1## Default values for Datadog Agent
2## See Datadog helm documentation to learn more:
3## https://docs.datadoghq.com/agent/kubernetes/helm/
5## FOR AN EFFORTLESS UPGRADE PATH, DO NOT COPY THIS FILE AS YOUR OWN values.yaml.
6## ONLY SET THE VALUES YOU WANT TO OVERRIDE IN YOUR values.yaml.
8# global.apmRegistryAllowList -- Restrict which registries can be used for APM library injection.
9## When non-empty, only libraries from the listed registries will be injected. Enforced by both the
10## admission controller webhook and the CSI driver. An empty list allows all registries (default).
12 apmRegistryAllowList: []
13 # - public.ecr.aws/datadog
15# nameOverride -- Override name of app
17# fullnameOverride -- Override the full qualified app name
19# kubeVersionOverride -- Override Kubernetes version detection. Useful for GitOps tools like FluxCD that don't expose the real cluster version to Helm
20kubeVersionOverride: # "1.28.0"
21# targetSystem -- Target OS for this deployment (possible values: linux, windows)
23# commonLabels -- Labels to apply to all resources
27# registry -- Registry to use for all Agent images (default depends on datadog.site and registryMigrationMode values)
29## Currently we offer Datadog Agent images on:
30## Datadog - use registry.datadoghq.com
31## GCR US - use gcr.io/datadoghq
32## GCR Europe - use eu.gcr.io/datadoghq
33## GCR Asia - use asia.gcr.io/datadoghq
34## Azure - use datadoghq.azurecr.io
35## AWS - use public.ecr.aws/datadog
36## DockerHub - use docker.io/datadog
37## If you are on GKE Autopilot, you must use a gcr.io variant registry.
38registry: chainreg.biz # gcr.io/datadoghq
39# registryMigrationMode -- Controls gradual migration of default image registry to
40# registry.datadoghq.com, replacing site-specific regional mirrors (GCR, ACR).
41# This setting has no effect when `registry` is explicitly set.
42# GKE Autopilot and GKE GDC clusters are excluded and always use their site-specific gcr.io variant.
43# US1-FED (ddog-gov.com) is excluded and always uses public.ecr.aws/datadog.
44# US3 (us3.datadoghq.com) is excluded and always uses datadoghq.azurecr.io.
46## "auto" (default): enable registry.datadoghq.com for sites where migration is rolled out.
47## Currently enabled: AP1 (ap1.datadoghq.com), AP2 (ap2.datadoghq.com), US5 (us5.datadoghq.com), EU1 (datadoghq.eu), US1 (datadoghq.com, when APM is disabled).
48## "all": enable registry.datadoghq.com for all sites (AP1, AP2, EU, US1, US5).
49## "": disable migration, keeping site-specific registries.
50registryMigrationMode: "auto"
52 # datadog.apiKey -- Your Datadog API key
54 ## ref: https://app.datadoghq.com/account/settings#agent/kubernetes
55 apiKey: # <DATADOG_API_KEY>
56 # datadog.apiKeyExistingSecret -- Use existing Secret which stores API key instead of creating a new one. The value should be set with the `api-key` key inside the secret.
58 ## If set, this parameter takes precedence over "apiKey".
59 apiKeyExistingSecret: # <DATADOG_API_KEY_SECRET>
60 # datadog.appKey -- Datadog APP key required to use metricsProvider
62 ## If you are using clusterAgent.metricsProvider.enabled = true, you must set
63 ## a Datadog application key for read access to your metrics.
64 appKey: # <DATADOG_APP_KEY>
65 # datadog.appKeyExistingSecret -- Use existing Secret which stores APP key instead of creating a new one. The value should be set with the `app-key` key inside the secret.
67 ## If set, this parameter takes precedence over "appKey".
68 appKeyExistingSecret: # <DATADOG_APP_KEY_SECRET>
69 # agents.secretAnnotations -- Annotations to add to the Secrets
73 ## Configure the secret backend feature https://docs.datadoghq.com/agent/guide/secrets-management
74 ## Examples: https://docs.datadoghq.com/agent/guide/secrets-management/#setup-examples-1
76 # datadog.secretBackend.command -- Configure the secret backend command, path to the secret backend binary.
78 ## Note: If the command value is "/readsecret_multiple_providers.sh", and datadog.secretBackend.enableGlobalPermissions is enabled below, the agents will have permissions to get secret objects across the cluster.
79 ## Read more about "/readsecret_multiple_providers.sh": https://docs.datadoghq.com/agent/guide/secrets-management/#script-for-reading-from-multiple-secret-providers-readsecret_multiple_providerssh
80 command: # "/readsecret.sh" or "/readsecret_multiple_providers.sh" or any custom binary path
81 # datadog.secretBackend.arguments -- Configure the secret backend command arguments (space-separated strings).
82 arguments: # "/etc/secret-volume" or any other custom arguments
83 # datadog.secretBackend.timeout -- Configure the secret backend command timeout in seconds.
85 # datadog.secretBackend.refreshInterval -- [PREVIEW] Configure the secret backend command refresh interval in seconds.
87 # datadog.secretBackend.type -- Configure the built-in secret backend type.
88 # Alternative to command; when set, the Agent uses the built-in backend to resolve secrets. Requires Agent 7.70+.
89 type: # Examples: "file.text", "k8s.secrets", "docker.secrets", "aws.secrets", etc.
90 # datadog.secretBackend.config -- Additional configuration for the secret backend type.
92 # Example for k8s.secrets:
93 # token_path: "/custom/path/token"
94 # ca_path: "/custom/path/ca.crt"
96 # datadog.secretBackend.enableGlobalPermissions -- Whether to create a global permission allowing Datadog agents to read all secrets when `datadog.secretBackend.command` is set to `"/readsecret_multiple_providers.sh"` or `datadog.secretBackend.type` is set.
97 enableGlobalPermissions: true
98 # datadog.secretBackend.roles -- Creates roles for Datadog to read the specified secrets - replacing `datadog.secretBackend.enableGlobalPermissions`.
100 # - namespace: secret-location-namespace
104 # datadog.securityContext -- Allows you to overwrite the default PodSecurityContext on the Daemonset or Deployment
113 # datadog.hostVolumeMountPropagation -- Allow to specify the `mountPropagation` value on all volumeMounts using HostPath
115 ## ref: https://kubernetes.io/docs/concepts/storage/volumes/#mount-propagation
116 hostVolumeMountPropagation: None
117 # datadog.clusterName -- Set a unique cluster name to allow scoping hosts and Cluster Checks easily
119 ## The name must be unique and must be dot-separated tokens with the following restrictions:
120 ## * Lowercase letters, numbers, and hyphens only.
121 ## * Must start with a letter.
122 ## * Must end with a number or a letter.
123 ## * Overall length should not be higher than 80 characters.
124 ## Compared to the rules of GKE, dots are allowed whereas they are not allowed on GKE:
125 ## https://cloud.google.com/kubernetes-engine/docs/reference/rest/v1beta1/projects.locations.clusters#Cluster.FIELDS.name
126 clusterName: # <CLUSTER_NAME>
127 # datadog.site -- The site of the Datadog intake to send Agent data to.
128 # (documentation: https://docs.datadoghq.com/getting_started/site/)
130 ## Set to 'datadoghq.com' to send data to the US1 site (default).
131 ## Set to 'datadoghq.eu' to send data to the EU site.
132 ## Set to 'us3.datadoghq.com' to send data to the US3 site.
133 ## Set to 'us5.datadoghq.com' to send data to the US5 site.
134 ## Set to 'ddog-gov.com' to send data to the US1-FED site.
135 ## Set to 'ap1.datadoghq.com' to send data to the AP1 site.
136 site: # datadoghq.com
137 # datadog.dd_url -- The host of the Datadog intake server to send Agent data to, only set this option if you need the Agent to send data to a custom URL
139 ## Overrides the site setting defined in "site".
140 dd_url: # https://app.datadoghq.com
141 # datadog.logLevel -- Set logging verbosity, valid log levels are: trace, debug, info, warn, error, critical, off
143 # datadog.kubeStateMetricsEnabled -- If true, deploys the kube-state-metrics deployment
145 ## ref: https://github.com/kubernetes/kube-state-metrics/tree/kube-state-metrics-helm-chart-2.13.2/charts/kube-state-metrics
146 # The kubeStateMetricsEnabled option will be removed in the 4.0 version of the Datadog Agent chart.
147 kubeStateMetricsEnabled: false
148 kubeStateMetricsNetworkPolicy:
149 # datadog.kubeStateMetricsNetworkPolicy.create -- If true, create a NetworkPolicy for kube state metrics
151 kubeStateMetricsCore:
152 # datadog.kubeStateMetricsCore.enabled -- Enable the kubernetes_state_core check in the Cluster Agent (Requires Cluster Agent 1.12.0+)
154 ## ref: https://docs.datadoghq.com/integrations/kubernetes_state_core
157 # datadog.kubeStateMetricsCore.rbac.create -- If true, create & use RBAC resources
159 ## Configuring this field changes the default kubernetes_state_core check configuration. Recommended for large clusters to reduce load on the API server.
160 useApiServerCache: false
161 # datadog.kubeStateMetricsCore.ignoreLegacyKSMCheck -- Disable the auto-configuration of legacy kubernetes_state check (taken into account only when datadog.kubeStateMetricsCore.enabled is true)
163 ## Disabling this field is not recommended as it results in enabling both checks, it can be useful though during the migration phase.
164 ## Migration guide: https://docs.datadoghq.com/integrations/kubernetes_state_core/?tab=helm#migration-from-kubernetes_state-to-kubernetes_state_core
165 ignoreLegacyKSMCheck: true
166 # datadog.kubeStateMetricsCore.collectSecretMetrics -- Enable watching secret objects and collecting their corresponding metrics kubernetes_state.secret.*
168 ## Configuring this field will change the default kubernetes_state_core check configuration and the RBACs granted to Datadog Cluster Agent to run the kubernetes_state_core check.
169 collectSecretMetrics: true
170 # datadog.kubeStateMetricsCore.collectConfigMaps -- Enable watching configmap objects and collecting their corresponding metrics kubernetes_state.configmap.*
172 ## Configuring this field will change the default kubernetes_state_core check configuration and the RBACs granted to Datadog Cluster Agent to run the kubernetes_state_core check.
173 collectConfigMaps: true
174 # datadog.kubeStateMetricsCore.collectVpaMetrics -- Enable watching VPA objects and collecting their corresponding metrics kubernetes_state.vpa.*
176 ## Configuring this field will change the default kubernetes_state_core check configuration and the RBACs granted to Datadog Cluster Agent to run the kubernetes_state_core check.
177 collectVpaMetrics: false
178 # datadog.kubeStateMetricsCore.collectCrdMetrics -- Enable watching CRD objects and collecting their corresponding metrics kubernetes_state.crd.*
180 ## Configuring this field will change the default kubernetes_state_core check configuration to run the kubernetes_state_core check.
181 collectCrdMetrics: false
182 # datadog.kubeStateMetricsCore.collectCrMetrics -- Enable watching CustomResource objects and collecting their corresponding metrics kubernetes_state_customresource.* (Requires Cluster Agent 7.63.0+)
184 ## Configuring this field will change the default kubernetes_state_core check configuration and the RBACs granted to Datadog Cluster Agent to run the kubernetes_state_core check.
186 ## See https://github.com/kubernetes/kube-state-metrics/blob/main/docs/metrics/extend/customresourcestate-metrics.md for a full description of each field.
188 # - groupVersionKind:
192 # resource: "foos" # optional, if not set, the resource will be pluralized from the kind by adding "s" to the end
199 # path: [status, uptime]
201 # datadog.kubeStateMetricsCore.collectApiServicesMetrics -- Enable watching apiservices objects and collecting their corresponding metrics kubernetes_state.apiservice.* (Requires Cluster Agent 7.45.0+)
203 ## Configuring this field will change the default kubernetes_state_core check configuration and the RBACs granted to Datadog Cluster Agent to run the kubernetes_state_core check.
204 collectApiServicesMetrics: false
205 # datadog.kubeStateMetricsCore.useClusterCheckRunners -- For large clusters where the Kubernetes State Metrics Check Core needs to be distributed on dedicated workers.
207 ## Configuring this field will create a separate deployment which will run Cluster Checks, including Kubernetes State Metrics Core.
208 ## If clusterChecksRunner.enabled is true, it's recommended to set this flag to true as well to better utilize dedicated workers and reduce load on the Cluster Agent.
209 ## ref: https://docs.datadoghq.com/agent/cluster_agent/clusterchecksrunner?tab=helm
210 useClusterCheckRunners: false
211 # datadog.kubeStateMetricsCore.labelsAsTags -- Extra labels to collect from resources and to turn into datadog tag.
213 ## It has the following structure:
215 ## <resource1>: # can be pod, deployment, node, etc.
216 ## <label1>: <tag1> # where <label1> is the kubernetes label and <tag1> is the datadog tag
228 # datadog.kubeStateMetricsCore.annotationsAsTags -- Extra annotations to collect from resources and to turn into datadog tag.
230 ## It has the following structure:
231 ## annotationsAsTags:
232 ## <resource1>: # can be pod, deployment, node, etc.
233 ## <annotation1>: <tag1> # where <annotation1> is the kubernetes annotation and <tag1> is the datadog tag
234 ## <annotation2>: <tag2>
236 ## <annotation3>: <tag3>
238 ## Warning: the annotation must match the transformation done by kube-state-metrics,
239 ## for example tags.datadoghq.com/version becomes tags_datadoghq_com_version.
240 annotationsAsTags: {}
247 # datadog.kubeStateMetricsCore.tags -- List of static tags to attach to all KSM metrics
249 # datadog.kubeStateMetricsCore.namespaces -- Restrict the kubernetes_state_core check to collect metrics only from the specified namespaces.
250 ## When set, namespace-scoped RBAC is created as Role+RoleBinding per listed namespace instead of a cluster-wide ClusterRole.
251 ## Cluster-scoped resources (nodes, persistentvolumes, storageclasses, etc.) are still collected via a ClusterRole.
255 ## Manage Cluster checks feature
257 ## ref: https://docs.datadoghq.com/agent/autodiscovery/clusterchecks/
258 ## Autodiscovery via Kube Service annotations is automatically enabled
260 # datadog.clusterChecks.enabled -- Enable the Cluster Checks feature on both the cluster-agents and the daemonset
262 # datadog.clusterChecks.shareProcessNamespace -- Set the process namespace sharing on the cluster checks agent
263 shareProcessNamespace: false
264 # datadog.nodeLabelsAsTags -- Provide a mapping of Kubernetes Node Labels to Datadog Tags
266 # beta.kubernetes.io/instance-type: aws-instance-type
267 # kubernetes.io/role: kube_role
268 # <KUBERNETES_NODE_LABEL>: <DATADOG_TAG_KEY>
270 # datadog.podLabelsAsTags -- Provide a mapping of Kubernetes Labels to Datadog Tags
273 # release: helm_release
274 # <KUBERNETES_LABEL>: <DATADOG_TAG_KEY>
276 # datadog.podAnnotationsAsTags -- Provide a mapping of Kubernetes Annotations to Datadog Tags
277 podAnnotationsAsTags: {}
278 # iam.amazonaws.com/role: kube_iamrole
279 # <KUBERNETES_ANNOTATIONS>: <DATADOG_TAG_KEY>
281 # datadog.namespaceLabelsAsTags -- Provide a mapping of Kubernetes Namespace Labels to Datadog Tags
282 namespaceLabelsAsTags: {}
284 # <KUBERNETES_NAMESPACE_LABEL>: <DATADOG_TAG_KEY>
286 # datadog.namespaceAnnotationsAsTags -- Provide a mapping of Kubernetes Namespace Annotations to Datadog Tags
287 namespaceAnnotationsAsTags: {}
289 # <KUBERNETES_NAMESPACE_ANNOTATIONS>: <DATADOG_TAG_KEY>
291 # datadog.kubernetesResourcesLabelsAsTags -- Provide a mapping of Kubernetes Resources Labels to Datadog Tags
292 kubernetesResourcesLabelsAsTags: {}
296 # kubernetes.io/metadata.name: name-as-tag
298 # <KUBERNETES_RESOURCE_LABEL>: <DATADOG_TAG_KEY>
300 # datadog.kubernetesResourcesAnnotationsAsTags -- Provide a mapping of Kubernetes Resources Annotations to Datadog Tags
301 kubernetesResourcesAnnotationsAsTags: {}
303 # x-ann: annotation-reference
305 # stale-annotation: annotation-as-tag
307 # <KUBERNETES_RESOURCE_ANNOTATION>: <DATADOG_TAG_KEY>
309 originDetectionUnified:
310 # datadog.originDetectionUnified.enabled -- Enabled enables unified mechanism for origin detection. Default: false. (Requires Agent 7.54.0+).
312 # datadog.tags -- List of static tags to attach to every metric, event and service check collected by this Agent.
314 ## Learn more about tagging: https://docs.datadoghq.com/tagging/
316 # - "<KEY_1>:<VALUE_1>"
317 # - "<KEY_2>:<VALUE_2>"
319 # datadog.checksCardinality -- Sets the tag cardinality for the checks run by the Agent.
