolicy: Always
242
# optional array of extra volumes to create
243
extraVolumes: []
244
# - name: some-volume-name
245
# emptyDir: {}
246
# optional array of mount points for extraVolumes
247
extraVolumeMounts: []
248
# - name: some-volume-name
249
# mountPath: /etc/wherever
250
251
# optional array of secrets to mount inside coredns container
252
# possible usecase: need for secure connection with etcd backend
253
extraSecrets: []
254
# - name: etcd-client-certs
255
# mountPath: /etc/coredns/tls/etcd
256
# defaultMode: 420
257
# - name: some-fancy-secret
258
# mountPath: /etc/wherever
259
# defaultMode: 440
260
261
# optional array of environment variables for coredns container
262
# possible usecase: provides username and password for etcd user authentications
263
env: []
264
# - name: WHATEVER_ENV
265
# value: whatever
266
# - name: SOME_SECRET_ENV
267
# valueFrom:
268
# secretKeyRef:
269
# name: some-secret-name
270
# key: secret-key
271
272
# To support legacy deployments using CoreDNS with the "k8s-app: kube-dns" label selectors.
273
# See https://github.com/coredns/helm/blob/master/charts/coredns/README.md#adopting-existing-coredns-resources
274
# k8sAppLabelOverride: "kube-dns"
275
276
# Custom labels to apply to Deployment, Pod, Configmap, Service, ServiceMonitor.
277
# Also applied to the autoscaler when autoscaler.inheritCustomLabels is true.
278
customLabels: {}
279
# Custom annotations to apply to Deployment, Pod, Configmap, Service, ServiceMonitor. Including autoscaler if enabled.
280
customAnnotations: {}
281
## Alternative configuration for HPA deployment if wanted
282
## Create HorizontalPodAutoscaler object.
283
##
284
# hpa:
285
# enabled: false
286
# minReplicas: 1
287
# maxReplicas: 10
288
# metrics:
289
# metrics:
290
# - type: Resource
291
# resource:
292
# name: memory
293
# target:
294
# type: Utilization
295
# averageUtilization: 60
296
# - type: Resource
297
# resource:
298
# name: cpu
299
# target:
300
# type: Utilization
301
# averageUtilization: 60
302
hpa:
303
enabled: false
304
minReplicas: 1
305
maxReplicas: 2
306
metrics: []
307
## Configue a cluster-proportional-autoscaler for coredns
308
# See https://github.com/kubernetes-incubator/cluster-proportional-autoscaler
309
autoscaler:
310
# Enabled the cluster-proportional-autoscaler
311
enabled: false
312
# Number of autoscaler pods. null omits replicas (Kubernetes defaults to one).
313
# Multiple replicas run independent scaling loops without leader election.
314
replicaCount: null
315
# Optional PodDisruptionBudget for autoscaler pods, e.g. {maxUnavailable: 1}.
316
# Use multiple replicas to retain availability during voluntary disruptions.
317
podDisruptionBudget: {}
318
# Number of cores in the cluster per coredns replica
319
coresPerReplica: 256
320
# Number of nodes in the cluster per coredns replica
321
nodesPerReplica: 16
322
# Min size of replicaCount
323
min: 0
324
# Max size of replicaCount (default of 0 is no max)
325
max: 0
326
# Whether to include unschedulable nodes in the nodes/cores calculations - this requires version 1.8.0+ of the autoscaler
327
includeUnschedulableNodes: false
328
# If true does not allow single points of failure to form
329
preventSinglePointFailure: true
330
# Annotations for the coredns proportional autoscaler pods
331
podAnnotations: {}
332
# When true, top-level customLabels are also applied to the autoscaler Deployment/pods.
333
inheritCustomLabels: true
334
# Extra labels for the autoscaler Deployment and pods. Independent of customLabels
335
# when inheritCustomLabels is false.
336
customLabels: {}
337
# Extra labels applied only to autoscaler pods.
338
podLabels: {}
339
# Optional pod selector override for the autoscaler Deployment.
340
# If set, pod template labels must match this selector.
341
selector: {}
342
podSecurityContext: {}
343
securityContext:
344
allowPrivilegeEscalation: false
345
readOnlyRootFilesystem: true
346
privileged: false
347
## Optionally specify some extra flags to pass to cluster-proprtional-autoscaler.
348
## Useful for e.g. the nodelabels flag.
349
# customFlags:
350
# - --nodelabels=topology.kubernetes.io/zone=us-east-1a
351
image:
352
repository: chainreg.biz/chainguard-private/cluster-proportional-autoscaler
353
tag: 1.11.0-r1@sha256:af49733d6fd5b556f9f28b7f02843c4a408fb855639a810fc7a86b100a56b319
354
pullPolicy: IfNotPresent
355
## Optionally specify an array of imagePullSecrets.
356
## Secrets must be manually created in the namespace.
357
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
358
##
359
pullSecrets: []
360
# pullSecrets:
361
# - name: myRegistryKeySecretName
362
# Optional priority class to be used for the autoscaler pods. priorityClassName used if not set.
363
priorityClassName: ""
364
# expects input structure as per specification https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.11/#affinity-v1-core
365
affinity: {}
366
# Node labels for pod assignment
367
# Ref: https://kubernetes.io/docs/user-guide/node-selection/
368
nodeSelector: {}
369
# expects input structure as per specification https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.11/#toleration-v1-core
370
tolerations: []
371
# resources for autoscaler pod
372
resources:
373
requests:
374
cpu: "20m"
375
memory: "10Mi"
376
limits:
377
cpu: "20m"
378
memory: "10Mi"
379
# Options for autoscaler configmap
380
configmap:
381
## Annotations for the coredns-autoscaler configmap
382
# i.e. strategy.spinnaker.io/versioned: "false" to ensure configmap isn't renamed
383
annotations: {}
384
# Enables the livenessProbe for cluster-proportional-autoscaler - this requires version 1.8.0+ of the autoscaler
385
livenessProbe:
386
enabled: true
387
initialDelaySeconds: 10
388
periodSeconds: 5
389
timeoutSeconds: 5
390
failureThreshold: 3
391
successThreshold: 1
392
# optional array of sidecar containers
393
extraContainers: []
394
# - name: some-container-name
395
# image: some-image:latest
396
# imagePullPolicy: Always
397
deployment:
398
skipConfig: false
399
enabled: true
400
name: ""
401
## Annotations for the coredns deployment
402
annotations: {}
403
## Pod selector
404
selector: {}
405
# dnsPolicy determines how DNS resolution is handled for the pod.
406
# When isClusterService is true, this defaults to "Default" to avoid circular DNS resolution.
407
# Options: Default, ClusterFirst, ClusterFirstWithHostNet, None
408
# If set to "None", you must provide dnsConfig.
409
dnsPolicy: "Default"
410
# dnsConfig allows fine-grained DNS configuration for the pod.
411
# Only used when dnsPolicy is set to "None" or when custom DNS settings are needed.
412
# Example:
413
# dnsConfig:
414
# nameservers:
415
# - 8.8.8.8
416
# searches:
417
# - my.dns.search.suffix
418
# options:
419
# - name: ndots
420
# value: "2"
421
dnsConfig: {}
422
# Configures initcontainers for the coredns deployment.
423
initContainers: []
424

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.