DirectorySecurity AdvisoriesPricing
Sign in
Directory
datadog-agent logoHELM

datadog-agent

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:
Compare:

1
## Default values for Datadog Agent
2
## See Datadog helm documentation to learn more:
3
## https://docs.datadoghq.com/agent/kubernetes/helm/
4
5
## FOR AN EFFORTLESS UPGRADE PATH, DO NOT COPY THIS FILE AS YOUR OWN values.yaml.
6
## ONLY SET THE VALUES YOU WANT TO OVERRIDE IN YOUR values.yaml.
7
8
# global.apmRegistryAllowList -- Restrict which registries can be used for APM library injection.
9
## When non-empty, only libraries from the listed registries will be injected. Enforced by both the
10
## admission controller webhook and the CSI driver. An empty list allows all registries (default).
11
global:
12
apmRegistryAllowList: []
13
# - public.ecr.aws/datadog
14
# - gcr.io/datadoghq
15
# nameOverride -- Override name of app
16
nameOverride: # ""
17
# fullnameOverride -- Override the full qualified app name
18
fullnameOverride: # ""
19
# kubeVersionOverride -- Override Kubernetes version detection. Useful for GitOps tools like FluxCD that don't expose the real cluster version to Helm
20
kubeVersionOverride: # "1.28.0"
21
# targetSystem -- Target OS for this deployment (possible values: linux, windows)
22
targetSystem: "linux"
23
# commonLabels -- Labels to apply to all resources
24
commonLabels: {}
25
# team_name: dev
26
27
# registry -- Registry to use for all Agent images (default depends on datadog.site and registryMigrationMode values)
28
29
## Currently we offer Datadog Agent images on:
30
## Datadog - use registry.datadoghq.com
31
## GCR US - use gcr.io/datadoghq
32
## GCR Europe - use eu.gcr.io/datadoghq
33
## GCR Asia - use asia.gcr.io/datadoghq
34
## Azure - use datadoghq.azurecr.io
35
## AWS - use public.ecr.aws/datadog
36
## DockerHub - use docker.io/datadog
37
## If you are on GKE Autopilot, you must use a gcr.io variant registry.
38
registry: chainreg.biz # gcr.io/datadoghq
39
# registryMigrationMode -- Controls gradual migration of default image registry to
40
# registry.datadoghq.com, replacing site-specific regional mirrors (GCR, ACR).
41
# This setting has no effect when `registry` is explicitly set.
42
# GKE Autopilot and GKE GDC clusters are excluded and always use their site-specific gcr.io variant.
43
# US1-FED (ddog-gov.com) is excluded and always uses public.ecr.aws/datadog.
44
# US3 (us3.datadoghq.com) is excluded and always uses datadoghq.azurecr.io.
45
46
## "auto" (default): enable registry.datadoghq.com for sites where migration is rolled out.
47
## Currently enabled: AP1 (ap1.datadoghq.com), AP2 (ap2.datadoghq.com), US5 (us5.datadoghq.com), EU1 (datadoghq.eu), US1 (datadoghq.com, when APM is disabled).
48
## "all": enable registry.datadoghq.com for all sites (AP1, AP2, EU, US1, US5).
49
## "": disable migration, keeping site-specific registries.
50
registryMigrationMode: "auto"
51
datadog:
52
# datadog.apiKey -- Your Datadog API key
53
54
## ref: https://app.datadoghq.com/account/settings#agent/kubernetes
55
apiKey: # <DATADOG_API_KEY>
56
# datadog.apiKeyExistingSecret -- Use existing Secret which stores API key instead of creating a new one. The value should be set with the `api-key` key inside the secret.
57
58
## If set, this parameter takes precedence over "apiKey".
59
apiKeyExistingSecret: # <DATADOG_API_KEY_SECRET>
60
# datadog.appKey -- Datadog APP key required to use metricsProvider
61
62
## If you are using clusterAgent.metricsProvider.enabled = true, you must set
63
## a Datadog application key for read access to your metrics.
64
appKey: # <DATADOG_APP_KEY>
65
# datadog.appKeyExistingSecret -- Use existing Secret which stores APP key instead of creating a new one. The value should be set with the `app-key` key inside the secret.
66
67
## If set, this parameter takes precedence over "appKey".
68
appKeyExistingSecret: # <DATADOG_APP_KEY_SECRET>
69
# agents.secretAnnotations -- Annotations to add to the Secrets
70
secretAnnotations: {}
71
# key: "value"
72
73
## Configure the secret backend feature https://docs.datadoghq.com/agent/guide/secrets-management
74
## Examples: https://docs.datadoghq.com/agent/guide/secrets-management/#setup-examples-1
75
secretBackend:
76
# datadog.secretBackend.command -- Configure the secret backend command, path to the secret backend binary.
77
78
## Note: If the command value is "/readsecret_multiple_providers.sh", and datadog.secretBackend.enableGlobalPermissions is enabled below, the agents will have permissions to get secret objects across the cluster.
79
## Read more about "/readsecret_multiple_providers.sh": https://docs.datadoghq.com/agent/guide/secrets-management/#script-for-reading-from-multiple-secret-providers-readsecret_multiple_providerssh
80
command: # "/readsecret.sh" or "/readsecret_multiple_providers.sh" or any custom binary path
81
# datadog.secretBackend.arguments -- Configure the secret backend command arguments (space-separated strings).
82
arguments: # "/etc/secret-volume" or any other custom arguments
83
# datadog.secretBackend.timeout -- Configure the secret backend command timeout in seconds.
84
timeout: # 30
85
# datadog.secretBackend.refreshInterval -- [PREVIEW] Configure the secret backend command refresh interval in seconds.
86
refreshInterval: # 0
87
# datadog.secretBackend.type -- Configure the built-in secret backend type.
88
# Alternative to command; when set, the Agent uses the built-in backend to resolve secrets. Requires Agent 7.70+.
89
type: # Examples: "file.text", "k8s.secrets", "docker.secrets", "aws.secrets", etc.
90
# datadog.secretBackend.config -- Additional configuration for the secret backend type.
91
config: {}
92
# Example for k8s.secrets:
93
# token_path: "/custom/path/token"
94
# ca_path: "/custom/path/ca.crt"
95
96
# datadog.secretBackend.enableGlobalPermissions -- Whether to create a global permission allowing Datadog agents to read all secrets when `datadog.secretBackend.command` is set to `"/readsecret_multiple_providers.sh"` or `datadog.secretBackend.type` is set.
97
enableGlobalPermissions: true
98
# datadog.secretBackend.roles -- Creates roles for Datadog to read the specified secrets - replacing `datadog.secretBackend.enableGlobalPermissions`.
99
roles: []
100
# - namespace: secret-location-namespace
101
# secrets:
102
# - secret-1
103
# - secret-2
104
# datadog.securityContext -- Allows you to overwrite the default PodSecurityContext on the Daemonset or Deployment
105
securityContext:
106
runAsUser: 0
107
# seLinuxOptions:
108
# user: "system_u"
109
# role: "system_r"
110
# type: "spc_t"
111
# level: "s0"
112
113
# datadog.hostVolumeMountPropagation -- Allow to specify the `mountPropagation` value on all volumeMounts using HostPath
114
115
## ref: https://kubernetes.io/docs/concepts/storage/volumes/#mount-propagation
116
hostVolumeMountPropagation: None
117
# datadog.clusterName -- Set a unique cluster name to allow scoping hosts and Cluster Checks easily
118
119
## The name must be unique and must be dot-separated tokens with the following restrictions:
120
## * Lowercase letters, numbers, and hyphens only.
121
## * Must start with a letter.
122
## * Must end with a number or a letter.
123
## * Overall length should not be higher than 80 characters.
124
## Compared to the rules of GKE, dots are allowed whereas they are not allowed on GKE:
125
## https://cloud.google.com/kubernetes-engine/docs/reference/rest/v1beta1/projects.locations.clusters#Cluster.FIELDS.name
126
clusterName: # <CLUSTER_NAME>
127
# datadog.site -- The site of the Datadog intake to send Agent data to.
128
# (documentation: https://docs.datadoghq.com/getting_started/site/)
129
130
## Set to 'datadoghq.com' to send data to the US1 site (default).
131
## Set to 'datadoghq.eu' to send data to the EU site.
132
## Set to 'us3.datadoghq.com' to send data to the US3 site.
133
## Set to 'us5.datadoghq.com' to send data to the US5 site.
134
## Set to 'ddog-gov.com' to send data to the US1-FED site.
135
## Set to 'ap1.datadoghq.com' to send data to the AP1 site.
136
site: # datadoghq.com
137
# datadog.dd_url -- The host of the Datadog intake server to send Agent data to, only set this option if you need the Agent to send data to a custom URL
138
139
## Overrides the site setting defined in "site".
140
dd_url: # https://app.datadoghq.com
141
# datadog.logLevel -- Set logging verbosity, valid log levels are: trace, debug, info, warn, error, critical, off
142
logLevel: INFO
143
# datadog.kubeStateMetricsEnabled -- If true, deploys the kube-state-metrics deployment
144
145
## ref: https://github.com/kubernetes/kube-state-metrics/tree/kube-state-metrics-helm-chart-2.13.2/charts/kube-state-metrics
146
# The kubeStateMetricsEnabled option will be removed in the 4.0 version of the Datadog Agent chart.
147
kubeStateMetricsEnabled: false
148
kubeStateMetricsNetworkPolicy:
149
# datadog.kubeStateMetricsNetworkPolicy.create -- If true, create a NetworkPolicy for kube state metrics
150
create: false
151
kubeStateMetricsCore:
152
# datadog.kubeStateMetricsCore.enabled -- Enable the kubernetes_state_core check in the Cluster Agent (Requires Cluster Agent 1.12.0+)
153
154
## ref: https://docs.datadoghq.com/integrations/kubernetes_state_core
155
enabled: true
156
rbac:
157
# datadog.kubeStateMetricsCore.rbac.create -- If true, create & use RBAC resources
158
create: true
159
## Configuring this field changes the default kubernetes_state_core check configuration. Recommended for large clusters to reduce load on the API server.
160
useApiServerCache: false
161
# datadog.kubeStateMetricsCore.ignoreLegacyKSMCheck -- Disable the auto-configuration of legacy kubernetes_state check (taken into account only when datadog.kubeStateMetricsCore.enabled is true)
162
163
## Disabling this field is not recommended as it results in enabling both checks, it can be useful though during the migration phase.
164
## Migration guide: https://docs.datadoghq.com/integrations/kubernetes_state_core/?tab=helm#migration-from-kubernetes_state-to-kubernetes_state_core
165
ignoreLegacyKSMCheck: true
166
# datadog.kubeStateMetricsCore.collectSecretMetrics -- Enable watching secret objects and collecting their corresponding metrics kubernetes_state.secret.*
167
168
## Configuring this field will change the default kubernetes_state_core check configuration and the RBACs granted to Datadog Cluster Agent to run the kubernetes_state_core check.