321 ## ref: https://docs.datadoghq.com/getting_started/tagging/assigning_tags/?tab=containerizedenvironments#environment-variables
322 checksCardinality: # low, orchestrator or high (not set by default to avoid overriding existing DD_CHECKS_TAG_CARDINALITY configurations, the default value in the Agent is low)
323 # kubelet configuration
325 # datadog.kubelet.host -- Override kubelet IP
329 fieldPath: status.hostIP
330 # datadog.kubelet.tlsVerify -- Toggle kubelet TLS verification
333 # datadog.kubelet.hostCAPath -- Path (on host) where the Kubelet CA certificate is stored
334 # @default -- None (no mount from host)
336 # datadog.kubelet.agentCAPath -- Path (inside Agent containers) where the Kubelet CA certificate is stored
337 # @default -- /var/run/host-kubelet-ca.crt if hostCAPath else /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
339 # datadog.kubelet.podLogsPath -- Path (on host) where the PODs logs are located
340 # @default -- /var/log/pods on Linux, C:\var\log\pods on Windows
342 # datadog.kubelet.coreCheckEnabled -- Toggle if kubelet core check should be used instead of Python check. (Requires Agent/Cluster Agent 7.53.0+)
344 coreCheckEnabled: true
345 # datadog.kubelet.podResourcesSocketDir -- Path (on host) where the kubelet.sock socket for the PodResources API is located
346 # @default -- /var/lib/kubelet/pod-resources
347 podResourcesSocketDir: /var/lib/kubelet/pod-resources
348 # datadog.kubelet.useApiServer -- Enable this to query the pod list from the API Server instead of the Kubelet. (Requires Agent 7.65.0+)
351 # datadog.kubelet.fineGrainedAuthorization -- Enable fine-grained authentication for kubelet (requires: Kubernetes 1.32+)
352 fineGrainedAuthorization: false
353 # datadog.expvarPort -- Specify the port to expose pprof and expvar to not interfere with the agent metrics port from the cluster-agent, which defaults to 5000
355 ## dogstatsd configuration
357 ## ref: https://docs.datadoghq.com/agent/kubernetes/dogstatsd/
358 ## To emit custom metrics from your Kubernetes application, use DogStatsD.
360 # datadog.dogstatsd.port -- Override the Agent DogStatsD port
362 ## Note: Make sure your client is sending to the same UDP port.
364 # datadog.dogstatsd.originDetection -- Enable origin detection for container tagging
366 ## ref: https://docs.datadoghq.com/developers/dogstatsd/unix_socket/#using-origin-detection-for-container-tagging
367 originDetection: false
368 # datadog.dogstatsd.tags -- List of static tags to attach to every custom metric, event and service check collected by Dogstatsd.
370 ## Learn more about tagging: https://docs.datadoghq.com/tagging/
372 # - "<KEY_1>:<VALUE_1>"
373 # - "<KEY_2>:<VALUE_2>"
375 # datadog.dogstatsd.tagCardinality -- Sets the tag cardinality relative to the origin detection
377 ## ref: https://docs.datadoghq.com/developers/dogstatsd/unix_socket/#using-origin-detection-for-container-tagging
379 # datadog.dogstatsd.useSocketVolume -- Enable dogstatsd over Unix Domain Socket with an HostVolume
381 ## ref: https://docs.datadoghq.com/developers/dogstatsd/unix_socket/
382 useSocketVolume: true
383 # datadog.dogstatsd.socketPath -- Path to the DogStatsD socket
384 socketPath: /var/run/datadog/dsd.socket
385 # datadog.dogstatsd.hostSocketPath -- Host path to the DogStatsD socket
386 hostSocketPath: /var/run/datadog
387 # datadog.dogstatsd.useHostPort -- Sets the hostPort to the same value of the container port
389 ## Needs to be used for sending custom metrics.
390 ## The ports need to be available on all hosts.
392 ## WARNING: Make sure that hosts using this are properly firewalled otherwise
393 ## metrics and traces are accepted from any host able to connect to this host.
395 # datadog.dogstatsd.useHostPID -- Run the agent in the host's PID namespace
396 ## DEPRECATED: use datadog.useHostPID instead.
398 ## This is required for Dogstatsd origin detection to work.
399 ## See https://docs.datadoghq.com/developers/dogstatsd/unix_socket/
401 # datadog.dogstatsd.nonLocalTraffic -- Enable this to make each node accept non-local statsd traffic (from outside of the pod)
403 ## ref: https://github.com/DataDog/docker-dd-agent#environment-variables
404 nonLocalTraffic: true
405 # datadog.useHostPID -- Run the agent in the host's PID namespace, required for origin detection
406 # / unified service tagging
408 ## This is required for Dogstatsd origin detection to work in dogstatsd and trace agent
409 ## See https://docs.datadoghq.com/developers/dogstatsd/unix_socket/
411 # datadog.collectEvents -- Enables this to start event collection from the kubernetes API
413 ## ref: https://docs.datadoghq.com/agent/kubernetes/#event-collection
415 # datadog.kubernetesUseEndpointSlices -- Enable this to map Kubernetes services to endpointslices instead of endpoints. (Requires Cluster Agent 7.62.0+).
416 kubernetesUseEndpointSlices: true
417 # datadog.kubernetesKubeServiceIgnoreReadiness -- Enable this to attach kube_service tag unconditionally. (Requires Cluster Agent 7.76.0+).
418 kubernetesKubeServiceIgnoreReadiness: false
419 # Configure Kubernetes events collection
421 # datadog.kubernetesEvents.sourceDetectionEnabled -- Enable this to map Kubernetes events to integration sources based on controller names. (Requires Cluster Agent 7.56.0+).
422 sourceDetectionEnabled: false
423 # datadog.kubernetesEvents.filteringEnabled -- Enable this to only include events that match the pre-defined allowed events. (Requires Cluster Agent 7.57.0+).
424 filteringEnabled: false
425 # datadog.kubernetesEvents.unbundleEvents -- Allow unbundling kubernetes events, 1:1 mapping between Kubernetes and Datadog events. (Requires Cluster Agent 7.42.0+).
426 unbundleEvents: false
427 # datadog.kubernetesEvents.collectedEventTypes -- Event types to be collected. This requires datadog.kubernetesEvents.unbundleEvents to be set to true.
429 # - kind: <kubernetes resource kind> # (optional if `source`` is provided)
430 # source: <controller name> # (optional if `kind`` is provided)
431 # reasons: # (optional) if empty accept all event reasons
432 # - <kubernetes event reason>
443 - TerminatingEvictedPod
450 # datadog.kubernetesEvents.maxEventsPerRun -- Maximum number of events you wish to collect per check run.
452 # datadog.kubernetesEvents.kubernetesEventResyncPeriodS -- Specify the frequency in seconds at which the Agent should list all events to re-sync following the informer pattern
453 kubernetesEventResyncPeriodS:
455 # datadog.clusterTagger.collectKubernetesTags -- Enables Kubernetes resources tags collection.
456 collectKubernetesTags: false
457 # datadog.leaderElection -- Enables leader election mechanism for event collection
459 # datadog.leaderLeaseDuration -- Set the lease time for leader election in second
460 leaderLeaseDuration: # 60
461 # datadog.leaderElectionResource -- Selects the default resource to use for leader election.
463 # * "lease" / "leases". Only supported in agent 7.47+
464 # * "configmap" / "configmaps".
465 # "" to automatically detect which one to use.
466 leaderElectionResource: configmap
468 # datadog.remoteConfiguration.enabled -- Set to true to enable remote configuration.
469 # DEPRECATED: Consider using remoteConfiguration.enabled instead
472 # datadog.privateActionRunner.enabled -- Enable the Private Action Runner on the node agent to execute workflow actions
474 # datadog.privateActionRunner.selfEnroll -- Enable self-enrollment for the Private Action Runner
475 ## When enabled, the runner will automatically register itself with Datadog using the provided API/APP keys
476 ## and store its identity in a local file. Requires leader election to be enabled.
478 # datadog.privateActionRunner.urn -- URN of the Private Action Runner (required if selfEnroll is false)
479 ## Format: urn:datadog:private-action-runner:organization:<org_id>:runner:<runner_id>
480 urn: # "urn:datadog:private-action-runner:organization:123456:runner:abc-def"
481 # datadog.privateActionRunner.privateKey -- Private key for the Private Action Runner (required if selfEnroll is false)
482 ## This key is used to authenticate the runner with Datadog
483 privateKey: # "<PRIVATE_KEY>"
484 # datadog.privateActionRunner.identityFromExistingSecret -- Use existing Secret which stores the Private Action Runner URN and private key
485 ## The secret should contain 'urn' and 'private_key' keys
486 ## If set, this parameter takes precedence over "urn" and "privateKey"
487 identityFromExistingSecret: # "<PAR_SECRET_NAME>"
488 # datadog.privateActionRunner.actionsAllowlist -- List of actions executable by the Private Action Runner
490 # - "com.datadoghq.http.request"
491 # - "com.datadoghq.gitlab.branches.*"
493 # datadog.privateActionRunner.apiKeyOnlyEnrollment -- Enroll using only the API key, without requiring an app key
494 apiKeyOnlyEnrollment: false
495 ## Enable logs agent and provide custom configs
497 # datadog.logs.enabled -- Enables this to activate Datadog Agent log collection
499 ## ref: https://docs.datadoghq.com/agent/basic_agent_usage/kubernetes/#log-collection-setup
501 # datadog.logs.containerCollectAll -- Enable this to allow log collection for all containers
503 ## ref: https://docs.datadoghq.com/agent/basic_agent_usage/kubernetes/#log-collection-setup
504 containerCollectAll: false
505 # datadog.logs.containerCollectUsingFiles -- Collect logs from files in /var/log/pods instead of using container runtime API
507 ## It's usually the most efficient way of collecting logs.
508 ## ref: https://docs.datadoghq.com/agent/basic_agent_usage/kubernetes/#log-collection-setup
509 containerCollectUsingFiles: true
510 # datadog.logs.autoMultiLineDetection -- Allows the Agent to detect common multi-line patterns automatically.
512 ## ref: https://docs.datadoghq.com/agent/logs/auto_multiline_detection/
513 autoMultiLineDetection: true
514 ## Enable apm agent and provide custom configs
516 ## APM is enabled by default. If local service Internal Traffic Policy is allowed (Kubernetes v1.22+), the agent service is created with the APM local traceport.
518 # datadog.apm.socketEnabled -- Enable APM over Socket (Unix Socket or windows named pipe)
520 ## ref: https://docs.datadoghq.com/agent/kubernetes/apm/
522 # datadog.apm.portEnabled -- Enable APM over TCP communication (hostPort 8126 by default)
524 ## ref: https://docs.datadoghq.com/agent/kubernetes/apm/
526 # datadog.apm.useLocalService -- Enable APM over TCP communication to use the local service only (requires Kubernetes v1.22+)
527 # Note: The hostPort 8126 is disabled when this is enabled.
529 ## ref: https://docs.datadoghq.com/tracing/guide/setting_up_apm_with_kubernetes_service/?tab=helm
530 useLocalService: false
531 # datadog.apm.enabled -- Enable this to enable APM and tracing, on port 8126
532 # DEPRECATED. Use datadog.apm.portEnabled instead
534 ## ref: https://github.com/DataDog/docker-dd-agent#tracing-from-the-host
536 # datadog.apm.port -- Override the trace Agent port
538 ## Note: Make sure your client is sending to the same UDP port.
540 # datadog.apm.useSocketVolume -- Enable APM over Unix Domain Socket
541 # DEPRECATED. Use datadog.apm.socketEnabled instead
543 ## ref: https://docs.datadoghq.com/agent/kubernetes/apm/
544 useSocketVolume: false
545 # datadog.apm.socketPath -- Path to the trace-agent socket
546 socketPath: /var/run/datadog/apm.socket
547 # datadog.apm.hostSocketPath -- Host path to the trace-agent socket
548 hostSocketPath: /var/run/datadog
549 # Error Tracking backend
550 errorTrackingStandalone:
551 # datadog.apm.errorTrackingStandalone.enabled -- Enables Error Tracking for backend services.
553 # APM Single Step Instrumentation
554 # Requires Cluster Agent 7.49+.
556 # datadog.apm.instrumentation.enabled -- Enable injecting the Datadog APM libraries into all pods in the cluster.
558 # datadog.apm.instrumentation.enabledNamespaces -- Enable injecting the Datadog APM libraries into pods in specific namespaces.
559 enabledNamespaces: []
560 # datadog.apm.instrumentation.disabledNamespaces -- Disable injecting the Datadog APM libraries into pods in specific namespaces.
561 disabledNamespaces: []
562 # datadog.apm.instrumentation.libVersions -- Inject specific version of tracing libraries with Single Step Instrumentation.
564 # datadog.apm.instrumentation.targets -- Enable target based workload selection.
565 # Requires Cluster Agent 7.64.0+.
567 # ddTraceConfigs[]valueFrom Requires Cluster Agent 7.66.0+.
579 # - name: "DD_PROFILING_ENABLED"
581 # - name: "DD_SERVICE"
584 # fieldPath: metadata.labels[my-label]
586 # datadog.apm.instrumentation.skipKPITelemetry -- Disable generating Configmap for APM Instrumentation KPIs
587 skipKPITelemetry: false
588 # Language detection currently only detects languages and adds them as annotations on deployments, but doesn't use these languages for injecting libraries to applicative pods.
589 # It requires Agent 7.52+ and Cluster Agent 7.52+
591 # datadog.apm.instrumentation.language_detection.enabled -- Run language detection to automatically detect languages of user workloads (preview).
593 # datadog.apm.instrumentation.injectionMode -- The injection mode to use for libraries injection.
594 # Valid values are: "auto", "init_container", "csi" (experimental, requires Cluster Agent 7.76.0+ and Datadog CSI Driver), "image_volume" (experimental, requires Cluster Agent 7.77.0+)
595 # Empty by default so the Cluster Agent can apply its own defaults.
597 # This feature is in preview. It requires Cluster Agent 7.57+.
599 # datadog.apm.instrumentation.injector.imageTag -- The image tag to use for the APM Injector (preview).
601 ## Application Security Managment (ASM) configuration
603 ## ASM is disabled by default and can be enabled by setting the various `enabled` fields to `true` under the `datadog.asm` section.
604 ## Manually adding the various environment variables to a pod will take precedence over the ones in the Helm chart.
605 ## These will only have an effect on containers that have Datadog client libraries installed, either manually or via Single Step Instrumentation (under the `datadog.apm.instrumentation` section).
606 ## It requires Datadog Cluster Agent 7.53.0+.
609 # datadog.asm.threats.enabled -- Enable Application Security Management Threats App & API Protection by injecting `DD_APPSEC_ENABLED=true` environment variable to all pods in the cluster
612 # datadog.asm.sca.enabled -- Enable Application Security Management Software Composition Analysis by injecting `DD_APPSEC_SCA_ENABLED=true` environment variable to all pods in the cluster
615 # datadog.asm.iast.enabled -- Enable Application Security Management Interactive Application Security Testing by injecting `DD_IAST_ENABLED=true` environment variable to all pods in the cluster
617 ## App & API Protection configuration
619 ## App & API Protection is disabled by default and can be enabled by setting the `enabled` field to `true` under the `datadog.appsec.injector` section.
620 ## The Datadog Helm Chart offer the option to auto-instrument supported proxies in the cluster to forward traffic to a custom security processor delegating
621 ## traffic analysis, WAF capabilities and API Posture management to Datadog's App and API Protection product that has to be deployed separately. Please follow the documentation to deploy the processor:
622 ## https://docs.datadoghq.com/security/application_security/setup/#proxies
623 ## It requires Datadog Cluster Agent 7.73.0+.
625 # App & API Protection Injector is used to automatically configure your proxy to forward traffic to a custom security processor delegating
626 # traffic analysis, WAF capabilities and API Posture management to Datadog's App and API Protection product.
628 # datadog.appsec.injector.enabled -- Enable App & API Protection on your cluster ingress usage across all your cluster at once
630 # datadog.appsec.injector.autoDetect -- Automatically detect and inject supported proxies in the cluster (Envoy Gateway, Istio Gateway API, native Istio Gateway, ingress-nginx)
632 # datadog.appsec.injector.mode -- Deployment mode for the AppSec processor. Valid values: "sidecar", "external". Leave empty to use the agent default (sidecar). Upgrading users who rely on the external-processor flow (processor.address / processor.service.*) should set this to "external" explicitly.
634 # datadog.appsec.injector.proxies -- Manually specify which proxy types to inject. Valid values: "envoy-gateway", "istio", "istio-gateway", "ingress-nginx"
635 # When autoDetect is true, detected proxies are added to this list
636 # When autoDetect is false, only proxies in this list are enabled
638 # - envoy-gateway: Configures Envoy Gateway resources for AppSec injection
639 # - istio: Watches Istio-managed Kubernetes Gateway API GatewayClasses for AppSec injection
640 # - istio-gateway: Watches native Istio Gateway resources for AppSec injection
641 # - ingress-nginx: Watches IngressClass resources to discover ingress-nginx controllers and injects the nginx-datadog module via an init container
644 # datadog.appsec.injector.rbac.create -- If true, add AppSec injector RBAC rules to the Cluster Agent ClusterRole. Disable only when AppSec injector is not used, generated resources are already cleaned up, or equivalent RBAC is managed externally.
647 # datadog.appsec.injector.sidecar.image -- Container image for the AppSec sidecar processor
648 image: "ghcr.io/datadog/dd-trace-go/service-extensions-callout"
649 # datadog.appsec.injector.sidecar.imageTag -- Image tag for the AppSec sidecar processor
651 # datadog.appsec.injector.sidecar.port -- Listening port for the AppSec sidecar processor
653 # datadog.appsec.injector.sidecar.healthPort -- Health check port for the AppSec sidecar processor
655 # datadog.appsec.injector.sidecar.bodyParsingSizeLimit -- Request body parsing size limit in bytes for the AppSec sidecar processor. Set to 0 to leave it unset (default agent behavior). Set to a negative value (e.g. -1) to disable body parsing entirely.
656 bodyParsingSizeLimit: 0
659 # datadog.appsec.injector.sidecar.resources.requests.cpu -- CPU request for the AppSec sidecar processor
661 # datadog.appsec.injector.sidecar.resources.requests.memory -- Memory request for the AppSec sidecar processor
664 # datadog.appsec.injector.sidecar.resources.limits.cpu -- Optional CPU limit for the AppSec sidecar processor
666 # datadog.appsec.injector.sidecar.resources.limits.memory -- Optional memory limit for the AppSec sidecar processor
669 # datadog.appsec.injector.processor.address -- Address of the AppSec processor service
670 # Defaults to `{service.name}.{service.namespace}.svc`
672 # datadog.appsec.injector.processor.port -- Port of the AppSec processor service (defaults to 443)
674 # datadog.appsec.injector.service -- Required service information to connect to the AppSec processor
675 # This service should point to a deployment of the image `ghcr.io/DataDog/dd-trace-go/service-extensions-callout:latest`
676 # This deployment is not managed by the Datadog Helm chart.
678 # datadog.appsec.injector.processor.service.name -- Name of the AppSec processor service
680 # datadog.appsec.injector.processor.service.namespace -- Namespace where the AppSec processor service is deployed
683 # datadog.appsec.injector.nginx.moduleMountPath -- Path inside the ingress-nginx controller pod where the nginx-datadog module .so is mounted from the shared emptyDir
684 moduleMountPath: "/modules_mount"
685 ## OTLP ingest related configuration
689 # datadog.otlp.receiver.protocols.grpc - OTLP/gRPC configuration
691 # datadog.otlp.receiver.protocols.grpc.enabled -- Enable the OTLP/gRPC endpoint
693 # datadog.otlp.receiver.protocols.grpc.endpoint -- OTLP/gRPC endpoint
694 endpoint: "0.0.0.0:4317"
695 # datadog.otlp.receiver.protocols.grpc.useHostPort -- Enable the Host Port for the OTLP/gRPC endpoint
697 # datadog.otlp.receiver.protocols.http - OTLP/HTTP configuration
699 # datadog.otlp.receiver.protocols.http.enabled -- Enable the OTLP/HTTP endpoint
701 # datadog.otlp.receiver.protocols.http.endpoint -- OTLP/HTTP endpoint
702 endpoint: "0.0.0.0:4318"
703 # datadog.otlp.receiver.protocols.http.useHostPort -- Enable the Host Port for the OTLP/HTTP endpoint
706 # datadog.otlp.logs.enabled -- Enable logs support in the OTLP ingest endpoint
708 ## Host Profiler related configuration for the host-profiler in Agent Daemonset. Note this is experimental and subject to change
710 # datadog.hostProfiler.enabled -- Enable the Host Profiler. This feature is experimental and subject to change.
712 # datadog.hostProfiler.image -- Image the Host Profiler. This parameter is experimental and will be removed once official image is available.
714 # datadog.hostProfiler.imagePullPolicy -- Pull policy for the Host Profiler image. Defaults to agents.image.pullPolicy when unset.
716 # datadog.hostProfiler.seccomp -- Seccomp profile configuration for the Host Profiler
718 # datadog.hostProfiler.seccomp.enabled -- Apply the localhost seccomp profile to the host-profiler container and run the init container that installs it on the node. Disable to run the host-profiler container Unconfined (no init container, no profile installed on the node).
720 # datadog.hostProfiler.seccompRoot -- Specify the seccomp profile root directory
721 seccompRoot: /var/lib/kubelet/seccomp
722 # datadog.hostProfiler.loggingSeccomp -- Use the seccomp profile that also permits logging syscalls
723 loggingSeccomp: false
724 # datadog.hostProfiler.apparmor -- Specify an AppArmor profile for the host-profiler container (e.g. "localhost/datadog-host-profiler").
725 ## Only used when agents.podSecurity.apparmor.enabled is true.
727 ## OTel collector related configuration for the otel-agent in Agent Daemonset
729 # datadog.otelCollector.enabled -- Enable the OTel Collector
731 # datadog.otelCollector.ports -- Ports that OTel Collector is listening on
733 # Default GRPC port of OTLP receiver
734 - containerPort: "4317"
737 # Default HTTP port of OTLP receiver
738 - containerPort: "4318"
741 # datadog.otelCollector.config -- OTel collector configuration
743 # datadog.otelCollector.configMap -- Use an existing ConfigMap for DDOT Collector configuration
745 # datadog.otelCollector.configMap.name -- Name of the existing ConfigMap that contains the DDOT Collector configuration
747 # datadog.otelCollector.configMap.items -- Items within the ConfigMap that contain DDOT Collector configuration
749 # - key: otel-config.yaml
750 # path: otel-config.yaml
751 # - key: otel-config-two.yaml
752 # path: otel-config-two.yaml
753 # datadog.otelCollector.configMap.key -- Key within the ConfigMap that contains the DDOT Collector configuration
754 key: otel-config.yaml
755 # datadog.otelCollector.featureGates -- Feature gates to pass to OTel collector, as a comma separated list
757 # datadog.otelCollector.useStandaloneImage -- If true, the OTel Collector will use the `ddot-collector` image instead of the `agent` image
758 # The tag is retrieved from the `agents.image.tag` value.
759 # This is only supported for agent versions 7.67.0+
760 # If set to false, you will need to set `agents.image.tagSuffix` to `full`
761 useStandaloneImage: true
762 ## Provide OTel Collector RBAC configuration
764 # datadog.otelCollector.rbac.create -- If true, check OTel Collector config for k8sattributes processor
765 # and create required ClusterRole to access Kubernetes API
767 # datadog.otelCollector.rbac.rules -- A set of additional RBAC rules to apply to OTel Collector's ClusterRole
770 # resources: ["pods", "nodes"]
771 # verbs: ["get", "list", "watch"]
772 ## Provide OTel Collector logs configuration
774 # datadog.otelCollector.logs.enabled -- Enable logs support in the OTel Collector.
775 # If true, checks OTel Collector config for filelog receiver and mounts additional volumes to collect containers
778 ## Continuous Profiler configuration
780 ## Continuous Profiler is disabled by default and can be enabled by setting the `enabled` field to
781 ## either `auto` or `true` value under the `datadog.profiling` section.
782 ## Manually adding the `DD_PROFILING_ENABLED` variable to a pod will take precedence over the
783 ## value in the Helm chart.
784 ## These will only have an effect on containers that have Datadog client libraries installed,
785 ## either manually or via Single Step Instrumentation (under the `datadog.apm.instrumentation`
787 ## It requires Datadog Cluster Agent 7.57.0+.
789 # datadog.profiling.enabled -- Enable Continuous Profiler by injecting `DD_PROFILING_ENABLED`
790 # environment variable with the same value to all pods in the cluster
792 # - false: Profiler is turned off and can not be turned on by other means.
793 # - null: Profiler is turned off, but can be turned on by other means.
794 # - auto: Profiler is turned off, but the library will turn it on if the application is a good candidate for profiling.
795 # - true: Profiler is turned on.
797 # datadog.envFrom -- Set environment variables for all Agents directly from configMaps and/or secrets
799 ## envFrom to pass configmaps or secrets as environment
802 # name: <CONFIGMAP_NAME>
804 # name: <SECRET_NAME>
806 # datadog.env -- Set environment variables for the node Agents containers only
808 ## The Datadog Agent supports many environment variables.
809 ## ref: https://docs.datadoghq.com/agent/docker/?tab=standard#environment-variables
811 # - name: <ENV_VAR_NAME>
812 # value: <ENV_VAR_VALUE>
814 # datadog.envDict -- Set environment variables defined in a dict for node Agents containers only
816 # <ENV_VAR_NAME>: <ENV_VAR_VALUE>
818 # datadog.confd -- Provide additional check configurations (static and Autodiscovery)
820 ## Each key becomes a file in /conf.d
821 ## ref: https://github.com/DataDog/datadog-agent/tree/main/Dockerfiles/agent#optional-volumes
822 ## ref: https://docs.datadoghq.com/agent/autodiscovery/
829 # kubernetes_state.yaml: |-
831 # - kube-state-metrics
834 # - kube_state_url: http://%%host%%:8080/metrics
836 # datadog.checksd -- Provide additional custom checks as python code
838 ## Each key becomes a file in /checks.d
839 ## ref: https://github.com/DataDog/datadog-agent/tree/main/Dockerfiles/agent#optional-volumes
843 # datadog.dockerSocketPath -- Path to the docker socket
844 dockerSocketPath: # /var/run/docker.sock
845 # datadog.criSocketPath -- Path to the container runtime socket (if different from Docker)
846 criSocketPath: # /var/run/containerd/containerd.sock
847 # Configure how the agent interact with the host's container runtime
848 containerRuntimeSupport:
849 # datadog.containerRuntimeSupport.enabled -- Set this to false to disable agent access to container runtime.
851 ## Enable process agent and provide custom configs
853 # datadog.processAgent.enabled -- Set this to true to enable live process monitoring agent
854 # DEPRECATED. Set `datadog.processAgent.processCollection` or `datadog.processAgent.containerCollection` instead.
855 ## Note: /etc/passwd is automatically mounted when `processCollection`, `processDiscovery`, or `containerCollection` is enabled.
856 ## ref: https://docs.datadoghq.com/graphing/infrastructure/process/#kubernetes-daemonset
858 # datadog.processAgent.processCollection -- Set this to true to enable process collection
859 processCollection: false
860 # datadog.processAgent.stripProcessArguments -- Set this to scrub all arguments from collected processes
861 ## Requires datadog.processAgent.processCollection to be set to true to have any effect
862 ## ref: https://docs.datadoghq.com/infrastructure/process/?tab=linuxwindows#process-arguments-scrubbing
863 stripProcessArguments: false
864 # datadog.processAgent.processDiscovery -- Enables or disables autodiscovery of integrations
865 processDiscovery: true
866 # datadog.processAgent.runInCoreAgent -- Set this to true to run the following features in the core agent: Live Processes, Live Containers, Process Discovery.
867 ## This requires Agent 7.60.0+ and Linux.
868 ## DEPRECATED: This behavior will be enabled by default for installations that meet the requirements.
869 ## For Agent 7.78.0+, this setting is ignored — process checks always run in the core agent on Linux.
871 # datadog.processAgent.containerCollection -- Set this to true to enable container collection
872 ## ref: https://docs.datadoghq.com/infrastructure/containers/?tab=helm
873 containerCollection: true
874 # datadog.disableDefaultOsReleasePaths -- Set this to true to disable mounting datadog.osReleasePath in all containers
875 disableDefaultOsReleasePaths: false
876 # datadog.disablePasswdMount -- Set this to true to disable mounting /etc/passwd in all containers
877 disablePasswdMount: false
878 # datadog.osReleasePath -- Specify the path to your os-release file
879 osReleasePath: /etc/os-release
880 ## Enable systemProbe agent and provide custom configs
882 # datadog.systemProbe.debugPort -- Specify the port to expose pprof and expvar for system-probe agent
884 # datadog.systemProbe.enableConntrack -- Enable the system-probe agent to connect to the netlink/conntrack subsystem to add NAT information to connection data
886 ## ref: http://conntrack-tools.netfilter.org/
887 enableConntrack: true
888 # datadog.systemProbe.seccomp -- Apply an ad-hoc seccomp profile to the system-probe agent to restrict its privileges
890 ## Note that this will break `kubectl exec … -c system-probe -- /bin/bash`
891 seccomp: localhost/system-probe
892 # datadog.systemProbe.seccompRoot -- Specify the seccomp profile root directory
893 seccompRoot: /var/lib/kubelet/seccomp
894 # datadog.systemProbe.bpfDebug -- Enable logging for kernel debug
896 # datadog.systemProbe.apparmor -- Specify a apparmor profile for system-probe
898 # datadog.systemProbe.enableTCPQueueLength -- Enable the TCP queue length eBPF-based check
899 enableTCPQueueLength: false
900 # datadog.systemProbe.enableOOMKill -- Enable the OOM kill eBPF-based check
902 # datadog.systemProbe.mountPackageManagementDirs -- Enables mounting of specific package management directories when runtime compilation is enabled
903 mountPackageManagementDirs: []
904 ## For runtime compilation to be able to download kernel headers, the host's package management folders
905 ## must be mounted to the /host directory. For example, for Ubuntu & Debian the following mount would be necessary:
906 # - name: "apt-config-dir"
908 # mountPath: /host/etc/apt
909 ## If this list is empty, then all necessary package management directories (for all supported OSs) will be mounted.
911 # datadog.systemProbe.runtimeCompilationAssetDir -- Specify a directory for runtime compilation assets to live in
912 runtimeCompilationAssetDir: /var/tmp/datadog-agent/system-probe
913 # datadog.systemProbe.btfPath -- Specify the path to a BTF file for your kernel
915 # datadog.systemProbe.collectDNSStats -- Enable DNS stat collection
916 collectDNSStats: true
917 # datadog.systemProbe.maxTrackedConnections -- the maximum number of tracked connections
918 maxTrackedConnections: 131072
919 # datadog.systemProbe.maxConnectionStateBuffered -- Maximum number of concurrent connections for Cloud Network Monitoring
920 maxConnectionStateBuffered:
921 # datadog.systemProbe.conntrackMaxStateSize -- the maximum size of the userspace conntrack cache
922 conntrackMaxStateSize: 131072 # 2 * maxTrackedConnections by default, per https://github.com/DataDog/datadog-agent/blob/d1c5de31e1bba72dfac459aed5ff9562c3fdcc20/pkg/process/config/config.go#L229
923 # datadog.systemProbe.conntrackInitTimeout -- the time to wait for conntrack to initialize before failing
924 conntrackInitTimeout: 10s
925 # DEPRECATED. Use datadog.disableDefaultOsReleasePaths instead.
926 # datadog.systemProbe.enableDefaultOsReleasePaths -- enable default os-release files mount
927 enableDefaultOsReleasePaths: true
928 # datadog.systemProbe.enableDefaultKernelHeadersPaths -- Enable mount of default paths where kernel headers are stored
929 enableDefaultKernelHeadersPaths: true
930 containerImageCollection:
931 # datadog.containerImageCollection.enabled -- Enable collection of container image metadata
933 # This parameter requires Agent version 7.46+
935 orchestratorExplorer:
936 # datadog.orchestratorExplorer.enabled -- Set this to false to disable the orchestrator explorer
938 ## This requires processAgent.enabled and clusterAgent.enabled to be set to true
939 ## ref: TODO - add doc link
941 # datadog.orchestratorExplorer.container_scrubbing -- Enable the scrubbing of containers in the kubernetes resource YAML for sensitive information
943 ## The container scrubbing is taking significant resources during data collection.
944 ## If you notice that the cluster-agent uses too much CPU in larger clusters
945 ## turning this option off will improve the situation.
948 # datadog.orchestratorExplorer.kubelet_configuration_check.enabled -- Enable the orchestrator kubelet configuration check
950 ## this enables the collection of the kubelet configuration for viewing in the orchestrator
951 kubelet_configuration_check:
953 # datadog.orchestratorExplorer.customResources -- Defines custom resources for the orchestrator explorer to collect
955 # customResources is required for RBAC creation if a custom orchestrator explorer configuration is provided in `clusterAgent.confd` or `clusterAgent.advancedConfd`
956 # Each item should follow group/version/name, for example
958 # - datadoghq.com/v1alpha1/datadogmetrics
959 # - datadoghq.com/v1alpha1/watermarkpodautoscalers
962 # datadog.orchestratorExplorer.rbac.create -- If true, create & use a dedicated ClusterRole and ClusterRoleBinding for orchestrator explorer permissions
964 # datadog.orchestratorExplorer.networkCRDs.enabled -- Enable RBAC for Gateway API, service mesh, and ingress controller CRD collection.
965 # Set to true to add RBAC rules for these resources to the orchestrator explorer ClusterRole
968 # datadog.orchestratorExplorer.useClusterCheckRunners -- For clusters where orchestrator explorer checks run on dedicated Cluster Checks Runners instead of the Cluster Agent.
970 ## When enabled, the orchestrator explorer RBAC is bound to the Cluster Checks Runner ServiceAccount instead of the Cluster Agent.
971 ## ref: https://docs.datadoghq.com/agent/cluster_agent/clusterchecksrunner?tab=helm
972 useClusterCheckRunners: false
974 # datadog.kubernetesActions.enabled -- Set this to true to enable the Kubernetes Actions feature on the Cluster Agent.
975 # This grants the Cluster Agent RBAC to delete pods and restart deployments so that the Datadog
976 # Kubernetes Actions product can drive remediation. Requires Cluster Agent version 7.79.0 or greater.
979 # datadog.helmCheck.enabled -- Set this to true to enable the Helm check (Requires Agent 7.35.0+ and Cluster Agent 1.19.0+)
980 # This requires clusterAgent.enabled to be set to true
982 # datadog.helmCheck.collectEvents -- Set this to true to enable event collection in the Helm Check (Requires Agent 7.36.0+ and Cluster Agent 1.20.0+)
983 # This requires datadog.HelmCheck.enabled to be set to true
985 # datadog.helmCheck.valuesAsTags -- Collects Helm values from a release and uses them as tags (Requires Agent and Cluster Agent 7.40.0+).
986 # This requires datadog.HelmCheck.enabled to be set to true
988 # <HELM_VALUE>: <LABEL_NAME>
990 # datadog.networkMonitoring.enabled -- Enable Cloud Network Monitoring
992 # datadog.networkMonitoring.dnsMonitoringPorts -- List of ports to monitor for DNS traffic
993 # @default -- `[53]` (set by agent)
994 dnsMonitoringPorts: []
996 connectionsMonitoring:
997 # datadog.networkPath.connectionsMonitoring.enabled -- Enable Network Path's "Network traffic paths" feature. Requires the `traceroute` system-probe module to be enabled.
1000 # datadog.networkPath.collector.workers -- Override the number of workers
1002 # datadog.networkPath.collector.pathtestTTL -- Override TTL in minutes for pathtests
1004 # datadog.networkPath.collector.pathtestInterval -- Override time interval between pathtest runs
1006 # datadog.networkPath.collector.pathtestContextsLimit -- Override maximum number of pathtests stored to run
1007 pathtestContextsLimit:
1008 # datadog.networkPath.collector.pathtestMaxPerMinute -- Override limit for total pathtests run, per minute
1009 pathtestMaxPerMinute:
1011 # datadog.serviceMonitoring.enabled -- Enable Universal Service Monitoring
1013 # datadog.serviceMonitoring.httpMonitoringEnabled -- Enable HTTP monitoring for Universal Service Monitoring (Requires Agent 7.40.0+). Empty values use the default setting in the datadog agent.
1014 httpMonitoringEnabled:
1015 # datadog.serviceMonitoring.http2MonitoringEnabled -- Enable HTTP2 & gRPC monitoring for Universal Service Monitoring (Requires Agent 7.53.0+ and kernel 5.2 or later). Empty values use the default setting in the datadog agent.