169
collectSecretMetrics: true
170
# datadog.kubeStateMetricsCore.collectConfigMaps -- Enable watching configmap objects and collecting their corresponding metrics kubernetes_state.configmap.*
171
172
## Configuring this field will change the default kubernetes_state_core check configuration and the RBACs granted to Datadog Cluster Agent to run the kubernetes_state_core check.
173
collectConfigMaps: true
174
# datadog.kubeStateMetricsCore.collectVpaMetrics -- Enable watching VPA objects and collecting their corresponding metrics kubernetes_state.vpa.*
175
176
## Configuring this field will change the default kubernetes_state_core check configuration and the RBACs granted to Datadog Cluster Agent to run the kubernetes_state_core check.
177
collectVpaMetrics: false
178
# datadog.kubeStateMetricsCore.collectCrdMetrics -- Enable watching CRD objects and collecting their corresponding metrics kubernetes_state.crd.*
179
180
## Configuring this field will change the default kubernetes_state_core check configuration to run the kubernetes_state_core check.
181
collectCrdMetrics: false
182
# datadog.kubeStateMetricsCore.collectCrMetrics -- Enable watching CustomResource objects and collecting their corresponding metrics kubernetes_state_customresource.* (Requires Cluster Agent 7.63.0+)
183
184
## Configuring this field will change the default kubernetes_state_core check configuration and the RBACs granted to Datadog Cluster Agent to run the kubernetes_state_core check.
185
##
186
## See https://github.com/kubernetes/kube-state-metrics/blob/main/docs/metrics/extend/customresourcestate-metrics.md for a full description of each field.
187
collectCrMetrics: []
188
# - groupVersionKind:
189
# group: myteam.io
190
# kind: "Foo"
191
# version: "v1"
192
# resource: "foos" # optional, if not set, the resource will be pluralized from the kind by adding "s" to the end
193
# metrics:
194
# - name: "uptime"
195
# help: "Foo uptime"
196
# each:
197
# type: Gauge
198
# gauge:
199
# path: [status, uptime]
200
201
# datadog.kubeStateMetricsCore.collectApiServicesMetrics -- Enable watching apiservices objects and collecting their corresponding metrics kubernetes_state.apiservice.* (Requires Cluster Agent 7.45.0+)
202
203
## Configuring this field will change the default kubernetes_state_core check configuration and the RBACs granted to Datadog Cluster Agent to run the kubernetes_state_core check.
204
collectApiServicesMetrics: false
205
# datadog.kubeStateMetricsCore.useClusterCheckRunners -- For large clusters where the Kubernetes State Metrics Check Core needs to be distributed on dedicated workers.
206
207
## Configuring this field will create a separate deployment which will run Cluster Checks, including Kubernetes State Metrics Core.
208
## If clusterChecksRunner.enabled is true, it's recommended to set this flag to true as well to better utilize dedicated workers and reduce load on the Cluster Agent.
209
## ref: https://docs.datadoghq.com/agent/cluster_agent/clusterchecksrunner?tab=helm
210
useClusterCheckRunners: false
211
# datadog.kubeStateMetricsCore.labelsAsTags -- Extra labels to collect from resources and to turn into datadog tag.
212
213
## It has the following structure:
214
## labelsAsTags:
215
## <resource1>: # can be pod, deployment, node, etc.
216
## <label1>: <tag1> # where <label1> is the kubernetes label and <tag1> is the datadog tag
217
## <label2>: <tag2>
218
## <resource2>:
219
## <label3>: <tag3>
220
##
221
labelsAsTags: {}
222
# pod:
223
# app: app
224
# node:
225
# zone: zone
226
# team: team
227
228
# datadog.kubeStateMetricsCore.annotationsAsTags -- Extra annotations to collect from resources and to turn into datadog tag.
229
230
## It has the following structure:
231
## annotationsAsTags:
232
## <resource1>: # can be pod, deployment, node, etc.
233
## <annotation1>: <tag1> # where <annotation1> is the kubernetes annotation and <tag1> is the datadog tag
234
## <annotation2>: <tag2>
235
## <resource2>:
236
## <annotation3>: <tag3>
237
##
238
## Warning: the annotation must match the transformation done by kube-state-metrics,
239
## for example tags.datadoghq.com/version becomes tags_datadoghq_com_version.
240
annotationsAsTags: {}
241
# pod:
242
# app: app
243
# node:
244
# zone: zone
245
# team: team
246
247
# datadog.kubeStateMetricsCore.tags -- List of static tags to attach to all KSM metrics
248
tags: []
249
# datadog.kubeStateMetricsCore.namespaces -- Restrict the kubernetes_state_core check to collect metrics only from the specified namespaces.
250
## When set, namespace-scoped RBAC is created as Role+RoleBinding per listed namespace instead of a cluster-wide ClusterRole.
251
## Cluster-scoped resources (nodes, persistentvolumes, storageclasses, etc.) are still collected via a ClusterRole.
252
namespaces: []
253
# - default
254
# - kube-system
255
## Manage Cluster checks feature
256
257
## ref: https://docs.datadoghq.com/agent/autodiscovery/clusterchecks/
258
## Autodiscovery via Kube Service annotations is automatically enabled
259
clusterChecks:
260
# datadog.clusterChecks.enabled -- Enable the Cluster Checks feature on both the cluster-agents and the daemonset
261
enabled: true
262
# datadog.clusterChecks.shareProcessNamespace -- Set the process namespace sharing on the cluster checks agent
263
shareProcessNamespace: false
264
# datadog.nodeLabelsAsTags -- Provide a mapping of Kubernetes Node Labels to Datadog Tags
265
nodeLabelsAsTags: {}
266
# beta.kubernetes.io/instance-type: aws-instance-type
267
# kubernetes.io/role: kube_role
268
# <KUBERNETES_NODE_LABEL>: <DATADOG_TAG_KEY>
269
270
# datadog.podLabelsAsTags -- Provide a mapping of Kubernetes Labels to Datadog Tags
271
podLabelsAsTags: {}
272
# app: kube_app
273
# release: helm_release
274
# <KUBERNETES_LABEL>: <DATADOG_TAG_KEY>
275
276
# datadog.podAnnotationsAsTags -- Provide a mapping of Kubernetes Annotations to Datadog Tags
277
podAnnotationsAsTags: {}
278
# iam.amazonaws.com/role: kube_iamrole
279
# <KUBERNETES_ANNOTATIONS>: <DATADOG_TAG_KEY>
280
281
# datadog.namespaceLabelsAsTags -- Provide a mapping of Kubernetes Namespace Labels to Datadog Tags
282
namespaceLabelsAsTags: {}
283
# env: environment
284
# <KUBERNETES_NAMESPACE_LABEL>: <DATADOG_TAG_KEY>
285
286
# datadog.namespaceAnnotationsAsTags -- Provide a mapping of Kubernetes Namespace Annotations to Datadog Tags
287
namespaceAnnotationsAsTags: {}
288
# env: environment
289
# <KUBERNETES_NAMESPACE_ANNOTATIONS>: <DATADOG_TAG_KEY>
290
291
# datadog.kubernetesResourcesLabelsAsTags -- Provide a mapping of Kubernetes Resources Labels to Datadog Tags
292
kubernetesResourcesLabelsAsTags: {}
293
# pods:
294
# x-ref: reference
295
# namespaces:
296
# kubernetes.io/metadata.name: name-as-tag
297
# <RESOURCE_TYPE>:
298
# <KUBERNETES_RESOURCE_LABEL>: <DATADOG_TAG_KEY>
299
300
# datadog.kubernetesResourcesAnnotationsAsTags -- Provide a mapping of Kubernetes Resources Annotations to Datadog Tags
301
kubernetesResourcesAnnotationsAsTags: {}
302
# pods:
303
# x-ann: annotation-reference
304
# namespaces:
305
# stale-annotation: annotation-as-tag
306
# <RESOURCE_TYPE>:
307
# <KUBERNETES_RESOURCE_ANNOTATION>: <DATADOG_TAG_KEY>
308
309
originDetectionUnified:
310
# datadog.originDetectionUnified.enabled -- Enabled enables unified mechanism for origin detection. Default: false. (Requires Agent 7.54.0+).
311
enabled: false
312
# datadog.tags -- List of static tags to attach to every metric, event and service check collected by this Agent.
313
314
## Learn more about tagging: https://docs.datadoghq.com/tagging/
315
tags: []
316
# - "<KEY_1>:<VALUE_1>"
317
# - "<KEY_2>:<VALUE_2>"
318
319
# datadog.checksCardinality -- Sets the tag cardinality for the checks run by the Agent.
320
321
## ref: https://docs.datadoghq.com/getting_started/tagging/assigning_tags/?tab=containerizedenvironments#environment-variables
322
checksCardinality: # low, orchestrator or high (not set by default to avoid overriding existing DD_CHECKS_TAG_CARDINALITY configurations, the default value in the Agent is low)
323
# kubelet configuration
324
kubelet:
325
# datadog.kubelet.host -- Override kubelet IP
326
host:
327
valueFrom:
328
fieldRef:
329
fieldPath: status.hostIP
330
# datadog.kubelet.tlsVerify -- Toggle kubelet TLS verification
331
# @default -- true
332
tlsVerify: # false
333
# datadog.kubelet.hostCAPath -- Path (on host) where the Kubelet CA certificate is stored
334
# @default -- None (no mount from host)
335
hostCAPath:
336
# datadog.kubelet.agentCAPath -- Path (inside Agent containers) where the Kubelet CA certificate is stored
337
# @default -- /var/run/host-kubelet-ca.crt if hostCAPath else /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
338
agentCAPath:
339
# datadog.kubelet.podLogsPath -- Path (on host) where the PODs logs are located
340
# @default -- /var/log/pods on Linux, C:\var\log\pods on Windows
341
podLogsPath:
342
# datadog.kubelet.coreCheckEnabled -- Toggle if kubelet core check should be used instead of Python check. (Requires Agent/Cluster Agent 7.53.0+)
343
# @default -- true
344
coreCheckEnabled: true
345
# datadog.kubelet.podResourcesSocketDir -- Path (on host) where the kubelet.sock socket for the PodResources API is located
346
# @default -- /var/lib/kubelet/pod-resources
347
podResourcesSocketDir: /var/lib/kubelet/pod-resources
348
# datadog.kubelet.useApiServer -- Enable this to query the pod list from the API Server instead of the Kubelet. (Requires Agent 7.65.0+)
349
# @default -- false
350
useApiServer: false
351
# datadog.kubelet.fineGrainedAuthorization -- Enable fine-grained authentication for kubelet (requires: Kubernetes 1.32+)
352
fineGrainedAuthorization: false
353
# datadog.expvarPort -- Specify the port to expose pprof and expvar to not interfere with the agent metrics port from the cluster-agent, which defaults to 5000
354
expvarPort: 6000
355
## dogstatsd configuration
356
357
## ref: https://docs.datadoghq.com/agent/kubernetes/dogstatsd/
358
## To emit custom metrics from your Kubernetes application, use DogStatsD.
359
dogstatsd:
360
# datadog.dogstatsd.port -- Override the Agent DogStatsD port
361
362
## Note: Make sure your client is sending to the same UDP port.
363
port: 8125
364
# datadog.dogstatsd.originDetection -- Enable origin detection for container tagging
365
366
## ref: https://docs.datadoghq.com/developers/dogstatsd/unix_socket/#using-origin-detection-for-container-tagging
367
originDetection: false
368
# datadog.dogstatsd.tags -- List of static tags to attach to every custom metric, event and service check collected by Dogstatsd.
369
370
## Learn more about tagging: https://docs.datadoghq.com/tagging/
371
tags: []
372
# - "<KEY_1>:<VALUE_1>"
373
# - "<KEY_2>:<VALUE_2>"
374
375
# datadog.dogstatsd.tagCardinality -- Sets the tag cardinality relative to the origin detection
376
377
## ref: https://docs.datadoghq.com/developers/dogstatsd/unix_socket/#using-origin-detection-for-container-tagging
378
tagCardinality: low
379
# datadog.dogstatsd.useSocketVolume -- Enable dogstatsd over Unix Domain Socket with an HostVolume
380
381
## ref: https://docs.datadoghq.com/developers/dogstatsd/unix_socket/
382
useSocketVolume: true
383
# datadog.dogstatsd.socketPath -- Path to the DogStatsD socket
384
socketPath: /var/run/datadog/dsd.socket
385
# datadog.dogstatsd.hostSocketPath -- Host path to the DogStatsD socket
386
hostSocketPath: /var/run/datadog
387
# datadog.dogstatsd.useHostPort -- Sets the hostPort to the same value of the container port
388
389
## Needs to be used for sending custom metrics.
390
## The ports need to be available on all hosts.
391
##
392
## WARNING: Make sure that hosts using this are properly firewalled otherwise
393
## metrics and traces are accepted from any host able to connect to this host.
394
useHostPort: false
395
# datadog.dogstatsd.useHostPID -- Run the agent in the host's PID namespace
396
## DEPRECATED: use datadog.useHostPID instead.
397
398
## This is required for Dogstatsd origin detection to work.
399
## See https://docs.datadoghq.com/developers/dogstatsd/unix_socket/
400
useHostPID: false
401
# datadog.dogstatsd.nonLocalTraffic -- Enable this to make each node accept non-local statsd traffic (from outside of the pod)
402
403
## ref: https://github.com/DataDog/docker-dd-agent#environment-variables
404
nonLocalTraffic: true
405
# datadog.useHostPID -- Run the agent in the host's PID namespace, required for origin detection
406
# / unified service tagging
407
408
## This is required for Dogstatsd origin detection to work in dogstatsd and trace agent
409
## See https://docs.datadoghq.com/developers/dogstatsd/unix_socket/
410
useHostPID: true
411
# datadog.collectEvents -- Enables this to start event collection from the kubernetes API
412
413
## ref: https://docs.datadoghq.com/agent/kubernetes/#event-collection
414
collectEvents: true
415
# datadog.kubernetesUseEndpointSlices -- Enable this to map Kubernetes services to endpointslices instead of endpoints. (Requires Cluster Agent 7.62.0+).
416
kubernetesUseEndpointSlices: true
417
# datadog.kubernetesKubeServiceIgnoreReadiness -- Enable this to attach kube_service tag unconditionally. (Requires Cluster Agent 7.76.0+).
418
kubernetesKubeServiceIgnoreReadiness: false
419
# Configure Kubernetes events collection
420
kubernetesEvents:
421
# datadog.kubernetesEvents.sourceDetectionEnabled -- Enable this to map Kubernetes events to integration sources based on controller names. (Requires Cluster Agent 7.56.0+).
422
sourceDetectionEnabled: false
423
# datadog.kubernetesEvents.filteringEnabled -- Enable this to only include events that match the pre-defined allowed events. (Requires Cluster Agent 7.57.0+).
424
filteringEnabled: false
425
# datadog.kubernetesEvents.unbundleEvents -- Allow unbundling kubernetes events, 1:1 mapping between Kubernetes and Datadog events. (Requires Cluster Agent 7.42.0+).
426
unbundleEvents: false
427
# datadog.kubernetesEvents.collectedEventTypes -- Event types to be collected. This requires datadog.kubernetesEvents.unbundleEvents to be set to true.
428
collectedEventTypes:
429
# - kind: <kubernetes resource kind> # (optional if `source`` is provided)
430
# source: <controller name> # (optional if `kind`` is provided)
431
# reasons: # (optional) if empty accept all event reasons
432
# - <kubernetes event reason>
433
- kind: Pod
434
reasons:
435
- Failed
436
- BackOff
437
- Unhealthy
438
- FailedScheduling
439
- FailedMount
440
- FailedAttachVolume
441
- kind: Node
442
reasons:
443
- TerminatingEvictedPod
444
- NodeNotReady
445
- Rebooted
446
- HostPortConflict
447
- kind: CronJob
448
reasons:
449
- SawCompletedJob
450
# datadog.kubernetesEvents.maxEventsPerRun -- Maximum number of events you wish to collect per check run.
451
maxEventsPerRun:
452
# datadog.kubernetesEvents.kubernetesEventResyncPeriodS -- Specify the frequency in seconds at which the Agent should list all events to re-sync following the informer pattern
453
kubernetesEventResyncPeriodS:
454
clusterTagger:
455
# datadog.clusterTagger.collectKubernetesTags -- Enables Kubernetes resources tags collection.
456
collectKubernetesTags: false
457
# datadog.leaderElection -- Enables leader election mechanism for event collection
458
leaderElection: true
459
# datadog.leaderLeaseDuration -- Set the lease time for leader election in second
460
leaderLeaseDuration: # 60
461
# datadog.leaderElectionResource -- Selects the default resource to use for leader election.
462
# Can be:
463
# * "lease" / "leases". Only supported in agent 7.47+
464
# * "configmap" / "configmaps".
465
# "" to automatically detect which one to use.
466
leaderElectionResource: configmap
467
remoteConfiguration:
468
# datadog.remoteConfiguration.enabled -- Set to true to enable remote configuration.
469
# DEPRECATED: Consider using remoteConfiguration.enabled instead
470
enabled: true
471
privateActionRunner:
472
# datadog.privateActionRunner.enabled -- Enable the Private Action Runner on the node agent to execute workflow actions
473
enabled: false
474
# datadog.privateActionRunner.selfEnroll -- Enable self-enrollment for the Private Action Runner
475
## When enabled, the runner will automatically register itself with Datadog using the provided API/APP keys
476
## and store its identity in a local file. Requires leader election to be enabled.
477
selfEnroll: true
478
# datadog.privateActionRunner.urn -- URN of the Private Action Runner (required if selfEnroll is false)
479
## Format: urn:datadog:private-action-runner:organization:<org_id>:runner:<runner_id>
480
urn: # "urn:datadog:private-action-runner:organization:123456:runner:abc-def"
481
# datadog.privateActionRunner.privateKey -- Private key for the Private Action Runner (required if selfEnroll is false)
482
## This key is used to authenticate the runner with Datadog
483
privateKey: # "<PRIVATE_KEY>"
484
# datadog.privateActionRunner.identityFromExistingSecret -- Use existing Secret which stores the Private Action Runner URN and private key
485
## The secret should contain 'urn' and 'private_key' keys
486
## If set, this parameter takes precedence over "urn" and "privateKey"
487
identityFromExistingSecret: # "<PAR_SECRET_NAME>"
488
# datadog.privateActionRunner.actionsAllowlist -- List of actions executable by the Private Action Runner
489
actionsAllowlist: []
490
# - "com.datadoghq.http.request"
491
# - "com.datadoghq.gitlab.branches.*"
492
493
# datadog.privateActionRunner.apiKeyOnlyEnrollment -- Enroll using only the API key, without requiring an app key
494
apiKeyOnlyEnrollment: false
495
## Enable logs agent and provide custom configs
496
logs:
497
# datadog.logs.enabled -- Enables this to activate Datadog Agent log collection
498
499
## ref: https://docs.datadoghq.com/agent/basic_agent_usage/kubernetes/#log-collection-setup
500
enabled: false
501
# datadog.logs.containerCollectAll -- Enable this to allow log collection for all containers
502
503
## ref: https://docs.datadoghq.com/agent/basic_agent_usage/kubernetes/#log-collection-setup
504
containerCollectAll: false
505
# datadog.logs.containerCollectUsingFiles -- Collect logs from files in /var/log/pods instead of using container runtime API
506
507
## It's usually the most efficient way of collecting logs.
508
## ref: https://docs.datadoghq.com/agent/basic_agent_usage/kubernetes/#log-collection-setup
509
containerCollectUsingFiles: true
510
# datadog.logs.autoMultiLineDetection -- Allows the Agent to detect common multi-line patterns automatically.
511
512
## ref: https://docs.datadoghq.com/agent/logs/auto_multiline_detection/
513
autoMultiLineDetection: true
514
## Enable apm agent and provide custom configs
515
##
516
## APM is enabled by default. If local service Internal Traffic Policy is allowed (Kubernetes v1.22+), the agent service is created with the APM local traceport.
517
apm:
518
# datadog.apm.socketEnabled -- Enable APM over Socket (Unix Socket or windows named pipe)
519
520
## ref: https://docs.datadoghq.com/agent/kubernetes/apm/
521
socketEnabled: true
522
# datadog.apm.portEnabled -- Enable APM over TCP communication (hostPort 8126 by default)
523
524
## ref: https://docs.datadoghq.com/agent/kubernetes/apm/
525
portEnabled: false
526
# datadog.apm.useLocalService -- Enable APM over TCP communication to use the local service only (requires Kubernetes v1.22+)
527
# Note: The hostPort 8126 is disabled when this is enabled.
528
529
## ref: https://docs.datadoghq.com/tracing/guide/setting_up_apm_with_kubernetes_service/?tab=helm
530
useLocalService: false
531
# datadog.apm.enabled -- Enable this to enable APM and tracing, on port 8126
532
# DEPRECATED. Use datadog.apm.portEnabled instead
533
534
## ref: https://github.com/DataDog/docker-dd-agent#tracing-from-the-host
535
enabled: false
536
# datadog.apm.port -- Override the trace Agent port
537
538
## Note: Make sure your client is sending to the same UDP port.
539
port: 8126
540
# datadog.apm.useSocketVolume -- Enable APM over Unix Domain Socket
541
# DEPRECATED. Use datadog.apm.socketEnabled instead
542
543
## ref: https://docs.datadoghq.com/agent/kubernetes/apm/
544
useSocketVolume: false
545
# datadog.apm.socketPath -- Path to the trace-agent socket
546
socketPath: /var/run/datadog/apm.socket
547
# datadog.apm.hostSocketPath -- Host path to the trace-agent socket
548
hostSocketPath: /var/run/datadog
549
# Error Tracking backend
550
errorTrackingStandalone:
551
# datadog.apm.errorTrackingStandalone.enabled -- Enables Error Tracking for backend services.
552
enabled: false
553
# APM Single Step Instrumentation
554
# Requires Cluster Agent 7.49+.
555
instrumentation:
556
# datadog.apm.instrumentation.enabled -- Enable injecting the Datadog APM libraries into all pods in the cluster.
557
enabled: false
558
# datadog.apm.instrumentation.enabledNamespaces -- Enable injecting the Datadog APM libraries into pods in specific namespaces.