1016 http2MonitoringEnabled:
1019 # datadog.serviceMonitoring.tls.go.enabled -- (bool) Enable TLS monitoring for Golang services (Requires Agent 7.51.0+). Empty values use the default setting in the datadog agent.
1022 # datadog.serviceMonitoring.tls.istio.enabled -- (bool) Enable TLS monitoring for Istio services (Requires Agent 7.50.0+). Empty values use the default setting in the datadog agent.
1025 # datadog.serviceMonitoring.tls.nodejs.enabled -- (bool) Enable TLS monitoring for Node.js services (Requires Agent 7.54.0+). Empty values use the default setting in the datadog agent.
1028 # datadog.serviceMonitoring.tls.native.enabled -- (bool) Enable TLS monitoring for native (openssl, libssl, gnutls) services (Requires Agent 7.51.0+). Empty values use the default setting in the datadog agent.
1031 # datadog.traceroute.enabled -- (bool) Enable traceroutes in system-probe for Network Path
1034 # datadog.discovery.enabled -- (bool) Enable Service Discovery. If omitted, the chart auto-enables it when the effective node Agent version resolved by the chart is >= 7.78.0, except on GKE Autopilot clusters where system-probe is not supported. If that resolution still yields a non-semver-ish tag, discovery treats it as latest. Explicit true/false always takes precedence. On supported Agent versions, the chart also enables `discovery.use_system_probe_lite` so discovery-only deployments can exec into `system-probe-lite`.
1036 # datadog.discovery.networkStats.enabled -- (bool) Enable Service Discovery Network Stats
1039 # datadog.discovery.serviceMap.enabled -- (bool) Enable Discovery Service Map (restricted USM)
1043 # datadog.gpuMonitoring.enabled -- Enable GPU monitoring core check
1045 # datadog.gpuMonitoring.privilegedMode -- Enable advanced GPU metrics and monitoring via system-probe
1046 # Note: system-probe component of the agent runs with elevated privileges
1047 privilegedMode: false
1048 # datadog.gpuMonitoring.configureCgroupPerms -- Configure cgroup permissions for GPU monitoring
1049 configureCgroupPerms: false
1050 # datadog.gpuMonitoring.enableEbpfProbes -- DEPRECATED. Enable the GPU monitoring eBPF probes in system-probe
1051 # The eBPF probes are deprecated and disabled by default, even when `datadog.gpuMonitoring.privilegedMode` is
1052 # enabled. This option only applies in privileged mode and exists so that users who still rely on the probes can
1053 # opt back in; expect it to be removed in a future release.
1054 enableEbpfProbes: false
1055 # datadog.gpuMonitoring.runtimeClassName -- Runtime class name for the agent pods to get access to NVIDIA resources. Can be left empty to use the default runtime class.
1056 runtimeClassName: "nvidia"
1057 # Software Bill of Materials configuration
1060 # datadog.sbom.containerImage.enabled -- Enable SBOM collection for container images
1062 # datadog.sbom.containerImage.uncompressedLayersSupport -- Use container runtime snapshotter
1063 # This should be set to true when using EKS, GKE or if containerd is configured to
1064 # discard uncompressed layers.
1065 # This feature will cause the SYS_ADMIN capability to be added to the Agent container.
1066 # Setting this to false could cause a high error rate when generating SBOMs due to missing uncompressed layer.
1067 # See https://docs.datadoghq.com/security/cloud_security_management/troubleshooting/vulnerabilities/#uncompressed-container-image-layers
1068 uncompressedLayersSupport: true
1069 # datadog.sbom.containerImage.overlayFSDirectScan -- Use experimental overlayFS direct scan
1070 overlayFSDirectScan: false
1071 # datadog.sbom.containerImage.containerExclude -- Exclude containers from SBOM generation, as a space-separated list
1073 ## ref: https://docs.datadoghq.com/agent/guide/autodiscovery-management/?tab=containerizedagent#exclude-containers
1074 containerExclude: # "image:datadog/agent"
1075 # datadog.sbom.containerImage.containerInclude -- Include containers in SBOM generation, as a space-separated list.
1076 # If a container matches an include rule, it’s always included in SBOM generation
1078 ## ref: https://docs.datadoghq.com/agent/guide/autodiscovery-management/?tab=containerizedagent#include-containers
1080 # datadog.sbom.containerImage.analyzers -- List of analyzers to use for container image SBOM generation
1084 # datadog.sbom.host.enabled -- Enable SBOM collection for host filesystems
1086 # datadog.sbom.host.analyzers -- List of analyzers to use for host SBOM generation
1091 # datadog.sbom.enrichment.usage.enabled -- Enable runtime "package in use" SBOM enrichment.
1092 # Requires the system-probe container (auto-enabled when set to true) for eBPF-based file
1093 # access tracking, and sets `hostPID: true` on the agent pod. Requires Agent 7.79.0+.
1095 ## Enable security agent and provide custom configs
1098 # datadog.securityAgent.compliance.enabled -- Set to true to enable Cloud Security Posture Management (CSPM)
1100 # datadog.securityAgent.compliance.configMap -- Contains CSPM compliance benchmarks that will be used
1102 # datadog.securityAgent.compliance.checkInterval -- Compliance check run interval
1104 # datadog.securityAgent.compliance.containerInclude -- Include containers in CSPM monitoring, as a space-separated list.
1105 # If a container matches an include rule, it’s always included
1107 ## ref: https://docs.datadoghq.com/agent/guide/autodiscovery-management/?tab=containerizedagent#include-containers
1109 # DEPRECATED. Use datadog.securityAgent.compliance.host_benchmarks.enabled instead.
1112 # datadog.securityAgent.compliance.host_benchmarks.enabled -- Set to false to disable host benchmarks. If enabled, this feature requires 160 MB extra memory for the `security-agent` container. (Requires Agent 7.47.0+)
1115 # datadog.securityAgent.compliance.runInSystemProbe -- Set to true to run compliance checks in system-probe instead of security-agent.
1116 # When enabled in conjunction with datadog.securityAgent.runtime.directSendFromSystemProbe, the security-agent container will not be created.
1117 runInSystemProbe: false
1119 # datadog.securityAgent.runtime.enabled -- Set to true to enable Cloud Workload Security (CWS)
1121 # datadog.securityAgent.runtime.fimEnabled -- Set to true to enable Cloud Workload Security (CWS) File Integrity Monitoring
1122 # DEPRECATED. This option has no effect. Cloud Workload Security is now only controlled by datadog.securityAgent.runtime.enabled.
1124 # datadog.securityAgent.runtime.useSecruntimeTrack -- Set to true to send Cloud Workload Security (CWS) events directly to the Agent events explorer. This value shouldn't be changed unless advised by Datadog support.
1125 useSecruntimeTrack: true
1126 # datadog.securityAgent.runtime.directSendFromSystemProbe -- Set to true to enable direct sending of CWS events from system-probe to Datadog, bypassing security-agent.
1127 # When enabled, the security-agent container will not be created for CWS functionality (it may still be created if compliance features are enabled).
1128 directSendFromSystemProbe: false
1129 ## ref: https://docs.datadoghq.com/agent/guide/autodiscovery-management/?tab=containerizedagent#exclude-containers
1130 containerExclude: # "image:datadog/agent"
1131 # datadog.securityAgent.runtime.containerInclude -- Include containers in runtime security monitoring, as a space-separated list.
1132 # If a container matches an include rule, it’s always included
1134 ## ref: https://docs.datadoghq.com/agent/guide/autodiscovery-management/?tab=containerizedagent#include-containers
1137 # datadog.securityAgent.runtime.policies.configMap -- Contains CWS policies that will be used
1140 # datadog.securityAgent.runtime.syscallMonitor.enabled -- Set to true to enable the Syscall monitoring (recommended for troubleshooting only)
1143 # datadog.securityAgent.runtime.network.enabled -- Set to true to enable the collection of CWS network events
1146 # datadog.securityAgent.runtime.activityDump.enabled -- Set to true to enable the collection of CWS activity dumps
1148 # datadog.securityAgent.runtime.activityDump.tracedCgroupsCount -- Set to the number of containers that should be traced concurrently
1149 tracedCgroupsCount: 3
1150 # datadog.securityAgent.runtime.activityDump.cgroupDumpTimeout -- Set to the desired duration of a single container tracing (in minutes)
1151 cgroupDumpTimeout: 20
1152 # datadog.securityAgent.runtime.activityDump.cgroupWaitListSize -- Set to the size of the wait list for already traced containers
1153 cgroupWaitListSize: 0
1155 # datadog.securityAgent.runtime.activityDump.pathMerge.enabled -- Set to true to enable the merging of similar paths
1158 # datadog.securityAgent.runtime.securityProfile.enabled -- Set to true to enable CWS runtime security profiles
1161 # datadog.securityAgent.runtime.securityProfile.anomalyDetection.enabled -- Set to true to enable CWS runtime drift events
1164 # datadog.securityAgent.runtime.securityProfile.autoSuppression.enabled -- Set to true to enable CWS runtime auto suppression
1167 # datadog.securityAgent.runtime.enforcement.enabled -- Set to false to disable CWS runtime enforcement
1169 ## Manage NetworkPolicy
1171 # datadog.networkPolicy.create -- If true, create NetworkPolicy for all the components
1173 # datadog.networkPolicy.flavor -- Flavor of the network policy to use.
1175 # * kubernetes for networking.k8s.io/v1/NetworkPolicy
1176 # * cilium for cilium.io/v2/CiliumNetworkPolicy
1179 # datadog.networkPolicy.cilium.dnsSelector -- Cilium selector of the DNS server entity
1180 # @default -- kube-dns in namespace kube-system
1184 "k8s:io.kubernetes.pod.namespace": kube-system
1185 "k8s:k8s-app": kube-dns
1186 ## Configure prometheus scraping autodiscovery
1188 ## ref: https://docs.datadoghq.com/agent/kubernetes/prometheus/
1190 # datadog.prometheusScrape.enabled -- Enable autodiscovering pods and services exposing prometheus metrics.
1192 # datadog.prometheusScrape.serviceEndpoints -- Enable generating dedicated checks for service endpoints.
1193 serviceEndpoints: false
1194 # datadog.prometheusScrape.additionalConfigs -- Allows adding advanced openmetrics check configurations with custom discovery rules. (Requires Agent version 7.27+)
1195 additionalConfigs: []
1198 # kubernetes_annotations:
1200 # custom_include_label: 'true'
1202 # custom_exclude_label: 'true'
1203 # kubernetes_container_names:
1206 # - send_distribution_buckets: true
1208 # datadog.prometheusScrape.version -- Version of the openmetrics check to schedule by default.
1210 # See https://datadoghq.dev/integrations-core/legacy/prometheus/#config-changes-between-versions for the differences between the two versions.
1211 # (Version 2 requires Agent version 7.34+)
1213 # datadog.ignoreAutoConfig -- List of integration to ignore auto_conf.yaml.
1215 ## ref: https://docs.datadoghq.com/agent/faq/auto_conf/
1216 ignoreAutoConfig: []
1218 # - kubernetes_state
1220 # datadog.containerExclude -- Exclude containers from Agent Autodiscovery, as a space-separated list
1222 ## ref: https://docs.datadoghq.com/agent/guide/autodiscovery-management/?tab=containerizedagent#exclude-containers
1223 containerExclude: # "image:datadog/agent"
1224 # datadog.containerInclude -- Include containers in Agent Autodiscovery, as a space-separated list.
1225 # If a container matches an include rule, it’s always included in Autodiscovery
1227 ## ref: https://docs.datadoghq.com/agent/guide/autodiscovery-management/?tab=containerizedagent#include-containers
1229 # datadog.containerExcludeLogs -- Exclude logs from Agent Autodiscovery, as a space-separated list
1230 containerExcludeLogs:
1231 # datadog.containerIncludeLogs -- Include logs in Agent Autodiscovery, as a space-separated list
1232 containerIncludeLogs:
1233 # datadog.containerExcludeMetrics -- Exclude metrics from Agent Autodiscovery, as a space-separated list
1234 containerExcludeMetrics:
1235 # datadog.containerIncludeMetrics -- Include metrics in Agent Autodiscovery, as a space-separated list
1236 containerIncludeMetrics:
1237 # datadog.celWorkloadExclude -- Exclude workloads using a CEL-based definition in the Agent. (Requires Agent 7.73.0+)
1238 # ref: https://docs.datadoghq.com/containers/guide/container-discovery-management/
1240 # datadog.excludePauseContainer -- Exclude pause containers from Agent Autodiscovery.
1242 ## ref: https://docs.datadoghq.com/agent/guide/autodiscovery-management/?tab=containerizedagent#pause-containers
1243 excludePauseContainer: true
1245 # datadog.containerLifecycle.enabled -- Enable container lifecycle events collection
1248 # datadog.csi.enabled -- Enable datadog csi driver
1249 # Requires version 7.67 or later of the cluster agent
1251 # - When set to true, the CSI driver subchart will be installed automatically.
1252 # - Do not install the CSI driver separately if this is enabled, or you may hit conflicts.
1255 # datadog.instrumentationCrd.enabled -- (bool) Enable the DatadogInstrumentation CRD controller and reconciliation platform.
1256 # Requires version 7.82.0 or later of both cluster and node agent.
1259 # datadog.dataPlane.enabled -- Whether or not the data plane is enabled
1261 # Requires version 7.74 or later of the Datadog Agent.
1263 # The data plane feature is currently in preview. Please reach out to your Datadog representative for more information.
1266 # datadog.dataPlane.dogstatsd.enabled -- Whether or not DogStatsD is enabled in the data plane
1269 ## * Enable the Datadog Operator chart dependency.
1270 ## * Configure the Datadog Operator sub-chart using the values config, `operator`.
1271 ## For all available Operator chart options see: https://github.com/DataDog/helm-charts/blob/main/charts/datadog-operator/values.yaml
1273 # datadog.operator.enabled -- Enable the Datadog Operator.
1275 # datadog.operator.migration.enabled -- Enable migration of Agent workloads to be managed by the Datadog Operator.
1276 # Creates a DatadogAgent manifest based on current release's values.yaml.
1279 # datadog.operator.migration.preview -- Set to true to preview the DatadogAgent manifest mapped from the
1280 # Helm release's values.yaml. Mapped DatadogAgent manifest can be viewed by checking the `dda-mapper`
1281 # container logs in the migration job.
1283 # datadog.operator.migration.userValues -- Provide datadog chart values as a YAML string to be mapped to the DatadogAgent manifest.
1284 # Use --set-file to pass the file contents: helm install datadog ./charts/datadog --set-file datadog.operator.migration.userValues=myValues.yaml -f myValues.yaml
1286 # Configuration related to Dynamic Instrumentation for Go services.
1287 dynamicInstrumentationGo:
1288 # datadog.dynamicInstrumentationGo.enabled -- Enable Dynamic Instrumentation and Live Debugger for Go services.
1290 # Configuration related to Workload Autoscaling
1293 # datadog.autoscaling.workload.enabled -- (bool) Enable Workload Autoscaling.
1295## This is the Datadog Cluster Agent implementation that handles cluster-wide
1296## metrics more cleanly, separates concerns for better rbac, and implements
1297## the external metrics API so you can autoscale HPAs based on datadog metrics
1298## ref: https://docs.datadoghq.com/agent/kubernetes/cluster/
1300 # clusterAgent.enabled -- Set this to false to disable Datadog Cluster Agent
1302 # clusterAgent.shareProcessNamespace -- Set the process namespace sharing on the Datadog Cluster Agent
1303 shareProcessNamespace: false
1304 ## Define the Datadog Cluster-Agent image to work with
1306 # clusterAgent.image.name -- Cluster Agent image name to use (relative to `registry`)
1307 name: scratch-images/test-tmp/datadog-cluster-agent
1308 # clusterAgent.image.tag -- Cluster Agent image tag to use
1309 tag: 7.82.3-r0@sha256:3da8981733a442abea94d770d171b55e99fa644aab1486b54bcaed7024ded285
1310 # clusterAgent.image.digest -- Cluster Agent image digest to use, takes precedence over tag if specified
1312 # clusterAgent.image.repository -- Override default registry + image.name for Cluster Agent
1314 # clusterAgent.image.pullPolicy -- Cluster Agent image pullPolicy
1315 pullPolicy: IfNotPresent
1316 # clusterAgent.image.pullSecrets -- Cluster Agent repository pullSecret (ex: specify docker registry credentials)
1318 ## See https://kubernetes.io/docs/concepts/containers/images/#specifying-imagepullsecrets-on-a-pod
1320 # - name: "<REG_SECRET>"
1322 # clusterAgent.image.doNotCheckTag -- Skip the version and chart compatibility check
1324 ## By default, the version passed in clusterAgent.image.tag is checked
1325 ## for compatibility with the version of the chart.
1326 ## This boolean permits completely skipping this check.
1327 ## This is useful, for example, for custom tags that are not
1328 ## respecting semantic versioning.
1329 doNotCheckTag: # false
1330 # clusterAgent.securityContext -- Allows you to overwrite the default PodSecurityContext on the cluster-agent pods.
1334 # clusterAgent.containers.clusterAgent.securityContext -- Specify securityContext on the cluster-agent container.
1336 allowPrivilegeEscalation: false
1337 readOnlyRootFilesystem: true
1339 # clusterAgent.containers.initContainers.securityContext -- Specify securityContext on the initContainers.
1341 # clusterAgent.containers.initContainers.resources -- Resource requests and limits for the Cluster Agent init containers
1349 # clusterAgent.command -- Command to run in the Cluster Agent container as entrypoint
1351 # clusterAgent.token -- Cluster Agent token is a preshared key between node agents and cluster agent (autogenerated if empty, needs to be at least 32 characters a-zA-z)
1353 # clusterAgent.tokenExistingSecret -- Existing secret name to use for Cluster Agent token. Put the Cluster Agent token in a key named `token` inside the Secret
1354 tokenExistingSecret: ""
1355 # clusterAgent.replicas -- Specify the of cluster agent replicas, if > 1 it allow the cluster agent to work in HA mode.