559
enabledNamespaces: []
560
# datadog.apm.instrumentation.disabledNamespaces -- Disable injecting the Datadog APM libraries into pods in specific namespaces.
561
disabledNamespaces: []
562
# datadog.apm.instrumentation.libVersions -- Inject specific version of tracing libraries with Single Step Instrumentation.
563
libVersions: {}
564
# datadog.apm.instrumentation.targets -- Enable target based workload selection.
565
# Requires Cluster Agent 7.64.0+.
566
#
567
# ddTraceConfigs[]valueFrom Requires Cluster Agent 7.66.0+.
568
targets: []
569
# - name: "example"
570
# podSelector:
571
# matchLabels:
572
# language: "python"
573
# namespaceSelector:
574
# matchNames:
575
# - "applications"
576
# ddTraceVersions:
577
# python: "v2"
578
# ddTraceConfigs:
579
# - name: "DD_PROFILING_ENABLED"
580
# value: "true"
581
# - name: "DD_SERVICE"
582
# valueFrom:
583
# fieldRef:
584
# fieldPath: metadata.labels[my-label]
585
586
# datadog.apm.instrumentation.skipKPITelemetry -- Disable generating Configmap for APM Instrumentation KPIs
587
skipKPITelemetry: false
588
# Language detection currently only detects languages and adds them as annotations on deployments, but doesn't use these languages for injecting libraries to applicative pods.
589
# It requires Agent 7.52+ and Cluster Agent 7.52+
590
language_detection:
591
# datadog.apm.instrumentation.language_detection.enabled -- Run language detection to automatically detect languages of user workloads (preview).
592
enabled: true
593
# datadog.apm.instrumentation.injectionMode -- The injection mode to use for libraries injection.
594
# Valid values are: "auto", "init_container", "csi" (experimental, requires Cluster Agent 7.76.0+ and Datadog CSI Driver), "image_volume" (experimental, requires Cluster Agent 7.77.0+)
595
# Empty by default so the Cluster Agent can apply its own defaults.
596
injectionMode: ""
597
# This feature is in preview. It requires Cluster Agent 7.57+.
598
injector:
599
# datadog.apm.instrumentation.injector.imageTag -- The image tag to use for the APM Injector (preview).
600
imageTag: ""
601
## Application Security Managment (ASM) configuration
602
##
603
## ASM is disabled by default and can be enabled by setting the various `enabled` fields to `true` under the `datadog.asm` section.
604
## Manually adding the various environment variables to a pod will take precedence over the ones in the Helm chart.
605
## These will only have an effect on containers that have Datadog client libraries installed, either manually or via Single Step Instrumentation (under the `datadog.apm.instrumentation` section).
606
## It requires Datadog Cluster Agent 7.53.0+.
607
asm:
608
threats:
609
# datadog.asm.threats.enabled -- Enable Application Security Management Threats App & API Protection by injecting `DD_APPSEC_ENABLED=true` environment variable to all pods in the cluster
610
enabled: false
611
sca:
612
# datadog.asm.sca.enabled -- Enable Application Security Management Software Composition Analysis by injecting `DD_APPSEC_SCA_ENABLED=true` environment variable to all pods in the cluster
613
enabled: false
614
iast:
615
# datadog.asm.iast.enabled -- Enable Application Security Management Interactive Application Security Testing by injecting `DD_IAST_ENABLED=true` environment variable to all pods in the cluster
616
enabled: false
617
## App & API Protection configuration
618
##
619
## App & API Protection is disabled by default and can be enabled by setting the `enabled` field to `true` under the `datadog.appsec.injector` section.
620
## The Datadog Helm Chart offer the option to auto-instrument supported proxies in the cluster to forward traffic to a custom security processor delegating
621
## traffic analysis, WAF capabilities and API Posture management to Datadog's App and API Protection product that has to be deployed separately. Please follow the documentation to deploy the processor:
622
## https://docs.datadoghq.com/security/application_security/setup/#proxies
623
## It requires Datadog Cluster Agent 7.73.0+.
624
appsec:
625
# App & API Protection Injector is used to automatically configure your proxy to forward traffic to a custom security processor delegating
626
# traffic analysis, WAF capabilities and API Posture management to Datadog's App and API Protection product.
627
injector:
628
# datadog.appsec.injector.enabled -- Enable App & API Protection on your cluster ingress usage across all your cluster at once
629
enabled: false
630
# datadog.appsec.injector.autoDetect -- Automatically detect and inject supported proxies in the cluster (Envoy Gateway, Istio Gateway API, native Istio Gateway, ingress-nginx)
631
autoDetect: true
632
# datadog.appsec.injector.mode -- Deployment mode for the AppSec processor. Valid values: "sidecar", "external". Leave empty to use the agent default (sidecar). Upgrading users who rely on the external-processor flow (processor.address / processor.service.*) should set this to "external" explicitly.
633
mode: ""
634
# datadog.appsec.injector.proxies -- Manually specify which proxy types to inject. Valid values: "envoy-gateway", "istio", "istio-gateway", "ingress-nginx"
635
# When autoDetect is true, detected proxies are added to this list
636
# When autoDetect is false, only proxies in this list are enabled
637
proxies: []
638
# - envoy-gateway: Configures Envoy Gateway resources for AppSec injection
639
# - istio: Watches Istio-managed Kubernetes Gateway API GatewayClasses for AppSec injection
640
# - istio-gateway: Watches native Istio Gateway resources for AppSec injection
641
# - ingress-nginx: Watches IngressClass resources to discover ingress-nginx controllers and injects the nginx-datadog module via an init container
642
643
rbac:
644
# datadog.appsec.injector.rbac.create -- If true, add AppSec injector RBAC rules to the Cluster Agent ClusterRole. Disable only when AppSec injector is not used, generated resources are already cleaned up, or equivalent RBAC is managed externally.
645
create: true
646
sidecar:
647
# datadog.appsec.injector.sidecar.image -- Container image for the AppSec sidecar processor
648
image: "ghcr.io/datadog/dd-trace-go/service-extensions-callout"
649
# datadog.appsec.injector.sidecar.imageTag -- Image tag for the AppSec sidecar processor
650
imageTag: "v2.8.2"
651
# datadog.appsec.injector.sidecar.port -- Listening port for the AppSec sidecar processor
652
port: 8080
653
# datadog.appsec.injector.sidecar.healthPort -- Health check port for the AppSec sidecar processor
654
healthPort: 8081
655
# datadog.appsec.injector.sidecar.bodyParsingSizeLimit -- Request body parsing size limit in bytes for the AppSec sidecar processor. Set to 0 to leave it unset (default agent behavior). Set to a negative value (e.g. -1) to disable body parsing entirely.
656
bodyParsingSizeLimit: 0
657
resources:
658
requests:
659
# datadog.appsec.injector.sidecar.resources.requests.cpu -- CPU request for the AppSec sidecar processor
660
cpu: "10m"
661
# datadog.appsec.injector.sidecar.resources.requests.memory -- Memory request for the AppSec sidecar processor
662
memory: "128Mi"
663
limits:
664
# datadog.appsec.injector.sidecar.resources.limits.cpu -- Optional CPU limit for the AppSec sidecar processor
665
cpu: ""
666
# datadog.appsec.injector.sidecar.resources.limits.memory -- Optional memory limit for the AppSec sidecar processor
667
memory: ""
668
processor:
669
# datadog.appsec.injector.processor.address -- Address of the AppSec processor service
670
# Defaults to `{service.name}.{service.namespace}.svc`
671
address: ""
672
# datadog.appsec.injector.processor.port -- Port of the AppSec processor service (defaults to 443)
673
port: 443
674
# datadog.appsec.injector.service -- Required service information to connect to the AppSec processor
675
# This service should point to a deployment of the image `ghcr.io/DataDog/dd-trace-go/service-extensions-callout:latest`
676
# This deployment is not managed by the Datadog Helm chart.
677
service:
678
# datadog.appsec.injector.processor.service.name -- Name of the AppSec processor service
679
name: ""
680
# datadog.appsec.injector.processor.service.namespace -- Namespace where the AppSec processor service is deployed
681
namespace: ""
682
nginx:
683
# datadog.appsec.injector.nginx.moduleMountPath -- Path inside the ingress-nginx controller pod where the nginx-datadog module .so is mounted from the shared emptyDir
684
moduleMountPath: "/modules_mount"
685
## OTLP ingest related configuration
686
otlp:
687
receiver:
688
protocols:
689
# datadog.otlp.receiver.protocols.grpc - OTLP/gRPC configuration
690
grpc:
691
# datadog.otlp.receiver.protocols.grpc.enabled -- Enable the OTLP/gRPC endpoint
692
enabled: false
693
# datadog.otlp.receiver.protocols.grpc.endpoint -- OTLP/gRPC endpoint
694
endpoint: "0.0.0.0:4317"
695
# datadog.otlp.receiver.protocols.grpc.useHostPort -- Enable the Host Port for the OTLP/gRPC endpoint
696
useHostPort: true
697
# datadog.otlp.receiver.protocols.http - OTLP/HTTP configuration
698
http:
699
# datadog.otlp.receiver.protocols.http.enabled -- Enable the OTLP/HTTP endpoint
700
enabled: false
701
# datadog.otlp.receiver.protocols.http.endpoint -- OTLP/HTTP endpoint
702
endpoint: "0.0.0.0:4318"
703
# datadog.otlp.receiver.protocols.http.useHostPort -- Enable the Host Port for the OTLP/HTTP endpoint
704
useHostPort: true
705
logs:
706
# datadog.otlp.logs.enabled -- Enable logs support in the OTLP ingest endpoint
707
enabled: false
708
## Host Profiler related configuration for the host-profiler in Agent Daemonset. Note this is experimental and subject to change
709
hostProfiler:
710
# datadog.hostProfiler.enabled -- Enable the Host Profiler. This feature is experimental and subject to change.
711
enabled: false
712
# datadog.hostProfiler.image -- Image the Host Profiler. This parameter is experimental and will be removed once official image is available.
713
image: ""
714
# datadog.hostProfiler.imagePullPolicy -- Pull policy for the Host Profiler image. Defaults to agents.image.pullPolicy when unset.
715
imagePullPolicy: ""
716
# datadog.hostProfiler.seccomp -- Seccomp profile configuration for the Host Profiler
717
seccomp:
718
# datadog.hostProfiler.seccomp.enabled -- Apply the localhost seccomp profile to the host-profiler container and run the init container that installs it on the node. Disable to run the host-profiler container Unconfined (no init container, no profile installed on the node).
719
enabled: true
720
# datadog.hostProfiler.seccompRoot -- Specify the seccomp profile root directory
721
seccompRoot: /var/lib/kubelet/seccomp
722
# datadog.hostProfiler.loggingSeccomp -- Use the seccomp profile that also permits logging syscalls
723
loggingSeccomp: false
724
# datadog.hostProfiler.apparmor -- Specify an AppArmor profile for the host-profiler container (e.g. "localhost/datadog-host-profiler").
725
## Only used when agents.podSecurity.apparmor.enabled is true.
726
apparmor: unconfined
727
## OTel collector related configuration for the otel-agent in Agent Daemonset
728
otelCollector:
729
# datadog.otelCollector.enabled -- Enable the OTel Collector
730
enabled: false
731
# datadog.otelCollector.ports -- Ports that OTel Collector is listening on
732
ports:
733
# Default GRPC port of OTLP receiver
734
- containerPort: "4317"
735
name: otel-grpc
736
protocol: TCP
737
# Default HTTP port of OTLP receiver
738
- containerPort: "4318"
739
name: otel-http
740
protocol: TCP
741
# datadog.otelCollector.config -- OTel collector configuration
742
config: null
743
# datadog.otelCollector.configMap -- Use an existing ConfigMap for DDOT Collector configuration
744
configMap:
745
# datadog.otelCollector.configMap.name -- Name of the existing ConfigMap that contains the DDOT Collector configuration
746
name: null
747
# datadog.otelCollector.configMap.items -- Items within the ConfigMap that contain DDOT Collector configuration
748
items:
749
# - key: otel-config.yaml
750
# path: otel-config.yaml
751
# - key: otel-config-two.yaml
752
# path: otel-config-two.yaml
753
# datadog.otelCollector.configMap.key -- Key within the ConfigMap that contains the DDOT Collector configuration
754
key: otel-config.yaml
755
# datadog.otelCollector.featureGates -- Feature gates to pass to OTel collector, as a comma separated list
756
featureGates: null
757
# datadog.otelCollector.useStandaloneImage -- If true, the OTel Collector will use the `ddot-collector` image instead of the `agent` image
758
# The tag is retrieved from the `agents.image.tag` value.
759
# This is only supported for agent versions 7.67.0+
760
# If set to false, you will need to set `agents.image.tagSuffix` to `full`
761
useStandaloneImage: true
762
## Provide OTel Collector RBAC configuration
763
rbac:
764
# datadog.otelCollector.rbac.create -- If true, check OTel Collector config for k8sattributes processor
765
# and create required ClusterRole to access Kubernetes API
766
create: true
767
# datadog.otelCollector.rbac.rules -- A set of additional RBAC rules to apply to OTel Collector's ClusterRole
768
rules: []
769
# - apiGroups: [""]
770
# resources: ["pods", "nodes"]
771
# verbs: ["get", "list", "watch"]
772
## Provide OTel Collector logs configuration
773
logs:
774
# datadog.otelCollector.logs.enabled -- Enable logs support in the OTel Collector.
775
# If true, checks OTel Collector config for filelog receiver and mounts additional volumes to collect containers
776
# and pods logs.
777
enabled: false
778
## Continuous Profiler configuration
779
##
780
## Continuous Profiler is disabled by default and can be enabled by setting the `enabled` field to
781
## either `auto` or `true` value under the `datadog.profiling` section.
782
## Manually adding the `DD_PROFILING_ENABLED` variable to a pod will take precedence over the
783
## value in the Helm chart.
784
## These will only have an effect on containers that have Datadog client libraries installed,
785
## either manually or via Single Step Instrumentation (under the `datadog.apm.instrumentation`
786
## section).
787
## It requires Datadog Cluster Agent 7.57.0+.
788
profiling:
789
# datadog.profiling.enabled -- Enable Continuous Profiler by injecting `DD_PROFILING_ENABLED`
790
# environment variable with the same value to all pods in the cluster
791
# Valid values are:
792
# - false: Profiler is turned off and can not be turned on by other means.
793
# - null: Profiler is turned off, but can be turned on by other means.
794
# - auto: Profiler is turned off, but the library will turn it on if the application is a good candidate for profiling.
795
# - true: Profiler is turned on.
796
enabled: null
797
# datadog.envFrom -- Set environment variables for all Agents directly from configMaps and/or secrets
798
799
## envFrom to pass configmaps or secrets as environment
800
envFrom: []
801
# - configMapRef:
802
# name: <CONFIGMAP_NAME>
803
# - secretRef:
804
# name: <SECRET_NAME>
805
806
# datadog.env -- Set environment variables for the node Agents containers only
807
808
## The Datadog Agent supports many environment variables.
809
## ref: https://docs.datadoghq.com/agent/docker/?tab=standard#environment-variables
810
env: []
811
# - name: <ENV_VAR_NAME>
812
# value: <ENV_VAR_VALUE>
813
814
# datadog.envDict -- Set environment variables defined in a dict for node Agents containers only
815
envDict: {}
816
# <ENV_VAR_NAME>: <ENV_VAR_VALUE>
817
818
# datadog.confd -- Provide additional check configurations (static and Autodiscovery)
819
820
## Each key becomes a file in /conf.d
821
## ref: https://github.com/DataDog/datadog-agent/tree/main/Dockerfiles/agent#optional-volumes
822
## ref: https://docs.datadoghq.com/agent/autodiscovery/
823
confd: {}
824
# redisdb.yaml: |-
825
# init_config:
826
# instances:
827
# - host: "name"
828
# port: "6379"
829
# kubernetes_state.yaml: |-
830
# ad_identifiers:
831
# - kube-state-metrics
832
# init_config:
833
# instances:
834
# - kube_state_url: http://%%host%%:8080/metrics
835
836
# datadog.checksd -- Provide additional custom checks as python code
837
838
## Each key becomes a file in /checks.d
839
## ref: https://github.com/DataDog/datadog-agent/tree/main/Dockerfiles/agent#optional-volumes
840
checksd: {}
841
# service.py: |-
842
843
# datadog.dockerSocketPath -- Path to the docker socket
844
dockerSocketPath: # /var/run/docker.sock
845
# datadog.criSocketPath -- Path to the container runtime socket (if different from Docker)
846
criSocketPath: # /var/run/containerd/containerd.sock
847
# Configure how the agent interact with the host's container runtime
848
containerRuntimeSupport:
849
# datadog.containerRuntimeSupport.enabled -- Set this to false to disable agent access to container runtime.
850
enabled: true
851
## Enable process agent and provide custom configs
852
processAgent:
853
# datadog.processAgent.enabled -- Set this to true to enable live process monitoring agent
854
# DEPRECATED. Set `datadog.processAgent.processCollection` or `datadog.processAgent.containerCollection` instead.
855
## Note: /etc/passwd is automatically mounted when `processCollection`, `processDiscovery`, or `containerCollection` is enabled.
856
## ref: https://docs.datadoghq.com/graphing/infrastructure/process/#kubernetes-daemonset
857
enabled: true
858
# datadog.processAgent.processCollection -- Set this to true to enable process collection
859
processCollection: false
860
# datadog.processAgent.stripProcessArguments -- Set this to scrub all arguments from collected processes
861
## Requires datadog.processAgent.processCollection to be set to true to have any effect
862
## ref: https://docs.datadoghq.com/infrastructure/process/?tab=linuxwindows#process-arguments-scrubbing
863
stripProcessArguments: false
864
# datadog.processAgent.processDiscovery -- Enables or disables autodiscovery of integrations
865
processDiscovery: true
866
# datadog.processAgent.runInCoreAgent -- Set this to true to run the following features in the core agent: Live Processes, Live Containers, Process Discovery.
867
## This requires Agent 7.60.0+ and Linux.
868
## DEPRECATED: This behavior will be enabled by default for installations that meet the requirements.
869
## For Agent 7.78.0+, this setting is ignored — process checks always run in the core agent on Linux.
870
runInCoreAgent: true
871
# datadog.processAgent.containerCollection -- Set this to true to enable container collection
872
## ref: https://docs.datadoghq.com/infrastructure/containers/?tab=helm
873
containerCollection: true
874
# datadog.disableDefaultOsReleasePaths -- Set this to true to disable mounting datadog.osReleasePath in all containers
875
disableDefaultOsReleasePaths: false
876
# datadog.disablePasswdMount -- Set this to true to disable mounting /etc/passwd in all containers
877
disablePasswdMount: false
878
# datadog.osReleasePath -- Specify the path to your os-release file
879
osReleasePath: /etc/os-release
880
## Enable systemProbe agent and provide custom configs
881
systemProbe:
882
# datadog.systemProbe.debugPort -- Specify the port to expose pprof and expvar for system-probe agent
883
debugPort: 0
884
# datadog.systemProbe.enableConntrack -- Enable the system-probe agent to connect to the netlink/conntrack subsystem to add NAT information to connection data
885
886
## ref: http://conntrack-tools.netfilter.org/
887
enableConntrack: true
888
# datadog.systemProbe.seccomp -- Apply an ad-hoc seccomp profile to the system-probe agent to restrict its privileges
889
890
## Note that this will break `kubectl exec … -c system-probe -- /bin/bash`
891
seccomp: localhost/system-probe
892
# datadog.systemProbe.seccompRoot -- Specify the seccomp profile root directory
893
seccompRoot: /var/lib/kubelet/seccomp
894
# datadog.systemProbe.bpfDebug -- Enable logging for kernel debug
895
bpfDebug: false
896
# datadog.systemProbe.apparmor -- Specify a apparmor profile for system-probe
897
apparmor: unconfined
898
# datadog.systemProbe.enableTCPQueueLength -- Enable the TCP queue length eBPF-based check
899
enableTCPQueueLength: false
900
# datadog.systemProbe.enableOOMKill -- Enable the OOM kill eBPF-based check
901
enableOOMKill: false
902
# datadog.systemProbe.mountPackageManagementDirs -- Enables mounting of specific package management directories when runtime compilation is enabled
903
mountPackageManagementDirs: []