1357 # clusterAgent.revisionHistoryLimit -- The number of old ReplicaSets to keep in this Deployment.
1358 revisionHistoryLimit: 10
1359 ## Provide Cluster Agent Deployment pod(s) RBAC configuration
1361 # clusterAgent.rbac.create -- If true, create & use RBAC resources
1363 # clusterAgent.rbac.flareAdditionalPermissions -- If true, add Secrets and Configmaps get/list permissions to retrieve user Datadog Helm values from Cluster Agent namespace
1364 flareAdditionalPermissions: true
1365 # clusterAgent.rbac.serviceAccountName -- Specify a preexisting ServiceAccount to use if clusterAgent.rbac.create is false
1366 serviceAccountName: default
1367 # clusterAgent.rbac.serviceAccountAnnotations -- Annotations to add to the ServiceAccount if clusterAgent.rbac.create is true
1368 serviceAccountAnnotations: {}
1369 # clusterAgent.rbac.serviceAccountAdditionalLabels -- Labels to add to the ServiceAccount if clusterAgent.rbac.create is true
1370 serviceAccountAdditionalLabels: {}
1371 # clusterAgent.rbac.automountServiceAccountToken -- If true, automatically mount the ServiceAccount's API credentials if clusterAgent.rbac.create is true
1372 automountServiceAccountToken: true
1373 ## Provide Cluster Agent pod security configuration
1376 # clusterAgent.podSecurity.podSecurityPolicy.create -- If true, create a PodSecurityPolicy resource for Cluster Agent pods
1378 securityContextConstraints:
1379 # clusterAgent.podSecurity.securityContextConstraints.create -- If true, create a SCC resource for Cluster Agent pods
1381 # Enable the metricsProvider to be able to scale based on metrics in Datadog
1383 # clusterAgent.metricsProvider.enabled -- Set this to true to enable Metrics Provider
1385 # clusterAgent.metricsProvider.registerAPIService -- Set this to false to disable external metrics registration as an APIService
1386 registerAPIService: true
1387 # clusterAgent.metricsProvider.wpaController -- Enable informer and controller of the watermark pod autoscaler
1389 ## Note: You need to install the `WatermarkPodAutoscaler` CRD before
1390 wpaController: false
1391 # clusterAgent.metricsProvider.useDatadogMetrics -- Enable usage of DatadogMetric CRD to autoscale on arbitrary Datadog queries
1393 ## Note: It will install DatadogMetrics CRD automatically (it may conflict with previous installations)
1394 useDatadogMetrics: false
1395 # clusterAgent.metricsProvider.createReaderRbac -- Create `external-metrics-reader` RBAC automatically (to allow HPA to read data from Cluster Agent)
1396 createReaderRbac: true
1397 # clusterAgent.metricsProvider.aggregator -- Define the aggregator the cluster agent will use to process the metrics. The options are (avg, min, max, sum)
1399 ## Configuration for the service for the cluster-agent metrics server
1401 # clusterAgent.metricsProvider.service.type -- Set type of cluster-agent metrics server service
1403 # clusterAgent.metricsProvider.service.port -- Set port of cluster-agent metrics server service (Kubernetes >= 1.15)
1405 # clusterAgent.metricsProvider.endpoint -- Override the external metrics provider endpoint. If not set, the cluster-agent defaults to `datadog.site`
1406 endpoint: # https://api.datadoghq.com
1407 # clusterAgent.env -- Set environment variables specific to Cluster Agent
1409 ## The Cluster-Agent supports many additional environment variables
1410 ## ref: https://docs.datadoghq.com/agent/cluster_agent/commands/#cluster-agent-options
1412 # clusterAgent.envFrom -- Set environment variables specific to Cluster Agent from configMaps and/or secrets
1414 ## The Cluster-Agent supports many additional environment variables
1415 ## ref: https://docs.datadoghq.com/agent/cluster_agent/commands/#cluster-agent-options
1418 # name: <CONFIGMAP_NAME>
1420 # name: <SECRET_NAME>
1422 # clusterAgent.envDict -- Set environment variables specific to Cluster Agent defined in a dict
1424 # <ENV_VAR_NAME>: <ENV_VAR_VALUE>
1426 admissionController:
1427 # clusterAgent.admissionController.enabled -- Enable the admissionController to be able to inject APM/Dogstatsd config and standard tags (env, service, version) automatically into your pods
1429 # clusterAgent.admissionController.validation -- Validation Webhook configuration options
1431 # clusterAgent.admissionController.validation.enabled -- Enabled enables the Admission Controller validation webhook. Default: true. (Requires Agent 7.59.0+).
1433 # clusterAgent.admissionController.mutation -- Mutation Webhook configuration options
1435 # clusterAgent.admissionController.mutation.enabled -- Enabled enables the Admission Controller mutation webhook. Default: true. (Requires Agent 7.59.0+).
1437 # clusterAgent.admissionController.webhookName -- Name of the validatingwebhookconfiguration and mutatingwebhookconfiguration created by the cluster-agent
1438 webhookName: datadog-webhook
1439 # clusterAgent.admissionController.mutateUnlabelled -- Enable injecting config without having the pod label 'admission.datadoghq.com/enabled="true"'
1440 mutateUnlabelled: false
1441 # clusterAgent.admissionController.configMode -- The kind of configuration to be injected, it can be "hostip", "service", "socket" or "csi".
1443 ## If clusterAgent.admissionController.configMode is not set:
1444 ## * and datadog.apm.socketEnabled is true, the Admission Controller uses socket.
1445 ## * and datadog.apm.portEnabled is true, the Admission Controller uses hostip.
1446 ## * and datadog.apm.useLocalService is true and the aformentioned two are false, the Admission Controller uses service.
1447 ## * Otherwise, the Admission Controller defaults to hostip.
1448 ## Note: "service" mode relies on the internal traffic service to target the agent running on the local node (requires Kubernetes v1.22+).
1449 ## Note: "csi" mode requires enabling csi with `datadog.csi.enabled`. If not set, the admission controller will fallback to "socket" mode.
1450 ## Note: "csi" mode requires version 7.65 or later of the cluster agent.
1451 ## ref: https://docs.datadoghq.com/agent/cluster_agent/admission_controller/#configure-apm-and-dogstatsd-communication-mode
1452 configMode: # "hostip", "socket", "csi" or "service"
1453 # clusterAgent.admissionController.failurePolicy -- Set the failure policy for dynamic admission control.'
1455 ## The default of Ignore means that pods will still be admitted even if the webhook is unavailable to inject them.
1456 ## Setting to Fail will require the admission controller to be present and pods to be injected before they are allowed to run.
1457 failurePolicy: Ignore
1458 # clusterAgent.admissionController.containerRegistry -- Override the default registry for the admission controller.
1460 ## The clusterAgent uses this configuration for apm.instrumentation, agentSidecar, and cwsInstrumentation, if
1461 ## not otherwise specified.
1463 remoteInstrumentation:
1464 # clusterAgent.admissionController.remoteInstrumentation.enabled -- Enable polling and applying library injection using Remote Config.
1465 ## This feature is in beta, and enables Remote Config in the Cluster Agent. It also requires Cluster Agent version 7.43+.
1466 ## Enabling this feature grants the Cluster Agent the permissions to patch Deployment objects in the cluster.
1468 # clusterAgent.admissionController.port -- Set port of cluster-agent admission controller service
1471 # clusterAgent.admissionController.cwsInstrumentation.enabled -- Enable the CWS Instrumentation admission controller endpoint.
1473 # clusterAgent.admissionController.cwsInstrumentation.mode -- Mode defines how the CWS Instrumentation should behave.
1474 # Options are "remote_copy" or "init_container"
1476 kubernetesAdmissionEvents:
1477 # clusterAgent.admissionController.kubernetesAdmissionEvents.enabled -- Enable the Kubernetes Admission Events feature.
1480 # clusterAgent.admissionController.probe.enabled -- Enable the admission controller connectivity probe.
1481 ## The probe periodically sends dry-run ConfigMap creation requests to verify the webhook is reachable from the API server.
1482 ## (Requires Cluster Agent 7.78.0+).
1484 # clusterAgent.admissionController.probe.interval -- Seconds between probe executions.
1486 # clusterAgent.admissionController.probe.gracePeriod -- Seconds to wait at startup before the first probe.
1488 agentSidecarInjection:
1489 # clusterAgent.admissionController.agentSidecarInjection.enabled -- Enables Datadog Agent sidecar injection.
1491 ## When enabled, the admission controller mutating webhook will inject an Agent sidecar with minimal configuration in every pod meeting the configured criteria.
1493 # clusterAgent.admissionController.agentSidecarInjection.provider -- Used by the admission controller to add infrastructure provider-specific configurations to the Agent sidecar.
1495 ## Currently only "fargate" is supported. To use the feature in other environments (including local testing) omit the config.
1496 ## ref: https://docs.datadoghq.com/integrations/eks_fargate
1498 # clusterAgent.admissionController.agentSidecarInjection.clusterAgentCommunicationEnabled -- Enable communication between Agent sidecars and the Cluster Agent.
1499 clusterAgentCommunicationEnabled: true
1500 # clusterAgent.admissionController.agentSidecarInjection.clusterAgentTlsVerification -- TLS verification configuration for sidecar-to-cluster-agent communication.
1501 clusterAgentTlsVerification:
1502 # clusterAgent.admissionController.agentSidecarInjection.clusterAgentTlsVerification.enabled -- Enable TLS verification for Agent sidecars communicating with the Cluster Agent.
1504 # clusterAgent.admissionController.agentSidecarInjection.clusterAgentTlsVerification.copyCaConfigMap -- Enable automatic creation of a ConfigMap containing the Cluster Agent's CA certificate in namespaces where sidecar injection occurs.
1505 copyCaConfigMap: false
1506 # clusterAgent.admissionController.agentSidecarInjection.containerRegistry -- Override the default registry for the sidecar Agent.
1508 # clusterAgent.admissionController.imageName -- Override the default agents.image.name for the Agent sidecar.
1510 # clusterAgent.admissionController.imageTag -- Override the default agents.image.tag for the Agent sidecar.
1512 # clusterAgent.admissionController.agentSidecarInjection.selectors -- Defines the pod selector for sidecar injection, currently only one rule is supported.
1516 # "podlabelKey1": podlabelValue1
1517 # "podlabelKey2": podlabelValue2
1518 # namespaceSelector:
1520 # "nsLabelKey1": nsLabelValue1
1521 # "nsLabelKey2": nsLabelValue2
1523 # clusterAgent.admissionController.agentSidecarInjection.profiles -- Defines the sidecar configuration override, currently only one profile is supported.
1525 ## This setting allows overriding the sidecar Agent configuration by adding environment variables and providing resource settings.
1528 # - name: DD_ORCHESTRATOR_EXPLORER_ENABLED
1537 # clusterAgent.confd -- Provide additional cluster check configurations. Each key will become a file in /conf.d.
1539 ## ref: https://docs.datadoghq.com/agent/autodiscovery/
1542 # cluster_check: true
1544 # - host: <EXTERNAL_IP>
1547 # password: <YOUR_CHOSEN_PASSWORD>
1549 # clusterAgent.advancedConfd -- Provide additional cluster check configurations. Each key is an integration containing several config files.
1551 ## ref: https://docs.datadoghq.com/agent/autodiscovery/
1555 # cluster_check: true
1557 # - host: <EXTERNAL_IP>
1560 # password: <YOUR_CHOSEN_PASSWORD>
1562 # cluster_check: true
1564 # - host: <EXTERNAL_IP>
1567 # password: <YOUR_CHOSEN_PASSWORD>
1569 ## clusterAgent.kubernetesApiserverCheck -- correspond to options for configuring the kube_apiserver integration.
1570 kubernetesApiserverCheck:
1571 # clusterAgent.kubernetesApiserverCheck.disableUseComponentStatus -- Set this to true to disable use_component_status for the kube_apiserver integration.
1572 disableUseComponentStatus: false
1573 # clusterAgent.resources -- Datadog cluster-agent resource requests and limits.
1582 # clusterAgent.priorityClassName -- Name of the priorityClass to apply to the Cluster Agent
1583 priorityClassName: # system-cluster-critical
1584 # clusterAgent.nodeSelector -- Allow the Cluster Agent Deployment to be scheduled on selected nodes
1586 ## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#nodeselector
1587 ## Ref: https://kubernetes.io/docs/user-guide/node-selection/
1589 # clusterAgent.tolerations -- Allow the Cluster Agent Deployment to schedule on tainted nodes ((requires Kubernetes >= 1.6))
1591 ## Ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/
1593 # clusterAgent.affinity -- Allow the Cluster Agent Deployment to schedule using affinity rules
1595 ## By default, Cluster Agent Deployment Pods are forced to run on different Nodes.
1596 ## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity
1598 # clusterAgent.topologySpreadConstraints -- Allow the Cluster Agent Deployment to schedule using pod topology spreading
1600 ## By default, no constraints are set, allowing cluster defaults to be used for scheduling
1601 ## Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
1602 topologySpreadConstraints: []
1603 # clusterAgent.healthPort -- Port number to use in the Cluster Agent for the healthz endpoint
1605 privateActionRunner:
1606 # clusterAgent.privateActionRunner.enabled -- Enable the Private Action Runner to execute workflow actions
1608 # clusterAgent.privateActionRunner.selfEnroll -- Enable self-enrollment for the Private Action Runner
1609 ## When enabled, the runner will automatically register itself with Datadog using the provided API/APP keys
1610 ## and store its identity in a Kubernetes secret. Requires leader election to be enabled.
1612 # clusterAgent.privateActionRunner.identitySecretName -- Name of the Kubernetes secret used to store PAR identity when self-enrollment is enabled
1613 ## The Cluster Agent will create and manage this secret for storing the enrolled runner's URN and private key
1614 ## RBAC permissions are granted specifically for this secret name
1615 identitySecretName: "datadog-private-action-runner-identity"
1616 # clusterAgent.privateActionRunner.urn -- URN of the Private Action Runner (required if selfEnroll is false)
1617 ## Format: urn:datadog:private-action-runner:organization:<org_id>:runner:<runner_id>
1618 urn: # "urn:datadog:private-action-runner:organization:123456:runner:abc-def"
1619 # clusterAgent.privateActionRunner.privateKey -- Private key for the Private Action Runner (required if selfEnroll is false)
1620 ## This key is used to authenticate the runner with Datadog
1621 privateKey: # "<PRIVATE_KEY>"
1622 # clusterAgent.privateActionRunner.identityFromExistingSecret -- Use existing Secret which stores the Private Action Runner URN and private key
1623 ## The secret should contain 'urn' and 'private_key' keys
1624 ## If set, this parameter takes precedence over "urn" and "privateKey"
1625 identityFromExistingSecret: # "<PAR_SECRET_NAME>"
1626 # clusterAgent.privateActionRunner.actionsAllowlist -- List of actions executable by the Private Action Runner
1627 actionsAllowlist: []
1628 # - "com.datadoghq.http.request"
1629 # - "com.datadoghq.kubernetes.core.*"
1631 # clusterAgent.privateActionRunner.apiKeyOnlyEnrollment -- Enroll using only the API key, without requiring an app key
1632 apiKeyOnlyEnrollment: false
1633 # clusterAgent.privateActionRunner.k8sRemediationEnabled -- Enable k8s remediation RBAC for the Private Action Runner
1634 ## When enabled, a ClusterRole and ClusterRoleBinding are created granting the Cluster Agent
1635 ## permissions to read/patch workloads (Deployments, DaemonSets, StatefulSets, ReplicaSets, Pods)
1636 ## and manage ConfigMaps and Events cluster-wide.
1637 k8sRemediationEnabled: false
1638 # clusterAgent.livenessProbe -- Override default Cluster Agent liveness probe settings
1639 # @default -- Every 15s / 6 KO / 1 OK
1641 initialDelaySeconds: 15
1646 # clusterAgent.readinessProbe -- Override default Cluster Agent readiness probe settings
1647 # @default -- Every 15s / 6 KO / 1 OK
1649 initialDelaySeconds: 15
1654 # clusterAgent.startupProbe -- Override default Cluster Agent startup probe settings
1655 # @default -- Every 15s / 6 KO / 1 OK
1657 initialDelaySeconds: 15
1662 # clusterAgent.strategy -- Allow the Cluster Agent deployment to perform a rolling update on helm update
1664 ## ref: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#strategy
1670 # clusterAgent.deploymentAnnotations -- Annotations to add to the cluster-agents's deployment
1671 deploymentAnnotations: {}
1674 # clusterAgent.podAnnotations -- Annotations to add to the cluster-agents's pod(s)
1678 # clusterAgent.useHostNetwork -- Bind ports on the hostNetwork
1680 ## Useful for CNI networking where hostPort might
1681 ## not be supported. The ports need to be available on all hosts. It can be
1682 ## used for custom metrics instead of a service endpoint.
1684 ## WARNING: Make sure that hosts using this are properly firewalled otherwise
1685 ## metrics and traces are accepted from any host able to connect to this host.
1687 useHostNetwork: false
1688 # clusterAgent.dnsConfig -- Specify dns configuration options for datadog cluster agent containers e.g ndots
1690 ## ref: https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config
1696 # clusterAgent.volumes -- Specify additional volumes to mount in the cluster-agent container
1700 # name: <VOLUME_NAME>
1702 # clusterAgent.volumeMounts -- Specify additional volumes to mount in the cluster-agent container
1704 # - name: <VOLUME_NAME>
1705 # mountPath: <CONTAINER_PATH>
1708 # clusterAgent.datadog_cluster_yaml -- Specify custom contents for the datadog cluster agent config (datadog-cluster.yaml)
1709 datadog_cluster_yaml: {}
1710 # clusterAgent.createPodDisruptionBudget -- Create pod disruption budget for Cluster Agent deployments
1711 # DEPRECATED. Use clusterAgent.pdb.create instead
1712 createPodDisruptionBudget: false
1714 # clusterAgent.pdb.create -- Enable pod disruption budget for Cluster Agent deployments.
1716 ## Only one of `minAvailable` or `maxUnavailable` can be set. More information: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
1717 ## By default, minAvailable is set to 1 for cluster agent.
1719 # clusterAgent.pdb.minAvailable -- Minimum number of pods that must remain available during a disruption -- default to 1
1721 # clusterAgent.pdb.maxUnavailable -- Maximum number of pods that can be unavailable during a disruption
1724 # clusterAgent.networkPolicy.create -- If true, create a NetworkPolicy for the cluster agent.
1725 # DEPRECATED. Use datadog.networkPolicy.create instead
1727 # clusterAgent.additionalLabels -- Adds labels to the Cluster Agent deployment and pods
1728 additionalLabels: {}
1731 # clusterAgent.instanceLabelOverride -- Override the `app.kubernetes.io/instance` label on the Cluster Agent deployment and pods. Useful to restore the pre-3.140.0 value when callers (e.g. NetworkPolicies) match on that label.
1732 instanceLabelOverride: # "datadog"
1733 # clusterAgent.containerExclude -- Exclude containers from the Cluster Agent
1734 # Autodiscovery, as a space-separated list. (Requires Agent/Cluster Agent 7.50.0+)
1736 ## ref: https://docs.datadoghq.com/agent/guide/autodiscovery-management/?tab=containerizedagent#exclude-containers
1737 containerExclude: # "image:datadog/agent"
1738 # clusterAgent.containerInclude -- Include containers in the Cluster Agent Autodiscovery,
1739 # as a space-separated list. If a container matches an include rule, it’s
1740 # always included in the Autodiscovery. (Requires Agent/Cluster Agent 7.50.0+)
1742 ## ref: https://docs.datadoghq.com/agent/guide/autodiscovery-management/?tab=containerizedagent#include-containers
1744 # clusterAgent.celWorkloadExclude -- Exclude workloads using a CEL-based definition in the Cluster Agent. (Requires Agent 7.73.0+)
1745 # ref: https://docs.datadoghq.com/containers/guide/container-discovery-management/
1747## This section lets you configure the agents deployed by this chart to connect to a Cluster Agent
1748## deployed independently
1749existingClusterAgent:
1750 # existingClusterAgent.join -- set this to true if you want the agents deployed by this chart to
1751 # connect to a Cluster Agent deployed independently
1753 # existingClusterAgent.tokenSecretName -- Existing secret name to use for external Cluster Agent token
1754 tokenSecretName: # <EXISTING_DCA_SECRET_NAME>
1755 # existingClusterAgent.serviceName -- Existing service name to use for reaching the external Cluster Agent
1756 serviceName: # <EXISTING_DCA_SERVICE_NAME>
1757 # existingClusterAgent.clusterchecksEnabled -- set this to false if you don’t want the agents to run the cluster checks of the joined external cluster agent
1758 clusterchecksEnabled: true
1759# useFIPSAgent -- Setting useFIPSAgent to true makes the helm chart use Agent images that are FIPS-compliant for use in GOVCLOUD environments.
1760# Setting this to true disables the fips-proxy sidecar and is the recommended method for enabling FIPS compliance.
1761# Enable FIPS with this flag; do not embed `-fips` in `agents.image.tag`.
1763## fips is used to enable and configure the fips-proxy sidecar.
1765 # fips.enabled -- Enable fips proxy sidecar.
1766 # The fips-proxy method is getting phased out in favor of FIPS-compliant images (refer to the `useFIPSAgent` setting).
1768 # TODO: Option to override config of the FIPS side car: /etc/datadog-fips-proxy/datadog-fips-proxy.cfg
1769 # customConfig: false
1771 # fips.port -- Specifies which port is used by the containers to communicate to the FIPS sidecar.
1772 # This setting is only used for the fips-proxy sidecar.
1774 # fips.portRange -- Specifies the number of ports used, defaults to 13 https://github.com/DataDog/datadog-agent/blob/7.44.x/pkg/config/config.go#L1564-L1577.
1775 # This setting is only used for the fips-proxy sidecar.
1777 # fips.use_https -- Option to enable https.
1778 # This setting is only used for the fips-proxy sidecar.
1780 # fips.resources -- Resource requests and limits for the FIPS sidecar container.
1781 # This setting is only used for the fips-proxy sidecar.
1790 # fips.local_address -- Set local IP address.
1791 # This setting is only used for the fips-proxy sidecar.
1792 local_address: "127.0.0.1"
1793 ## Define the Datadog image to work with
1795 ## fips.image.name -- Define the FIPS sidecar container image name.
1797 # fips.image.tag -- Define the FIPS sidecar container version to use.
1799 # fips.image.pullPolicy -- Datadog the FIPS sidecar image pull policy
1800 pullPolicy: IfNotPresent
1801 # fips.image.digest -- Define the FIPS sidecar image digest to use, takes precedence over `fips.image.tag` if specified.
1803 # fips.image.repository -- Override default registry + image.name for the FIPS sidecar container.
1805 # fips.customFipsConfig -- Configure a custom configMap to provide the FIPS configuration. Specify custom contents for the FIPS proxy sidecar container config (/etc/datadog-fips-proxy/datadog-fips-proxy.cfg). If empty, the default FIPS proxy sidecar container config is used.
1807 ## Note: Use `|` to declare multi-line configuration.
1808 ## ref: https://docs.datadoghq.com/agent/guide/agent-fips-proxy
1809 customFipsConfig: {} # |
1813 # agents.enabled -- You should keep Datadog DaemonSet enabled!
1815 ## The exceptional case could be a situation when you need to run
1816 ## single Datadog pod per every namespace, but you do not need to
1817 ## re-create a DaemonSet for every non-default namespace install.
1818 ## Note: StatsD and DogStatsD work over UDP, so you may not
1819 ## get guaranteed delivery of the metrics in Datadog-per-namespace setup!
1821 # agents.shareProcessNamespace -- Set the process namespace sharing on the Datadog Daemonset
1822 shareProcessNamespace: false
1823 # agents.revisionHistoryLimit -- The number of ControllerRevision to keep in this DaemonSet.
1824 revisionHistoryLimit: 10
1825 ## Define the Datadog image to work with
1827 # agents.image.name -- Datadog Agent image name to use (relative to `registry`)
1829 ## use "dogstatsd" for Standalone Datadog Agent DogStatsD 7
1830 name: scratch-images/test-tmp/datadog-agent
1831 # agents.image.tag -- Define the Agent version to use
1832 # Set a pinned version here. Do not append build variants: put `full` or `jmx` in `agents.image.tagSuffix`, and enable FIPS with `useFIPSAgent`. To stay on the latest stable Agent, leave this unset and upgrade the chart periodically.
1833 tag: 7.82.3-r0@sha256:862f01af23fd70bc5676b071fc811b68f28315977d6e155a7c9f3b89b6d15ca2
1834 # agents.image.digest -- Define Agent image digest to use, takes precedence over tag if specified
1836 # agents.image.tagSuffix -- Suffix to append to Agent tag
1837 # This is the supported place for build variants like `full` or `jmx`; set them here rather than appending them to `agents.image.tag`.
1840 ## jmx to enable jmx fetch collection
1841 ## servercore to get Windows images based on servercore
1842 ## full to get as many features as possible, currently ddot-collector and jmx
1844 # agents.image.repository -- Override default registry + image.name for Agent
1846 # agents.image.doNotCheckTag -- Skip the version and chart compatibility check
1848 ## By default, the version passed in agents.image.tag is checked
1849 ## for compatibility with the version of the chart.
1850 ## This boolean permits to completely skip this check.
1851 ## This is useful, for example, for custom tags that are not
1852 ## respecting semantic versioning
1853 doNotCheckTag: # false
1854 # agents.image.pullPolicy -- Datadog Agent image pull policy
1855 pullPolicy: IfNotPresent
1856 # agents.image.pullSecrets -- Datadog Agent repository pullSecret (ex: specify docker registry credentials)
1858 ## See https://kubernetes.io/docs/concepts/containers/images/#specifying-imagepullsecrets-on-a-pod
1860 # - name: "<REG_SECRET>"
1861 ## Provide Daemonset RBAC configuration
1863 # agents.rbac.create -- If true, create & use RBAC resources
1865 # agents.rbac.serviceAccountName -- Specify a preexisting ServiceAccount to use if agents.rbac.create is false
1866 serviceAccountName: default
1867 # agents.rbac.serviceAccountAnnotations -- Annotations to add to the ServiceAccount if agents.rbac.create is true
1868 serviceAccountAnnotations: {}
1869 # agents.rbac.serviceAccountAdditionalLabels -- Labels to add to the ServiceAccount if agents.rbac.create is true
1870 serviceAccountAdditionalLabels: {}
1871 # agents.rbac.automountServiceAccountToken -- If true, automatically mount the ServiceAccount's API credentials if agents.rbac.create is true
1872 automountServiceAccountToken: true
1873 ## Provide Daemonset PodSecurityPolicy configuration
1876 # agents.podSecurity.podSecurityPolicy.create -- If true, create a PodSecurityPolicy resource for Agent pods
1878 securityContextConstraints:
1879 # agents.podSecurity.securityContextConstraints.create -- If true, create a SecurityContextConstraints resource for Agent pods
1881 # agents.podSecurity.seLinuxContext -- Provide seLinuxContext configuration for PSP/SCC
1882 # @default -- Must run as spc_t
1890 # agents.podSecurity.privileged -- If true, Allow to run privileged containers
1892 # agents.podSecurity.capabilities -- Allowed capabilities
1894 ## note: capabilities must contain all agents.containers.*.securityContext.capabilities.
1909 # agents.podSecurity.allowedUnsafeSysctls -- Allowed unsafe sysclts
1910 allowedUnsafeSysctls: []
1911 # agents.podSecurity.volumes -- Allowed volumes types
1918 # agents.podSecurity.seccompProfiles -- Allowed seccomp profiles
1921 - "localhost/system-probe"
1923 # agents.podSecurity.apparmor.enabled -- If true, enable apparmor enforcement
1925 ## see: https://kubernetes.io/docs/tutorials/clusters/apparmor/
1927 # agents.podSecurity.apparmorProfiles -- Allowed apparmor profiles
1931 # agents.podSecurity.defaultApparmor -- Default AppArmor profile for all containers but system-probe
1932 defaultApparmor: runtime/default
1935 # agents.containers.agent.env -- Additional environment variables for the agent container
1937 # agents.containers.agent.envFrom -- Set environment variables specific to agent container from configMaps and/or secrets
1940 # name: <CONFIGMAP_NAME>
1942 # name: <SECRET_NAME>
1944 # agents.containers.agent.envDict -- Set environment variables specific to agent container defined in a dict
1946 # <ENV_VAR_NAME>: <ENV_VAR_VALUE>
1948 # agents.containers.agent.logLevel -- Set logging verbosity, valid log levels are: trace, debug, info, warn, error, critical, and off.
1949 # If not set, fall back to the value of datadog.logLevel.
1951 # agents.containers.agent.resources -- Resource requests and limits for the agent container.
1960 # agents.containers.agent.healthPort -- Port number to use in the node agent for the healthz endpoint
1962 # agents.containers.agent.livenessProbe -- Override default agent liveness probe settings
1963 # @default -- Every 15s / 6 KO / 1 OK
1965 initialDelaySeconds: 15
1970 # agents.containers.agent.readinessProbe -- Override default agent readiness probe settings
1971 # @default -- Every 15s / 6 KO / 1 OK
1973 initialDelaySeconds: 15
1978 # agents.containers.agent.startupProbe -- Override default agent startup probe settings
1979 # @default -- Every 15s / 6 KO / 1 OK
1981 initialDelaySeconds: 15
1986 # agents.containers.agent.securityContext -- Allows you to overwrite the default container SecurityContext for the agent container.
1988 readOnlyRootFilesystem: true
1989 # agents.containers.agent.ports -- Allows to specify extra ports (hostPorts for instance) for this container
1991 # agents.containers.agent.command -- Override the default `agent run` entrypoint for the agent container.
1992 # Useful for wrapping the agent in a shell entrypoint (e.g. to set environment variables based on
1993 # node-level information before `exec`-ing the agent). When unset, the container runs `agent run`.
1994 # Not supported on GKE Autopilot or GDC: the Datadog WorkloadAllowlist requires the agent container
1995 # command to be exactly `["agent", "run"]` on those providers, so setting this value with
1996 # `providers.gke.autopilot=true` or `providers.gke.gdc=true` fails at template render time.
1998 privateActionRunner:
1999 # agents.containers.privateActionRunner.env -- Additional environment variables for the private-action-runner container
2001 # agents.containers.privateActionRunner.envFrom -- Set environment variables specific to private-action-runner from configMaps and/or secrets
2003 # agents.containers.privateActionRunner.envDict -- Set environment variables specific to private-action-runner defined in a dict
2005 # agents.containers.privateActionRunner.logLevel -- Set logging verbosity for the private-action-runner container
2007 # agents.containers.privateActionRunner.resources -- Resource requests and limits for the private-action-runner container.
2016 # agents.containers.privateActionRunner.securityContext -- Specify securityContext on the private-action-runner container.
2018 readOnlyRootFilesystem: true
2022 # agents.containers.processAgent.env -- Additional environment variables for the process-agent container
2024 # agents.containers.processAgent.envFrom -- Set environment variables specific to process-agent from configMaps and/or secrets
2027 # name: <CONFIGMAP_NAME>
2029 # name: <SECRET_NAME>
2031 # agents.containers.processAgent.envDict -- Set environment variables specific to process-agent defined in a dict
2033 # <ENV_VAR_NAME>: <ENV_VAR_VALUE>
2035 # agents.containers.processAgent.logLevel -- Set logging verbosity, valid log levels are: trace, debug, info, warn, error, critical, and off.
2036 # If not set, fall back to the value of datadog.logLevel.
2038 # agents.containers.processAgent.resources -- Resource requests and limits for the process-agent container
2047 # agents.containers.processAgent.securityContext -- Allows you to overwrite the default container SecurityContext for the process-agent container.
2049 readOnlyRootFilesystem: true
2050 # agents.containers.processAgent.ports -- Allows to specify extra ports (hostPorts for instance) for this container
2053 # agents.containers.otelAgent.env -- Additional environment variables for the otel-agent container
2055 # agents.containers.otelAgent.envFrom -- Set environment variables specific to otel-agent from configMaps and/or secrets
2058 # name: <CONFIGMAP_NAME>
2060 # name: <SECRET_NAME>
2062 # agents.containers.otelAgent.envDict -- Set environment variables specific to otel-agent defined in a dict
2064 # <ENV_VAR_NAME>: <ENV_VAR_VALUE>
2066 # agents.containers.otelAgent.resources -- Resource requests and limits for the otel-agent container
2075 # agents.containers.otelAgent.securityContext -- Allows you to overwrite the default container SecurityContext for the otel-agent container.
2077 readOnlyRootFilesystem: true
2078 # agents.containers.otelAgent.ports -- Allows to specify extra ports (hostPorts for instance) for this container
2080 # agents.containers.otelAgent.volumeMounts -- Specify additional volumes to mount in the otel-agent container
2082 # - name: <VOLUME_NAME>
2083 # mountPath: <CONTAINER_PATH>
2086 # agents.containers.hostProfiler.env -- Additional environment variables for the host-profiler container
2088 # agents.containers.hostProfiler.envFrom -- Set environment variables specific to host-profiler from configMaps and/or secrets
2091 # name: <CONFIGMAP_NAME>
2093 # name: <SECRET_NAME>
2095 # agents.containers.hostProfiler.envDict -- Set environment variables specific to host-profiler defined in a dict
2097 # <ENV_VAR_NAME>: <ENV_VAR_VALUE>
2099 # agents.containers.hostProfiler.resources -- Resource requests and limits for the host-profiler container
2108 # agents.containers.hostProfiler.securityContext -- Allows you to overwrite the default container SecurityContext for the host-profiler container.
2110 readOnlyRootFilesystem: true
2111 allowPrivilegeEscalation: false
2113 # spc_t so SELinux-enforcing nodes don't block host-profiler's cross-process /proc access.
2126 - CHECKPOINT_RESTORE
2128 # agents.containers.hostProfiler.volumeMounts -- Specify additional volumes to mount in the host-profiler container
2130 # - name: <VOLUME_NAME>
2131 # mountPath: <CONTAINER_PATH>
2134 # agents.containers.traceAgent.env -- Additional environment variables for the trace-agent container
2136 # agents.containers.traceAgent.envFrom -- Set environment variables specific to trace-agent from configMaps and/or secrets
2139 # name: <CONFIGMAP_NAME>
2141 # name: <SECRET_NAME>
2143 # agents.containers.traceAgent.envDict -- Set environment variables specific to trace-agent defined in a dict
2145 # <ENV_VAR_NAME>: <ENV_VAR_VALUE>
2147 # agents.containers.traceAgent.logLevel -- Set logging verbosity, valid log levels are: trace, debug, info, warn, error, critical, and off
2149 # agents.containers.traceAgent.resources -- Resource requests and limits for the trace-agent container
2158 # agents.containers.traceAgent.livenessProbe -- Override default agent liveness probe settings
2159 # @default -- Every 15s
2161 initialDelaySeconds: 15
2164 # agents.containers.traceAgent.securityContext -- Allows you to overwrite the default container SecurityContext for the trace-agent container.
2166 readOnlyRootFilesystem: true
2167 # agents.containers.traceAgent.ports -- Allows to specify extra ports (hostPorts for instance) for this container
2170 # agents.containers.systemProbe.env -- Additional environment variables for the system-probe container
2172 # agents.containers.systemProbe.envFrom -- Set environment variables specific to system-probe from configMaps and/or secrets
2175 # name: <CONFIGMAP_NAME>
2177 # name: <SECRET_NAME>
2179 # agents.containers.systemProbe.envDict -- Set environment variables specific to system-probe defined in a dict
2181 # <ENV_VAR_NAME>: <ENV_VAR_VALUE>
2183 # agents.containers.systemProbe.logLevel -- Set logging verbosity, valid log levels are: trace, debug, info, warn, error, critical, and off.