904
## For runtime compilation to be able to download kernel headers, the host's package management folders
905
## must be mounted to the /host directory. For example, for Ubuntu & Debian the following mount would be necessary:
906
# - name: "apt-config-dir"
907
# hostPath: /etc/apt
908
# mountPath: /host/etc/apt
909
## If this list is empty, then all necessary package management directories (for all supported OSs) will be mounted.
910
911
# datadog.systemProbe.runtimeCompilationAssetDir -- Specify a directory for runtime compilation assets to live in
912
runtimeCompilationAssetDir: /var/tmp/datadog-agent/system-probe
913
# datadog.systemProbe.btfPath -- Specify the path to a BTF file for your kernel
914
btfPath: ""
915
# datadog.systemProbe.collectDNSStats -- Enable DNS stat collection
916
collectDNSStats: true
917
# datadog.systemProbe.maxTrackedConnections -- the maximum number of tracked connections
918
maxTrackedConnections: 131072
919
# datadog.systemProbe.maxConnectionStateBuffered -- Maximum number of concurrent connections for Cloud Network Monitoring
920
maxConnectionStateBuffered:
921
# datadog.systemProbe.conntrackMaxStateSize -- the maximum size of the userspace conntrack cache
922
conntrackMaxStateSize: 131072 # 2 * maxTrackedConnections by default, per https://github.com/DataDog/datadog-agent/blob/d1c5de31e1bba72dfac459aed5ff9562c3fdcc20/pkg/process/config/config.go#L229
923
# datadog.systemProbe.conntrackInitTimeout -- the time to wait for conntrack to initialize before failing
924
conntrackInitTimeout: 10s
925
# DEPRECATED. Use datadog.disableDefaultOsReleasePaths instead.
926
# datadog.systemProbe.enableDefaultOsReleasePaths -- enable default os-release files mount
927
enableDefaultOsReleasePaths: true
928
# datadog.systemProbe.enableDefaultKernelHeadersPaths -- Enable mount of default paths where kernel headers are stored
929
enableDefaultKernelHeadersPaths: true
930
containerImageCollection:
931
# datadog.containerImageCollection.enabled -- Enable collection of container image metadata
932
933
# This parameter requires Agent version 7.46+
934
enabled: true
935
orchestratorExplorer:
936
# datadog.orchestratorExplorer.enabled -- Set this to false to disable the orchestrator explorer
937
938
## This requires processAgent.enabled and clusterAgent.enabled to be set to true
939
## ref: TODO - add doc link
940
enabled: true
941
# datadog.orchestratorExplorer.container_scrubbing -- Enable the scrubbing of containers in the kubernetes resource YAML for sensitive information
942
943
## The container scrubbing is taking significant resources during data collection.
944
## If you notice that the cluster-agent uses too much CPU in larger clusters
945
## turning this option off will improve the situation.
946
container_scrubbing:
947
enabled: true
948
# datadog.orchestratorExplorer.kubelet_configuration_check.enabled -- Enable the orchestrator kubelet configuration check
949
950
## this enables the collection of the kubelet configuration for viewing in the orchestrator
951
kubelet_configuration_check:
952
enabled: true
953
# datadog.orchestratorExplorer.customResources -- Defines custom resources for the orchestrator explorer to collect
954
955
# customResources is required for RBAC creation if a custom orchestrator explorer configuration is provided in `clusterAgent.confd` or `clusterAgent.advancedConfd`
956
# Each item should follow group/version/name, for example
957
# customResources:
958
# - datadoghq.com/v1alpha1/datadogmetrics
959
# - datadoghq.com/v1alpha1/watermarkpodautoscalers
960
customResources: []
961
rbac:
962
# datadog.orchestratorExplorer.rbac.create -- If true, create & use a dedicated ClusterRole and ClusterRoleBinding for orchestrator explorer permissions
963
create: true
964
# datadog.orchestratorExplorer.networkCRDs.enabled -- Enable RBAC for Gateway API, service mesh, and ingress controller CRD collection.
965
# Set to true to add RBAC rules for these resources to the orchestrator explorer ClusterRole
966
networkCRDs:
967
enabled: false
968
# datadog.orchestratorExplorer.useClusterCheckRunners -- For clusters where orchestrator explorer checks run on dedicated Cluster Checks Runners instead of the Cluster Agent.
969
970
## When enabled, the orchestrator explorer RBAC is bound to the Cluster Checks Runner ServiceAccount instead of the Cluster Agent.
971
## ref: https://docs.datadoghq.com/agent/cluster_agent/clusterchecksrunner?tab=helm
972
useClusterCheckRunners: false
973
kubernetesActions:
974
# datadog.kubernetesActions.enabled -- Set this to true to enable the Kubernetes Actions feature on the Cluster Agent.
975
# This grants the Cluster Agent RBAC to delete pods and restart deployments so that the Datadog
976
# Kubernetes Actions product can drive remediation. Requires Cluster Agent version 7.79.0 or greater.
977
enabled: false
978
helmCheck:
979
# datadog.helmCheck.enabled -- Set this to true to enable the Helm check (Requires Agent 7.35.0+ and Cluster Agent 1.19.0+)
980
# This requires clusterAgent.enabled to be set to true
981
enabled: false
982
# datadog.helmCheck.collectEvents -- Set this to true to enable event collection in the Helm Check (Requires Agent 7.36.0+ and Cluster Agent 1.20.0+)
983
# This requires datadog.HelmCheck.enabled to be set to true
984
collectEvents: false
985
# datadog.helmCheck.valuesAsTags -- Collects Helm values from a release and uses them as tags (Requires Agent and Cluster Agent 7.40.0+).
986
# This requires datadog.HelmCheck.enabled to be set to true
987
valuesAsTags: {}
988
# <HELM_VALUE>: <LABEL_NAME>
989
networkMonitoring:
990
# datadog.networkMonitoring.enabled -- Enable Cloud Network Monitoring
991
enabled: false
992
# datadog.networkMonitoring.dnsMonitoringPorts -- List of ports to monitor for DNS traffic
993
# @default -- `[53]` (set by agent)
994
dnsMonitoringPorts: []
995
networkPath:
996
connectionsMonitoring:
997
# datadog.networkPath.connectionsMonitoring.enabled -- Enable Network Path's "Network traffic paths" feature. Requires the `traceroute` system-probe module to be enabled.
998
enabled: false
999
collector:
1000
# datadog.networkPath.collector.workers -- Override the number of workers
1001
workers:
1002
# datadog.networkPath.collector.pathtestTTL -- Override TTL in minutes for pathtests
1003
pathtestTTL:
1004
# datadog.networkPath.collector.pathtestInterval -- Override time interval between pathtest runs
1005
pathtestInterval:
1006
# datadog.networkPath.collector.pathtestContextsLimit -- Override maximum number of pathtests stored to run
1007
pathtestContextsLimit:
1008
# datadog.networkPath.collector.pathtestMaxPerMinute -- Override limit for total pathtests run, per minute
1009
pathtestMaxPerMinute:
1010
serviceMonitoring:
1011
# datadog.serviceMonitoring.enabled -- Enable Universal Service Monitoring
1012
enabled: false
1013
# datadog.serviceMonitoring.httpMonitoringEnabled -- Enable HTTP monitoring for Universal Service Monitoring (Requires Agent 7.40.0+). Empty values use the default setting in the datadog agent.
1014
httpMonitoringEnabled:
1015
# datadog.serviceMonitoring.http2MonitoringEnabled -- Enable HTTP2 & gRPC monitoring for Universal Service Monitoring (Requires Agent 7.53.0+ and kernel 5.2 or later). Empty values use the default setting in the datadog agent.
1016
http2MonitoringEnabled:
1017
tls:
1018
go:
1019
# datadog.serviceMonitoring.tls.go.enabled -- (bool) Enable TLS monitoring for Golang services (Requires Agent 7.51.0+). Empty values use the default setting in the datadog agent.
1020
enabled:
1021
istio:
1022
# datadog.serviceMonitoring.tls.istio.enabled -- (bool) Enable TLS monitoring for Istio services (Requires Agent 7.50.0+). Empty values use the default setting in the datadog agent.
1023
enabled:
1024
nodejs:
1025
# datadog.serviceMonitoring.tls.nodejs.enabled -- (bool) Enable TLS monitoring for Node.js services (Requires Agent 7.54.0+). Empty values use the default setting in the datadog agent.
1026
enabled:
1027
native:
1028
# datadog.serviceMonitoring.tls.native.enabled -- (bool) Enable TLS monitoring for native (openssl, libssl, gnutls) services (Requires Agent 7.51.0+). Empty values use the default setting in the datadog agent.
1029
enabled:
1030
traceroute:
1031
# datadog.traceroute.enabled -- (bool) Enable traceroutes in system-probe for Network Path
1032
enabled: false
1033
discovery:
1034
# datadog.discovery.enabled -- (bool) Enable Service Discovery. If omitted, the chart auto-enables it when the effective node Agent version resolved by the chart is >= 7.78.0, except on GKE Autopilot clusters where system-probe is not supported. If that resolution still yields a non-semver-ish tag, discovery treats it as latest. Explicit true/false always takes precedence. On supported Agent versions, the chart also enables `discovery.use_system_probe_lite` so discovery-only deployments can exec into `system-probe-lite`.
1035
enabled: # false
1036
# datadog.discovery.networkStats.enabled -- (bool) Enable Service Discovery Network Stats
1037
networkStats:
1038
enabled: true
1039
# datadog.discovery.serviceMap.enabled -- (bool) Enable Discovery Service Map (restricted USM)
1040
serviceMap:
1041
enabled: false
1042
gpuMonitoring:
1043
# datadog.gpuMonitoring.enabled -- Enable GPU monitoring core check
1044
enabled: false
1045
# datadog.gpuMonitoring.privilegedMode -- Enable advanced GPU metrics and monitoring via system-probe
1046
# Note: system-probe component of the agent runs with elevated privileges
1047
privilegedMode: false
1048
# datadog.gpuMonitoring.configureCgroupPerms -- Configure cgroup permissions for GPU monitoring
1049
configureCgroupPerms: false
1050
# datadog.gpuMonitoring.enableEbpfProbes -- DEPRECATED. Enable the GPU monitoring eBPF probes in system-probe
1051
# The eBPF probes are deprecated and disabled by default, even when `datadog.gpuMonitoring.privilegedMode` is
1052
# enabled. This option only applies in privileged mode and exists so that users who still rely on the probes can
1053
# opt back in; expect it to be removed in a future release.
1054
enableEbpfProbes: false
1055
# datadog.gpuMonitoring.runtimeClassName -- Runtime class name for the agent pods to get access to NVIDIA resources. Can be left empty to use the default runtime class.