2184 # If not set, fall back to the value of datadog.logLevel.
2186 # agents.containers.systemProbe.resources -- Resource requests and limits for the system-probe container
2195 # agents.containers.systemProbe.securityContext -- Allows you to overwrite the default container SecurityContext for the system-probe container.
2197 ## agents.podSecurity.capabilities must reflect the changed made in securityContext.capabilities.
2199 readOnlyRootFilesystem: true
2202 add: ["SYS_ADMIN", "SYS_RESOURCE", "SYS_PTRACE", "NET_ADMIN", "NET_BROADCAST", "NET_RAW", "IPC_LOCK", "CHOWN", "DAC_READ_SEARCH"]
2203 # agents.containers.systemProbe.ports -- Allows to specify extra ports (hostPorts for instance) for this container
2206 # agents.containers.securityAgent.env -- Additional environment variables for the security-agent container
2208 # agents.containers.securityAgent.envFrom -- Set environment variables specific to security-agent from configMaps and/or secrets
2211 # name: <CONFIGMAP_NAME>
2213 # name: <SECRET_NAME>
2215 # agents.containers.securityAgent.envDict -- Set environment variables specific to security-agent defined in a dict
2217 # <ENV_VAR_NAME>: <ENV_VAR_VALUE>
2219 # agents.containers.securityAgent.logLevel -- Set logging verbosity, valid log levels are: trace, debug, info, warn, error, critical, and off.
2220 # If not set, fall back to the value of datadog.logLevel.
2222 # agents.containers.securityAgent.resources -- Resource requests and limits for the security-agent container
2231 # agents.containers.securityAgent.securityContext -- Allows you to overwrite the default container SecurityContext for the security-agent container.
2233 readOnlyRootFilesystem: true
2234 # agents.containers.securityAgent.ports -- Allows to specify extra ports (hostPorts for instance) for this container
2237 # agents.containers.agentDataPlane.env -- Additional environment variables for the agent-data-plane container
2239 # agents.containers.agentDataPlane.envFrom -- Set environment variables specific to agent-data-plane container from configMaps and/or secrets
2242 # name: <CONFIGMAP_NAME>
2244 # name: <SECRET_NAME>
2246 # agents.containers.agentDataPlane.envDict -- Set environment variables specific to agent-data-plane container defined in a dict
2248 # <ENV_VAR_NAME>: <ENV_VAR_VALUE>
2250 # agents.containers.agentDataPlane.logLevel -- Set logging verbosity, valid log levels are: trace, debug, info, warn, error, critical, and off.
2251 # If not set, fall back to the value of datadog.logLevel.
2253 # agents.containers.agentDataPlane.resources -- Resource requests and limits for the agent-data-plane container
2262 # agents.containers.agentDataPlane.unprivilegedApiPort -- Port for unprivileged API server, used primarily for health checks
2263 unprivilegedApiPort: 5100
2264 # agents.containers.agentDataPlane.privilegedApiPort -- Port for privileged API server, used for lower-level operations that
2265 # can alter the state of the ADP process or expose internal information
2266 privilegedApiPort: 5101
2267 # agents.containers.agentDataPlane.telemetryApiPort -- Port for telemetry API server, used for exposing internal
2268 # telemetry to be scraped by the Agent
2269 telemetryApiPort: 5102
2270 # agents.containers.agentDataPlane.livenessProbe -- Override default agent-data-plane liveness probe settings
2271 # @default -- Every 5s / 12 KO / 1 OK
2273 initialDelaySeconds: 5
2277 failureThreshold: 12
2278 # agents.containers.agentDataPlane.readinessProbe -- Override default agent-data-plane readiness probe settings
2279 # @default -- Every 5s / 12 KO / 1 OK
2281 initialDelaySeconds: 5
2285 failureThreshold: 12
2286 # agents.containers.agentDataPlane.securityContext -- Allows you to overwrite the default container SecurityContext for the agent-data-plane container.
2288 readOnlyRootFilesystem: true
2289 # agents.containers.agentDataPlane.ports -- Allows to specify extra ports (hostPorts for instance) for this container
2292 # agents.containers.initContainers.resources -- Resource requests and limits for the init containers
2300 # agents.containers.initContainers.securityContext -- Allows you to overwrite the default container SecurityContext for the init containers.
2302 # agents.containers.initContainers.volumeMounts -- Specify additional volumes to mount for the init containers
2304 # agents.volumes -- Specify additional volumes to mount in the dd-agent container
2308 # name: <VOLUME_NAME>
2310 # agents.volumeMounts -- Specify additional volumes to mount in all containers of the agent pod
2312 # - name: <VOLUME_NAME>
2313 # mountPath: <CONTAINER_PATH>
2316 # agents.useHostNetwork -- Bind ports on the hostNetwork
2318 ## Useful for CNI networking where hostPort might
2319 ## not be supported. The ports need to be available on all hosts. It Can be
2320 ## used for custom metrics instead of a service endpoint.
2322 ## WARNING: Make sure that hosts using this are properly firewalled otherwise
2323 ## metrics and traces are accepted from any host able to connect to this host.
2324 useHostNetwork: false
2325 # agents.dnsConfig -- specify dns configuration options for datadog cluster agent containers e.g ndots
2327 ## ref: https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config
2333 # agents.daemonsetAnnotations -- Annotations to add to the DaemonSet
2334 daemonsetAnnotations: {}
2337 # agents.podAnnotations -- Annotations to add to the DaemonSet's Pods
2341 # agents.tolerations -- Allow the DaemonSet to schedule on tainted nodes (requires Kubernetes >= 1.6)
2343 # agents.nodeSelector -- Allow the DaemonSet to schedule on selected nodes
2345 ## Ref: https://kubernetes.io/docs/user-guide/node-selection/
2347 # agents.affinity -- Allow the DaemonSet to schedule using affinity rules
2349 ## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity
2351 # agents.updateStrategy -- Allow the DaemonSet to perform a rolling update on helm update
2353 ## ref: https://kubernetes.io/docs/tasks/manage-daemon/update-daemon-set/
2357 maxUnavailable: "10%"
2358 # agents.priorityClassCreate -- Creates a priorityClass for the Datadog Agent's Daemonset pods.
2359 priorityClassCreate: false
2360 # agents.priorityClassName -- Sets PriorityClassName if defined
2362 # agents.priorityPreemptionPolicyValue -- Set to "Never" to change the PriorityClass to non-preempting
2363 priorityPreemptionPolicyValue: PreemptLowerPriority
2364 # agents.priorityClassValue -- Value used to specify the priority of the scheduling of Datadog Agent's Daemonset pods.
2366 ## The PriorityClass uses PreemptLowerPriority.
2367 priorityClassValue: 1000000000
2368 # agents.podLabels -- Sets podLabels if defined
2370 ## Note: These labels are also used as label selectors so they are immutable.
2372 # agents.additionalLabels -- Adds labels to the Agent daemonset and pods
2373 additionalLabels: {}
2376 # agents.instanceLabelOverride -- Override the `app.kubernetes.io/instance` label on the Agent daemonset and pods. Useful to restore the pre-3.140.0 value when callers (e.g. NetworkPolicies) match on that label.
2377 instanceLabelOverride: # "datadog"
2378 # agents.useConfigMap -- Configures a configmap to provide the agent configuration. Use this in combination with the `agents.customAgentConfig` parameter.
2379 useConfigMap: # false
2380 # agents.customAgentConfig -- Specify custom contents for the datadog agent config (datadog.yaml)
2382 ## ref: https://docs.datadoghq.com/agent/guide/agent-configuration-files/?tab=agentv6
2383 ## ref: https://github.com/DataDog/datadog-agent/blob/main/pkg/config/config_template.yaml
2384 ## Note the `agents.useConfigMap` needs to be set to `true` for this parameter to be taken into account.
2385 customAgentConfig: {}
2387 # # Enable java cgroup handling. Only one of those options should be enabled,
2388 # # depending on the agent version you are using along that chart.
2390 # # agent version < 6.15
2391 # # jmx_use_cgroup_memory_limit: true
2393 # # agent version >= 6.15
2394 # # jmx_use_container_support: true
2397 # agents.networkPolicy.create -- If true, create a NetworkPolicy for the agents.
2398 # DEPRECATED. Use datadog.networkPolicy.create instead
2401 # agents.localService.overrideName -- Name of the internal traffic service to target the agent running on the local node
2403 # agents.localService.forceLocalServiceEnabled -- Force the creation of the internal traffic policy service to target the agent running on the local node.
2404 # By default, the internal traffic service is created only on Kubernetes 1.22+ where the feature became beta and enabled by default.
2405 # This option allows to force the creation of the internal traffic service on kubernetes 1.21 where the feature was alpha and required a feature gate to be explicitly enabled.
2406 forceLocalServiceEnabled: false
2407 # agents.lifecycle -- Configure the lifecycle of the Agent.
2408 # Note: The `exec` lifecycle handler is not supported in GKE Autopilot.
2414 # command: ["/bin/sh", "-c", "sleep 70"]
2417 # command: ["/bin/sh", "-c", "sleep 70"]
2421 # agents.terminationGracePeriodSeconds -- (int) Configure the termination grace period for the Agent
2422 terminationGracePeriodSeconds: # 70
2424 # clusterChecksRunner.enabled -- If true, deploys agent dedicated for running the Cluster Checks instead of running in the Daemonset's agents.
2426 ## If both clusterChecksRunner.enabled and datadog.kubeStateMetricsCore.enabled are true, consider enabling datadog.kubeStateMetricsCore.useClusterCheckRunners as well.
2427 ## If datadog.kubeStateMetricsCore.useClusterCheckRunners is enabled, it's recommended to enable this flag as well so all Cluster Checks run on Cluster Checks Runners instead of node agents.
2428 ## ref: https://docs.datadoghq.com/agent/autodiscovery/clusterchecks/
2430 remoteConfiguration:
2431 # clusterChecksRunner.remoteConfiguration.enabled -- Enable remote configuration on the Cluster Checks Runner.
2432 # Set to true to enable remote configuration on the Cluster Checks Runner.
2434 ## Define the Datadog image to work with.
2436 # clusterChecksRunner.image.name -- Datadog Agent image name to use (relative to `registry`)
2437 name: scratch-images/test-tmp/datadog-agent
2438 # clusterChecksRunner.image.tag -- Define the Agent version to use
2439 tag: 7.82.3-r0@sha256:862f01af23fd70bc5676b071fc811b68f28315977d6e155a7c9f3b89b6d15ca2
2440 # clusterChecksRunner.image.digest -- Define Agent image digest to use, takes precedence over tag if specified
2442 # clusterChecksRunner.image.tagSuffix -- Suffix to append to Agent tag
2445 ## jmx to enable jmx fetch collection
2446 ## servercore to get Windows images based on servercore
2448 # clusterChecksRunner.image.repository -- Override default registry + image.name for Cluster Check Runners
2450 # clusterChecksRunner.image.pullPolicy -- Datadog Agent image pull policy
2451 pullPolicy: IfNotPresent
2452 # clusterChecksRunner.image.pullSecrets -- Datadog Agent repository pullSecret (ex: specify docker registry credentials)
2454 ## See https://kubernetes.io/docs/concepts/containers/images/#specifying-imagepullsecrets-on-a-pod
2456 # - name: "<REG_SECRET>"
2457 # clusterChecksRunner.createPodDisruptionBudget -- Create the pod disruption budget to apply to the cluster checks agents
2458 # DEPRECATED. Use clusterChecksRunner.pdb.create instead
2459 createPodDisruptionBudget: false
2461 # clusterChecksRunner.pdb.create -- Enable pod disruption budget for Cluster Checks Runner deployments.
2463 ## Only one of `minAvailable` or `maxUnavailable` can be set. More information: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
2464 ## By default, maxUnavailable is set to 1 for cluster checks runners.
2466 # clusterChecksRunner.pdb.minAvailable -- Minimum number of pods that must remain available during a disruption
2468 # clusterChecksRunner.pdb.maxUnavailable -- Maximum number of pods that can be unavailable during a disruption
2470 # Provide Cluster Checks Deployment pods RBAC configuration
2472 # clusterChecksRunner.rbac.create -- If true, create & use RBAC resources
2474 # clusterChecksRunner.rbac.dedicated -- If true, use a dedicated RBAC resource for the cluster checks agent(s)
2476 # clusterChecksRunner.rbac.serviceAccountAnnotations -- Annotations to add to the ServiceAccount if clusterChecksRunner.rbac.dedicated is true
2477 serviceAccountAnnotations: {}
2478 # clusterChecksRunner.rbac.serviceAccountAdditionalLabels -- Labels to add to the ServiceAccount if clusterChecksRunner.rbac.dedicated is true
2479 serviceAccountAdditionalLabels: {}
2480 # clusterChecksRunner.rbac.automountServiceAccountToken -- If true, automatically mount the ServiceAccount's API credentials if clusterChecksRunner.rbac.create is true
2481 automountServiceAccountToken: true
2482 # clusterChecksRunner.rbac.serviceAccountName -- Specify a preexisting ServiceAccount to use if clusterChecksRunner.rbac.create is false
2483 serviceAccountName: default
2484 # clusterChecksRunner.replicas -- Number of Cluster Checks Runner instances
2486 ## If you want to deploy the clusterChecks agent in HA, keep at least clusterChecksRunner.replicas set to 2.
2487 ## And increase the clusterChecksRunner.replicas according to the number of Cluster Checks.
2489 # clusterChecksRunner.revisionHistoryLimit -- The number of old ReplicaSets to keep in this Deployment.
2490 revisionHistoryLimit: 10
2491 # clusterChecksRunner.resources -- Datadog clusterchecks-agent resource requests and limits.
2500 # clusterChecksRunner.affinity -- Allow the ClusterChecks Deployment to schedule using affinity rules.
2502 ## By default, ClusterChecks Deployment Pods are preferred to run on different Nodes.
2503 ## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity
2505 # clusterChecksRunner.topologySpreadConstraints -- Allow the ClusterChecks Deployment to schedule using pod topology spreading
2507 ## By default, no constraints are set, allowing cluster defaults to be used for scheduling
2508 ## Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
2509 topologySpreadConstraints: []
2510 # clusterChecksRunner.strategy -- Allow the ClusterChecks deployment to perform a rolling update on helm update
2512 ## ref: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#strategy
2518 # clusterChecksRunner.dnsConfig -- specify dns configuration options for datadog cluster agent containers e.g ndots
2520 ## ref: https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config
2526 # clusterChecksRunner.priorityClassName -- Name of the priorityClass to apply to the Cluster checks runners
2527 priorityClassName: # system-cluster-critical
2528 # clusterChecksRunner.nodeSelector -- Allow the ClusterChecks Deployment to schedule on selected nodes
2530 ## Ref: https://kubernetes.io/docs/user-guide/node-selection/
2532 # clusterChecksRunner.tolerations -- Tolerations for pod assignment
2534 ## Ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/
2536 # clusterChecksRunner.healthPort -- Port number to use in the Cluster Checks Runner for the healthz endpoint
2538 # clusterChecksRunner.livenessProbe -- Override default agent liveness probe settings
2539 # @default -- Every 15s / 6 KO / 1 OK
2541 ## In case of issues with the probe, you can disable it with the
2542 ## following values, to allow easier investigating:
2546 # command: ["/bin/true"]
2549 initialDelaySeconds: 15
2554 # clusterChecksRunner.readinessProbe -- Override default agent readiness probe settings
2555 # @default -- Every 15s / 6 KO / 1 OK
2557 ## In case of issues with the probe, you can disable it with the
2558 ## following values, to allow easier investigating:
2562 # command: ["/bin/true"]
2565 initialDelaySeconds: 15
2570 # clusterChecksRunner.startupProbe -- Override default agent startup probe settings
2571 # @default -- Every 15s / 6 KO / 1 OK
2573 ## In case of issues with the probe, you can disable it with the
2574 ## following values, to allow easier investigating:
2578 # command: ["/bin/true"]
2581 initialDelaySeconds: 15
2586 # clusterChecksRunner.deploymentAnnotations -- Annotations to add to the cluster-checks-runner's Deployment
2587 deploymentAnnotations: {}
2590 # clusterChecksRunner.podAnnotations -- Annotations to add to the cluster-checks-runner's pod(s)
2594 # clusterChecksRunner.env -- Environment variables specific to Cluster Checks Runner
2596 ## ref: https://github.com/DataDog/datadog-agent/tree/main/Dockerfiles/agent#environment-variables
2598 # - name: <ENV_VAR_NAME>
2599 # value: <ENV_VAR_VALUE>
2601 # clusterChecksRunner.envFrom -- Set environment variables specific to Cluster Checks Runner from configMaps and/or secrets
2603 ## envFrom to pass configmaps or secrets as environment
2604 ## ref: https://github.com/DataDog/datadog-agent/tree/main/Dockerfiles/agent#environment-variables
2607 # name: <CONFIGMAP_NAME>
2609 # name: <SECRET_NAME>
2611 # clusterChecksRunner.envDict -- Set environment variables specific to Cluster Checks Runner defined in a dict
2613 # <ENV_VAR_NAME>: <ENV_VAR_VALUE>
2615 # clusterChecksRunner.volumes -- Specify additional volumes to mount in the cluster checks container
2619 # name: <VOLUME_NAME>
2621 # clusterChecksRunner.volumeMounts -- Specify additional volumes to mount in the cluster checks container
2623 # - name: <VOLUME_NAME>
2624 # mountPath: <CONTAINER_PATH>
2628 # clusterChecksRunner.networkPolicy.create -- If true, create a NetworkPolicy for the cluster checks runners.
2629 # DEPRECATED. Use datadog.networkPolicy.create instead
2631 # clusterChecksRunner.additionalLabels -- Adds labels to the cluster checks runner deployment and pods
2632 additionalLabels: {}
2635 # clusterChecksRunner.instanceLabelOverride -- Override the `app.kubernetes.io/instance` label on the cluster checks runner deployment and pods. Useful to restore the pre-3.140.0 value when callers (e.g. NetworkPolicies) match on that label.