1056
runtimeClassName: "nvidia"
1057
# Software Bill of Materials configuration
1058
sbom:
1059
containerImage:
1060
# datadog.sbom.containerImage.enabled -- Enable SBOM collection for container images
1061
enabled: false
1062
# datadog.sbom.containerImage.uncompressedLayersSupport -- Use container runtime snapshotter
1063
# This should be set to true when using EKS, GKE or if containerd is configured to
1064
# discard uncompressed layers.
1065
# This feature will cause the SYS_ADMIN capability to be added to the Agent container.
1066
# Setting this to false could cause a high error rate when generating SBOMs due to missing uncompressed layer.
1067
# See https://docs.datadoghq.com/security/cloud_security_management/troubleshooting/vulnerabilities/#uncompressed-container-image-layers
1068
uncompressedLayersSupport: true
1069
# datadog.sbom.containerImage.overlayFSDirectScan -- Use experimental overlayFS direct scan
1070
overlayFSDirectScan: false
1071
# datadog.sbom.containerImage.containerExclude -- Exclude containers from SBOM generation, as a space-separated list
1072
1073
## ref: https://docs.datadoghq.com/agent/guide/autodiscovery-management/?tab=containerizedagent#exclude-containers
1074
containerExclude: # "image:datadog/agent"
1075
# datadog.sbom.containerImage.containerInclude -- Include containers in SBOM generation, as a space-separated list.
1076
# If a container matches an include rule, it’s always included in SBOM generation
1077
1078
## ref: https://docs.datadoghq.com/agent/guide/autodiscovery-management/?tab=containerizedagent#include-containers
1079
containerInclude:
1080
# datadog.sbom.containerImage.analyzers -- List of analyzers to use for container image SBOM generation
1081
analyzers:
1082
- "os"
1083
host:
1084
# datadog.sbom.host.enabled -- Enable SBOM collection for host filesystems
1085
enabled: false
1086
# datadog.sbom.host.analyzers -- List of analyzers to use for host SBOM generation
1087
analyzers:
1088
- "os"
1089
enrichment:
1090
usage:
1091
# datadog.sbom.enrichment.usage.enabled -- Enable runtime "package in use" SBOM enrichment.
1092
# Requires the system-probe container (auto-enabled when set to true) for eBPF-based file
1093
# access tracking, and sets `hostPID: true` on the agent pod. Requires Agent 7.79.0+.
1094
enabled: false
1095
## Enable security agent and provide custom configs
1096
securityAgent:
1097
compliance:
1098
# datadog.securityAgent.compliance.enabled -- Set to true to enable Cloud Security Posture Management (CSPM)
1099
enabled: false
1100
# datadog.securityAgent.compliance.configMap -- Contains CSPM compliance benchmarks that will be used
1101
configMap:
1102
# datadog.securityAgent.compliance.checkInterval -- Compliance check run interval
1103
checkInterval: 20m
1104
# datadog.securityAgent.compliance.containerInclude -- Include containers in CSPM monitoring, as a space-separated list.
1105
# If a container matches an include rule, it’s always included
1106
1107
## ref: https://docs.datadoghq.com/agent/guide/autodiscovery-management/?tab=containerizedagent#include-containers
1108
containerInclude:
1109
# DEPRECATED. Use datadog.securityAgent.compliance.host_benchmarks.enabled instead.
1110
xccdf:
1111
enabled: false
1112
# datadog.securityAgent.compliance.host_benchmarks.enabled -- Set to false to disable host benchmarks. If enabled, this feature requires 160 MB extra memory for the `security-agent` container. (Requires Agent 7.47.0+)
1113
host_benchmarks:
1114
enabled: true
1115
# datadog.securityAgent.compliance.runInSystemProbe -- Set to true to run compliance checks in system-probe instead of security-agent.
1116
# When enabled in conjunction with datadog.securityAgent.runtime.directSendFromSystemProbe, the security-agent container will not be created.
1117
runInSystemProbe: false
1118
runtime:
1119
# datadog.securityAgent.runtime.enabled -- Set to true to enable Cloud Workload Security (CWS)
1120
enabled: false
1121
# datadog.securityAgent.runtime.fimEnabled -- Set to true to enable Cloud Workload Security (CWS) File Integrity Monitoring
1122
# DEPRECATED. This option has no effect. Cloud Workload Security is now only controlled by datadog.securityAgent.runtime.enabled.
1123
fimEnabled: false
1124
# datadog.securityAgent.runtime.useSecruntimeTrack -- Set to true to send Cloud Workload Security (CWS) events directly to the Agent events explorer. This value shouldn't be changed unless advised by Datadog support.
1125
useSecruntimeTrack: true
1126
# datadog.securityAgent.runtime.directSendFromSystemProbe -- Set to true to enable direct sending of CWS events from system-probe to Datadog, bypassing security-agent.
1127
# When enabled, the security-agent container will not be created for CWS functionality (it may still be created if compliance features are enabled).
1128
directSendFromSystemProbe: false
1129
## ref: https://docs.datadoghq.com/agent/guide/autodiscovery-management/?tab=containerizedagent#exclude-containers
1130
containerExclude: # "image:datadog/agent"
1131
# datadog.securityAgent.runtime.containerInclude -- Include containers in runtime security monitoring, as a space-separated list.
1132
# If a container matches an include rule, it’s always included
1133
1134
## ref: https://docs.datadoghq.com/agent/guide/autodiscovery-management/?tab=containerizedagent#include-containers
1135
containerInclude:
1136
policies:
1137
# datadog.securityAgent.runtime.policies.configMap -- Contains CWS policies that will be used
1138
configMap:
1139
syscallMonitor:
1140
# datadog.securityAgent.runtime.syscallMonitor.enabled -- Set to true to enable the Syscall monitoring (recommended for troubleshooting only)
1141
enabled: false
1142
network:
1143
# datadog.securityAgent.runtime.network.enabled -- Set to true to enable the collection of CWS network events
1144
enabled: true
1145
activityDump:
1146
# datadog.securityAgent.runtime.activityDump.enabled -- Set to true to enable the collection of CWS activity dumps
1147
enabled: true
1148
# datadog.securityAgent.runtime.activityDump.tracedCgroupsCount -- Set to the number of containers that should be traced concurrently
1149
tracedCgroupsCount: 3
1150
# datadog.securityAgent.runtime.activityDump.cgroupDumpTimeout -- Set to the desired duration of a single container tracing (in minutes)
1151
cgroupDumpTimeout: 20
1152
# datadog.securityAgent.runtime.activityDump.cgroupWaitListSize -- Set to the size of the wait list for already traced containers
1153
cgroupWaitListSize: 0
1154
pathMerge:
1155
# datadog.securityAgent.runtime.activityDump.pathMerge.enabled -- Set to true to enable the merging of similar paths
1156
enabled: false
1157
securityProfile:
1158
# datadog.securityAgent.runtime.securityProfile.enabled -- Set to true to enable CWS runtime security profiles
1159
enabled: true
1160
anomalyDetection:
1161
# datadog.securityAgent.runtime.securityProfile.anomalyDetection.enabled -- Set to true to enable CWS runtime drift events
1162
enabled: true
1163
autoSuppression:
1164
# datadog.securityAgent.runtime.securityProfile.autoSuppression.enabled -- Set to true to enable CWS runtime auto suppression
1165
enabled: true
1166
enforcement:
1167
# datadog.securityAgent.runtime.enforcement.enabled -- Set to false to disable CWS runtime enforcement
1168
enabled: true
1169
## Manage NetworkPolicy
1170
networkPolicy:
1171
# datadog.networkPolicy.create -- If true, create NetworkPolicy for all the components
1172
create: false
1173
# datadog.networkPolicy.flavor -- Flavor of the network policy to use.
1174
# Can be:
1175
# * kubernetes for networking.k8s.io/v1/NetworkPolicy
1176
# * cilium for cilium.io/v2/CiliumNetworkPolicy
1177
flavor: kubernetes
1178
cilium:
1179
# datadog.networkPolicy.cilium.dnsSelector -- Cilium selector of the DNS server entity
1180
# @default -- kube-dns in namespace kube-system
1181
dnsSelector:
1182
toEndpoints:
1183
- matchLabels:
1184
"k8s:io.kubernetes.pod.namespace": kube-system
1185
"k8s:k8s-app": kube-dns
1186
## Configure prometheus scraping autodiscovery
1187
1188
## ref: https://docs.datadoghq.com/agent/kubernetes/prometheus/
1189
prometheusScrape:
1190
# datadog.prometheusScrape.enabled -- Enable autodiscovering pods and services exposing prometheus metrics.
1191
enabled: false
1192
# datadog.prometheusScrape.serviceEndpoints -- Enable generating dedicated checks for service endpoints.
1193
serviceEndpoints: false
1194
# datadog.prometheusScrape.additionalConfigs -- Allows adding advanced openmetrics check configurations with custom discovery rules. (Requires Agent version 7.27+)
1195
additionalConfigs: []
1196
# -
1197
# autodiscovery:
1198
# kubernetes_annotations:
1199
# include:
1200
# custom_include_label: 'true'
1201
# exclude:
1202
# custom_exclude_label: 'true'
1203
# kubernetes_container_names:
1204
# - my-app
1205
# configurations:
1206
# - send_distribution_buckets: true
1207
# timeout: 5
1208
# datadog.prometheusScrape.version -- Version of the openmetrics check to schedule by default.
1209
1210
# See https://datadoghq.dev/integrations-core/legacy/prometheus/#config-changes-between-versions for the differences between the two versions.
1211
# (Version 2 requires Agent version 7.34+)
1212
version: 2
1213
# datadog.ignoreAutoConfig -- List of integration to ignore auto_conf.yaml.
1214
1215
## ref: https://docs.datadoghq.com/agent/faq/auto_conf/
1216
ignoreAutoConfig: []
1217
# - redisdb
1218
# - kubernetes_state
1219
1220
# datadog.containerExclude -- Exclude containers from Agent Autodiscovery, as a space-separated list
1221
1222
## ref: https://docs.datadoghq.com/agent/guide/autodiscovery-management/?tab=containerizedagent#exclude-containers
1223
containerExclude: # "image:datadog/agent"
1224
# datadog.containerInclude -- Include containers in Agent Autodiscovery, as a space-separated list.
1225
# If a container matches an include rule, it’s always included in Autodiscovery
1226
1227
## ref: https://docs.datadoghq.com/agent/guide/autodiscovery-management/?tab=containerizedagent#include-containers
1228
containerInclude:
1229
# datadog.containerExcludeLogs -- Exclude logs from Agent Autodiscovery, as a space-separated list
1230
containerExcludeLogs:
1231
# datadog.containerIncludeLogs -- Include logs in Agent Autodiscovery, as a space-separated list
1232
containerIncludeLogs:
1233
# datadog.containerExcludeMetrics -- Exclude metrics from Agent Autodiscovery, as a space-separated list
1234
containerExcludeMetrics:
1235
# datadog.containerIncludeMetrics -- Include metrics in Agent Autodiscovery, as a space-separated list
1236
containerIncludeMetrics:
1237
# datadog.celWorkloadExclude -- Exclude workloads using a CEL-based definition in the Agent. (Requires Agent 7.73.0+)
1238
# ref: https://docs.datadoghq.com/containers/guide/container-discovery-management/
1239
celWorkloadExclude:
1240
# datadog.excludePauseContainer -- Exclude pause containers from Agent Autodiscovery.
1241
1242
## ref: https://docs.datadoghq.com/agent/guide/autodiscovery-management/?tab=containerizedagent#pause-containers
1243
excludePauseContainer: true
1244
containerLifecycle:
1245
# datadog.containerLifecycle.enabled -- Enable container lifecycle events collection
1246
enabled: true
1247
csi:
1248
# datadog.csi.enabled -- Enable datadog csi driver
1249
# Requires version 7.67 or later of the cluster agent
1250
# Note:
1251
# - When set to true, the CSI driver subchart will be installed automatically.
1252
# - Do not install the CSI driver separately if this is enabled, or you may hit conflicts.
1253
enabled: false
1254
instrumentationCrd:
1255
# datadog.instrumentationCrd.enabled -- (bool) Enable the DatadogInstrumentation CRD controller and reconciliation platform.