2636 instanceLabelOverride: # "datadog"
2637 # clusterChecksRunner.securityContext -- Allows you to overwrite the default PodSecurityContext on the clusterchecks pods.
2641 # clusterChecksRunner.containers.agent.securityContext -- Specify securityContext on the agent container
2643 readOnlyRootFilesystem: true
2645 # clusterChecksRunner.containers.initContainers.securityContext -- Specify securityContext on the init containers
2647 # clusterChecksRunner.ports -- Allows to specify extra ports (hostPorts for instance) for this container
2651 # operator.image.tag -- Define the Datadog Operator version to use
2654 # operator.datadogAgent.enabled -- Enables Datadog Agent controller
2656 datadogAgentInternal:
2657 # operator.datadogAgentInternal.enabled -- Enables the Datadog Agent Internal controller
2660 # operator.datadogDashboard.enabled -- Enables the Datadog Dashboard controller
2662 datadogGenericResource:
2663 # operator.datadogGenericResource.enabled -- Enables the Datadog Generic Resource controller
2666 # operator.datadogMonitor.enabled -- Enables the Datadog Monitor controller
2669 # operator.datadogSLO.enabled -- Enables the Datadog SLO controller
2672 # operator.untaintController.enabled -- Enables the Datadog Operator untaint controller (removes the `agent.datadoghq.com/not-ready=presence:NoSchedule` startup taint once the Agent is ready) and adds the matching toleration to the Agent DaemonSet so it can schedule on tainted nodes. Requires Operator v1.28.0+
2675 # operator.datadogCRDs.keepCrds -- Set to true to keep the CRDs when the helm chart is uninstalled. This must be set to true if datadog.operator.migration.enabled is set to true.
2678 # operator.datadogCRDs.crds.datadogAgents -- Set to true to deploy the DatadogAgents CRD
2680 # operator.datadogCRDs.crds.datadogMonitors -- Set to true to deploy the DatadogMonitors CRD
2681 datadogMonitors: true
2682 # operator.datadogCRDs.crds.datadogSLOs -- Set to true to deploy the DatadogSLO CRD
2684 # operator.datadogCRDs.crds.datadogDashboards -- Set to true to deploy the DatadogDashboard CRD
2685 datadogDashboards: true
2686 # operator.datadogCRDs.crds.datadogGenericResources -- Set to true to deploy the DatadogGenericResource CRD
2687 datadogGenericResources: true
2688 # operator.datadogCRDs.crds.datadogMetrics -- Set to true to deploy the DatadogMetrics CRD
2689 datadogMetrics: false
2690 # operator.datadogCRDs.crds.datadogPodAutoscalers -- Set to true to deploy the DatadogPodAutoscalers CRD
2691 datadogPodAutoscalers: false
2692 # operator.datadogCRDs.crds.datadogPodAutoscalerClusterProfile -- Set to false to deploy the DatadogPodAutoscalerClusterProfiles CRD
2693 datadogPodAutoscalerClusterProfiles: false
2694 # operator.datadogCRDs.crds.datadogAgentInternals -- Set to true to deploy the DatadogAgentInternals CRD
2695 datadogAgentInternals: true
2696 # operator.datadogCRDs.crds.datadogCSIDrivers -- Set to true to deploy the DatadogCSIDriver CRD
2697 datadogCSIDrivers: true
2698 # operator.datadogCRDs.crds.datadogInstrumentations -- Set to true to deploy the DatadogInstrumentations CRD
2699 datadogInstrumentations: false
2702 # datadog-crds.crds.datadogMetrics -- Set to true to deploy the DatadogMetrics CRD
2703 datadogMetrics: true
2704 # datadog-crds.crds.datadogPodAutoscalers -- Set to true to deploy the DatadogPodAutoscalers CRD
2705 datadogPodAutoscalers: true
2706 # crds.datadogPodAutoscalerClusterProfile -- Set to true to deploy the DatadogPodAutoscalerClusterProfiles CRD
2707 datadogPodAutoscalerClusterProfiles: true
2708datadog-instrumentation-crd:
2710 # datadog-instrumentation-crd.crds.datadogInstrumentations -- Set to true to deploy the DatadogInstrumentations CRD
2711 datadogInstrumentations: true
2713 # kube-state-metrics.image.repository -- Default kube-state-metrics image repository.
2715 repository: registry.k8s.io/kube-state-metrics/kube-state-metrics
2717 # kube-state-metrics.rbac.create -- If true, create & use RBAC resources
2720 # kube-state-metrics.serviceAccount.create -- If true, create ServiceAccount, require rbac kube-state-metrics.rbac.create true
2722 # kube-state-metrics.serviceAccount.name -- The name of the ServiceAccount to use.
2724 ## If not set and create is true, a name is generated using the fullname template
2726 # kube-state-metrics.resources -- Resource requests and limits for the kube-state-metrics container.
2735 # kube-state-metrics.nodeSelector -- Node selector for KSM. KSM only supports Linux.
2737 kubernetes.io/os: linux
2740 # providers.gke.autopilot -- Enables Datadog Agent deployment on GKE Autopilot
2742 # providers.gke.cos -- Enables Datadog Agent deployment on GKE with Container-Optimized OS (COS)
2744 # providers.gke.gdc -- Enables Datadog Agent deployment on GKE on Google Distributed Cloud (GDC)
2747 # providers.flatcar.enabled -- Enable Flatcar Container Linux support. Flatcar mounts `/usr` read-only, so the host `/usr/src` volume is not mounted into system-probe.
2750 # providers.eks.controlPlaneMonitoring -- Enable control plane monitoring checks in the EKS cluster.
2751 controlPlaneMonitoring: false
2753 # providers.eks.ec2.useHostnameFromFile -- Use hostname from EC2 filesystem instead of fetching from metadata endpoint.
2755 ## When deploying to EC2-backed EKS infrastructure, there are situations where the
2756 ## IMDS metadata endpoint is not accessible to containers. This flag mounts the host's
2757 ## `/var/lib/cloud/data/instance-id` and uses that for Agent's hostname instead.
2758 useHostnameFromFile: false
2760 # providers.aks.enabled -- Activate all specificities related to AKS configuration. Required as currently we cannot auto-detect AKS.
2763 # providers.openshift.controlPlaneMonitoring -- Enable control plane monitoring checks in the OpenShift cluster.
2764 # Certificates are needed to communicate with the Etcd service, which can be found in the secret `etcd-metric-client` in the `openshift-etcd-operator` namespace.
2765 # To give the Datadog Agent access to these certificates, copy them into the same namespace the Datadog Agent is running in:
2766 # `oc get secret etcd-metric-client -n openshift-etcd-operator -o yaml | sed 's/namespace: openshift-etcd-operator/namespace: <datadog agent namespace>/' | oc create -f -`
2767 controlPlaneMonitoring: false
2769 # providers.talos.enabled -- Activate all required specificities related to Talos.dev configuration,
2770 # as currently the chart cannot auto-detect Talos.dev cluster.
2771 # Note: The Agent deployment requires additional privileges that are not permitted by the default pod security policy.
2772 # The annotation `pod-security.kubernetes.io/enforce=privileged` must be applied to the Datadog installation
2773 # Kubernetes namespace. For more information on pod security policies in Talos.dev clusters, see:
2774 # https://www.talos.dev/v1.8/kubernetes-guides/configuration/pod-security/
2777 # remoteConfiguration.enabled -- Set to true to enable remote configuration on the Cluster Agent (if set) and the node agent.
2778 # Can be overridden if `datadog.remoteConfiguration.enabled`
2779 # Preferred way to enable Remote Configuration.
2781## OTel collector related configuration for otel-agent in Gateway Deployment
2782## Note this is different from the otel-agent in Daemonset (datadog.otelCollector)
2784 # otelAgentGateway.enabled -- Enable otel-agent Gateway
2786 # otelAgentGateway.ports -- Ports that OTel Collector is listening on
2788 # Default GRPC port of OTLP receiver
2789 - containerPort: "4317"
2792 # Default HTTP port of OTLP receiver
2793 - containerPort: "4318"
2796 # otelAgentGateway.config -- Gateway OTel Agent configuration
2798 ## otelAgentGateway.configMap -- Use an existing ConfigMap for Gateway OTel Agent configuration
2800 # otelAgentGateway.configMap.name -- Name of the existing ConfigMap that contains the Gateway OTel Agent configuration
2802 # otelAgentGateway.configMap.checksum -- Checksum of the existing ConfigMap that contains the Gateway OTel Agent configuration
2804 # otelAgentGateway.configMap.items -- Items within the ConfigMap that contain Gateway OTel Agent configuration
2806 # - key: otel-gateway-config.yaml
2807 # path: otel-gateway-config.yaml
2808 # - key: otel-gateway-config-two.yaml
2809 # path: otel-gateway-config-two.yaml
2810 # otelAgentGateway.configMap.key -- Key within the ConfigMap that contains the Gateway OTel Agent configuration
2811 key: otel-gateway-config.yaml
2812 # otelAgentGateway.featureGates -- Feature gates to pass to OTel collector, as a comma separated list
2814 # otelAgentGateway.replicas -- Number of otel-agent instances in the Gateway Deployment
2816 # otelAgentGateway.revisionHistoryLimit -- The number of old ReplicaSets to keep in this Deployment.
2817 revisionHistoryLimit: 10
2818 # otelAgentGateway.deploymentAnnotations -- Annotations to add to the otel-agent Gateway Deployment
2819 deploymentAnnotations: {}
2822 # otelAgentGateway.podAnnotations -- Annotations to add to the Gateway Deployment's Pods
2826 # otelAgentGateway.tolerations -- Allow the Gateway Deployment to schedule on tainted nodes (requires Kubernetes >= 1.6)
2828 # otelAgentGateway.useHostNetwork -- Bind ports on the hostNetwork
2830 ## Useful for CNI networking where hostPort might
2831 ## not be supported. The ports need to be available on all hosts. It can be
2832 ## used for custom metrics instead of a service endpoint.
2834 ## WARNING: Make sure that hosts using this are properly firewalled otherwise
2835 ## metrics and traces are accepted from any host able to connect to this host.
2837 useHostNetwork: false
2838 # otelAgentGateway.dnsConfig -- Specify dns configuration options for otel agent containers e.g ndots
2840 ## ref: https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config
2846 # otelAgentGateway.volumes -- Specify additional volumes to mount in the otel-agent container
2850 # name: <VOLUME_NAME>
2852 # otelAgentGateway.volumeMounts -- Specify additional volumes to mount in the otel-agent container
2854 # - name: <VOLUME_NAME>
2855 # mountPath: <CONTAINER_PATH>
2858 # otelAgentGateway.nodeSelector -- Allow the Gateway Deployment to schedule on selected nodes
2860 ## Ref: https://kubernetes.io/docs/user-guide/node-selection/
2862 # otelAgentGateway.affinity -- Allow the Gateway Deployment to schedule using affinity rules
2864 ## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity
2866 # otelAgentGateway.strategy -- Allow the otel-agent Gateway Deployment to perform a rolling update on helm update
2868 ## ref: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#strategy
2874 # otelAgentGateway.priorityClassCreate -- Creates a priorityClass for the otel-agent Gateway Deployment pods.
2875 priorityClassCreate: false
2876 # otelAgentGateway.priorityClassName -- Sets PriorityClassName if defined
2877 priorityClassName: null
2878 # otelAgentGateway.priorityPreemptionPolicyValue -- Set to "Never" to change the PriorityClass to non-preempting
2879 priorityPreemptionPolicyValue: PreemptLowerPriority
2880 # otelAgentGateway.priorityClassValue -- Value used to specify the priority of the scheduling of otel-agent Gateway Deployment pods.
2882 ## The PriorityClass uses PreemptLowerPriority.
2883 priorityClassValue: 1000000000
2884 # otelAgentGateway.podLabels -- Sets podLabels if defined
2886 ## Note: These labels are also used as label selectors so they are immutable.
2888 # otelAgentGateway.additionalLabels -- Adds labels to the Agent Gateway Deployment and pods
2889 additionalLabels: {}
2890 # otelAgentGateway.shareProcessNamespace -- Set the process namespace sharing on the otel-agent
2891 shareProcessNamespace: false
2892 # otelAgentGateway.lifecycle -- Configure the lifecycle of the otel-agent
2896 # command: ["/bin/sh", "-c", "sleep 70"]
2898 # otelAgentGateway.terminationGracePeriodSeconds -- (int) Configure the termination grace period for the otel-agent
2899 terminationGracePeriodSeconds: # 70
2900 # otelAgentGateway.topologySpreadConstraints -- Allow the otel-agent Gateway Deployment to schedule using pod topology spreading
2902 ## By default, no constraints are set, allowing cluster defaults to be used for scheduling
2903 ## Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
2904 topologySpreadConstraints: []
2905 ## Configuration for the service for the OTel Agent Gateway
2907 # otelAgentGateway.service.type -- Set type of otel-agent-gateway service
2909 ## Allow to override the Datadog otel-agent image
2911 # otelAgentGateway.image.name -- otel agent image name to use (relative to `registry`)
2912 name: ddot-collector
2913 # otelAgentGateway.image.tag -- Override the image tag of otel agent
2915 # otelAgentGateway.image.tagSuffix -- Suffix to append to image tag of otel agent
2917 # otelAgentGateway.image.digest -- Override the image digest of otel agent, takes precedence over tag if specified
2919 # otelAgentGateway.image.repository -- Override the image repository to override default registry
2921 # otelAgentGateway.image.doNotCheckTag -- Skip the version and chart compatibility check
2923 ## By default, the version passed in otelAgentGateway.image.tag is checked
2924 ## for compatibility with the version of the chart.
2925 ## This boolean permits completely skipping this check.
2926 ## This is useful, for example, for custom tags that are not
2927 ## respecting semantic versioning.
2928 doNotCheckTag: # false
2929 # otelAgentGateway.image.pullPolicy -- otel Agent image pullPolicy
2930 pullPolicy: IfNotPresent
2931 # otelAgentGateway.image.pullSecrets -- otel Agent repository pullSecret (ex: specify docker registry credentials)
2933 ## See https://kubernetes.io/docs/concepts/containers/images/#specifying-imagepullsecrets-on-a-pod
2935 # - name: "<REG_SECRET>"
2937 # otelAgentGateway.initContainers.securityContext -- Allows you to overwrite the default container SecurityContext for init containers
2939 # otelAgentGateway.initContainers.resources -- Resource requests and limits for init containers
2949 # otelAgentGateway.containers.otelAgent.env -- Additional environment variables for the otel-agent container
2951 # otelAgentGateway.containers.otelAgent.envFrom -- Set environment variables specific to otel-agent from configMaps and/or secrets
2954 # name: <CONFIGMAP_NAME>
2956 # name: <SECRET_NAME>
2958 # otelAgentGateway.containers.otelAgent.envDict -- Set environment variables specific to otel-agent defined in a dict
2960 # <ENV_VAR_NAME>: <ENV_VAR_VALUE>
2962 # otelAgentGateway.containers.otelAgent.resources -- Resource requests and limits for the otel-agent container
2971 # otelAgentGateway.containers.otelAgent.securityContext -- Allows you to overwrite the default container SecurityContext for the otel-agent container.
2973 # otelAgentGateway.containers.otelAgent.logLevel -- Set logging verbosity, valid log levels are: trace, debug, info, warn, error, critical, and off.
2974 # If not set, fall back to the value of datadog.logLevel.
2976 # otelAgentGateway.containers.otelAgent.healthPort -- Port number to use for the otel-agent-gateway health check endpoint (OTel health_check extension)
2978 # otelAgentGateway.containers.otelAgent.livenessProbe -- otel-agent-gateway liveness probe settings.
2979 # Set enabled to true to activate. The OTel config must expose the health_check extension
2980 # on healthPort (default 13133); the generated default config does this automatically.
2983 initialDelaySeconds: 15
2988 # otelAgentGateway.containers.otelAgent.readinessProbe -- otel-agent-gateway readiness probe settings.
2989 # Set enabled to true to activate. The OTel config must expose the health_check extension
2990 # on healthPort (default 13133); the generated default config does this automatically.
2993 initialDelaySeconds: 15
2998 ## Provide OTel Collector RBAC configuration in Gateway
3000 # otelAgentGateway.rbac.create -- If true, check OTel Collector config for k8sattributes processor
3001 # and create required ClusterRole to access Kubernetes API
3003 # otelAgentGateway.rbac.rules -- A set of additional RBAC rules to apply to OTel Collector's ClusterRole
3006 # resources: ["pods", "nodes"]
3007 # verbs: ["get", "list", "watch"]
3008 ## Provide OTel Collector logs configuration
3010 # otelAgentGateway.logs.enabled -- Enable logs support in the OTel Collector.
3011 # If true, checks OTel Collector config for filelog receiver and mounts additional volumes to collect containers
3014 ## Provide Horizontal Pod Autoscaler (HPA) configuration in OTel Agent Gateway, requires k8s 1.23.0 and above
3016 # otelAgentGateway.autoscaling.enabled -- enable autoscaling using Horizontal Pod Autoscaler (HPA), requires k8s 1.23.0 and above.
3017 # Will override otelAgentGateway.replicas.
3019 # otelAgentGateway.autoscaling.annotations -- annotations for OTel Agent Gateway HPA
3021 # otelAgentGateway.autoscaling.minReplicas -- min number of replicas for OTel Agent Gateway HPA
3023 # otelAgentGateway.autoscaling.maxReplicas -- max number of replicas for OTel Agent Gateway HPA
3025 # otelAgentGateway.autoscaling.metrics -- the metrics used for OTel Agent Gateway HPA
3027 # otelAgentGateway.autoscaling.behavior -- defines the scaling behavior in OTel Agent Gateway HPA
3029 # otelAgentGateway.autoscaling.behavior.scaleUp -- defines the scaling up behavior in OTel Agent Gateway HPA
3031 # otelAgentGateway.autoscaling.behavior.scaleDown -- defines the scaling down behavior in OTel Agent Gateway HPA