1256
# Requires version 7.82.0 or later of both cluster and node agent.
1257
enabled: true
1258
dataPlane:
1259
# datadog.dataPlane.enabled -- Whether or not the data plane is enabled
1260
#
1261
# Requires version 7.74 or later of the Datadog Agent.
1262
#
1263
# The data plane feature is currently in preview. Please reach out to your Datadog representative for more information.
1264
enabled: false
1265
dogstatsd:
1266
# datadog.dataPlane.dogstatsd.enabled -- Whether or not DogStatsD is enabled in the data plane
1267
enabled: true
1268
## Datadog Operator
1269
## * Enable the Datadog Operator chart dependency.
1270
## * Configure the Datadog Operator sub-chart using the values config, `operator`.
1271
## For all available Operator chart options see: https://github.com/DataDog/helm-charts/blob/main/charts/datadog-operator/values.yaml
1272
operator:
1273
# datadog.operator.enabled -- Enable the Datadog Operator.
1274
enabled: true
1275
# datadog.operator.migration.enabled -- Enable migration of Agent workloads to be managed by the Datadog Operator.
1276
# Creates a DatadogAgent manifest based on current release's values.yaml.
1277
migration:
1278
enabled: false
1279
# datadog.operator.migration.preview -- Set to true to preview the DatadogAgent manifest mapped from the
1280
# Helm release's values.yaml. Mapped DatadogAgent manifest can be viewed by checking the `dda-mapper`
1281
# container logs in the migration job.
1282
preview: false
1283
# datadog.operator.migration.userValues -- Provide datadog chart values as a YAML string to be mapped to the DatadogAgent manifest.
1284
# Use --set-file to pass the file contents: helm install datadog ./charts/datadog --set-file datadog.operator.migration.userValues=myValues.yaml -f myValues.yaml
1285
userValues: ""
1286
# Configuration related to Dynamic Instrumentation for Go services.
1287
dynamicInstrumentationGo:
1288
# datadog.dynamicInstrumentationGo.enabled -- Enable Dynamic Instrumentation and Live Debugger for Go services.
1289
enabled: false
1290
# Configuration related to Workload Autoscaling
1291
autoscaling:
1292
workload:
1293
# datadog.autoscaling.workload.enabled -- (bool) Enable Workload Autoscaling.
1294
enabled:
1295
## This is the Datadog Cluster Agent implementation that handles cluster-wide
1296
## metrics more cleanly, separates concerns for better rbac, and implements
1297
## the external metrics API so you can autoscale HPAs based on datadog metrics
1298
## ref: https://docs.datadoghq.com/agent/kubernetes/cluster/
1299
clusterAgent:
1300
# clusterAgent.enabled -- Set this to false to disable Datadog Cluster Agent
1301
enabled: true
1302
# clusterAgent.shareProcessNamespace -- Set the process namespace sharing on the Datadog Cluster Agent
1303
shareProcessNamespace: false
1304
## Define the Datadog Cluster-Agent image to work with
1305
image:
1306
# clusterAgent.image.name -- Cluster Agent image name to use (relative to `registry`)
1307
name: scratch-images/test-tmp/datadog-cluster-agent
1308
# clusterAgent.image.tag -- Cluster Agent image tag to use
1309
tag: 7.82.3-r0@sha256:3da8981733a442abea94d770d171b55e99fa644aab1486b54bcaed7024ded285
1310
# clusterAgent.image.digest -- Cluster Agent image digest to use, takes precedence over tag if specified
1311
digest: ""
1312
# clusterAgent.image.repository -- Override default registry + image.name for Cluster Agent
1313
repository:
1314
# clusterAgent.image.pullPolicy -- Cluster Agent image pullPolicy
1315
pullPolicy: IfNotPresent
1316
# clusterAgent.image.pullSecrets -- Cluster Agent repository pullSecret (ex: specify docker registry credentials)
1317
1318
## See https://kubernetes.io/docs/concepts/containers/images/#specifying-imagepullsecrets-on-a-pod
1319
pullSecrets: []
1320
# - name: "<REG_SECRET>"
1321
1322
# clusterAgent.image.doNotCheckTag -- Skip the version and chart compatibility check
1323
1324
## By default, the version passed in clusterAgent.image.tag is checked
1325
## for compatibility with the version of the chart.
1326
## This boolean permits completely skipping this check.
1327
## This is useful, for example, for custom tags that are not
1328
## respecting semantic versioning.
1329
doNotCheckTag: # false
1330
# clusterAgent.securityContext -- Allows you to overwrite the default PodSecurityContext on the cluster-agent pods.
1331
securityContext: {}
1332
containers:
1333
clusterAgent:
1334
# clusterAgent.containers.clusterAgent.securityContext -- Specify securityContext on the cluster-agent container.
1335
securityContext:
1336
allowPrivilegeEscalation: false
1337
readOnlyRootFilesystem: true
1338
initContainers:
1339
# clusterAgent.containers.initContainers.securityContext -- Specify securityContext on the initContainers.
1340
securityContext: {}
1341
# clusterAgent.containers.initContainers.resources -- Resource requests and limits for the Cluster Agent init containers
1342
resources: {}
1343
# requests:
1344
# cpu: 100m
1345
# memory: 200Mi
1346
# limits:
1347
# cpu: 100m
1348
# memory: 200Mi
1349
# clusterAgent.command -- Command to run in the Cluster Agent container as entrypoint
1350
command: []
1351
# clusterAgent.token -- Cluster Agent token is a preshared key between node agents and cluster agent (autogenerated if empty, needs to be at least 32 characters a-zA-z)
1352
token: ""
1353
# clusterAgent.tokenExistingSecret -- Existing secret name to use for Cluster Agent token. Put the Cluster Agent token in a key named `token` inside the Secret
1354
tokenExistingSecret: ""
1355
# clusterAgent.replicas -- Specify the of cluster agent replicas, if > 1 it allow the cluster agent to work in HA mode.
1356
replicas: 1
1357
# clusterAgent.revisionHistoryLimit -- The number of old ReplicaSets to keep in this Deployment.
1358
revisionHistoryLimit: 10
1359
## Provide Cluster Agent Deployment pod(s) RBAC configuration
1360
rbac:
1361
# clusterAgent.rbac.create -- If true, create & use RBAC resources
1362
create: true
1363
# clusterAgent.rbac.flareAdditionalPermissions -- If true, add Secrets and Configmaps get/list permissions to retrieve user Datadog Helm values from Cluster Agent namespace
1364
flareAdditionalPermissions: true
1365
# clusterAgent.rbac.serviceAccountName -- Specify a preexisting ServiceAccount to use if clusterAgent.rbac.create is false
1366
serviceAccountName: default
1367
# clusterAgent.rbac.serviceAccountAnnotations -- Annotations to add to the ServiceAccount if clusterAgent.rbac.create is true
1368
serviceAccountAnnotations: {}
1369
# clusterAgent.rbac.serviceAccountAdditionalLabels -- Labels to add to the ServiceAccount if clusterAgent.rbac.create is true
1370
serviceAccountAdditionalLabels: {}
1371
# clusterAgent.rbac.automountServiceAccountToken -- If true, automatically mount the ServiceAccount's API credentials if clusterAgent.rbac.create is true
1372
automountServiceAccountToken: true
1373
## Provide Cluster Agent pod security configuration
1374
podSecurity:
1375
podSecurityPolicy:
1376
# clusterAgent.podSecurity.podSecurityPolicy.create -- If true, create a PodSecurityPolicy resource for Cluster Agent pods
1377
create: false
1378
securityContextConstraints:
1379
# clusterAgent.podSecurity.securityContextConstraints.create -- If true, create a SCC resource for Cluster Agent pods
1380
create: false
1381
# Enable the metricsProvider to be able to scale based on metrics in Datadog
1382
metricsProvider:
1383
# clusterAgent.metricsProvider.enabled -- Set this to true to enable Metrics Provider
1384
enabled: false
1385
# clusterAgent.metricsProvider.registerAPIService -- Set this to false to disable external metrics registration as an APIService
1386
registerAPIService: true
1387
# clusterAgent.metricsProvider.wpaController -- Enable informer and controller of the watermark pod autoscaler
1388
1389
## Note: You need to install the `WatermarkPodAutoscaler` CRD before
1390
wpaController: false
1391
# clusterAgent.metricsProvider.useDatadogMetrics -- Enable usage of DatadogMetric CRD to autoscale on arbitrary Datadog queries
1392
1393
## Note: It will install DatadogMetrics CRD automatically (it may conflict with previous installations)
1394
useDatadogMetrics: false
1395
# clusterAgent.metricsProvider.createReaderRbac -- Create `external-metrics-reader` RBAC automatically (to allow HPA to read data from Cluster Agent)
1396
createReaderRbac: true
1397
# clusterAgent.metricsProvider.aggregator -- Define the aggregator the cluster agent will use to process the metrics. The options are (avg, min, max, sum)
1398
aggregator: avg
1399
## Configuration for the service for the cluster-agent metrics server
1400
service:
1401
# clusterAgent.metricsProvider.service.type -- Set type of cluster-agent metrics server service
1402
type: ClusterIP
1403
# clusterAgent.metricsProvider.service.port -- Set port of cluster-agent metrics server service (Kubernetes >= 1.15)
1404
port: 8443
1405
# clusterAgent.metricsProvider.endpoint -- Override the external metrics provider endpoint. If not set, the cluster-agent defaults to `datadog.site`
1406
endpoint: # https://api.datadoghq.com
1407
# clusterAgent.env -- Set environment variables specific to Cluster Agent
1408
1409
## The Cluster-Agent supports many additional environment variables
1410
## ref: https://docs.datadoghq.com/agent/cluster_agent/commands/#cluster-agent-options
1411
env: []
1412
# clusterAgent.envFrom -- Set environment variables specific to Cluster Agent from configMaps and/or secrets
1413
1414
## The Cluster-Agent supports many additional environment variables
1415
## ref: https://docs.datadoghq.com/agent/cluster_agent/commands/#cluster-agent-options
1416
envFrom: []
1417
# - configMapRef:
1418
# name: <CONFIGMAP_NAME>
1419
# - secretRef:
1420
# name: <SECRET_NAME>
1421
1422
# clusterAgent.envDict -- Set environment variables specific to Cluster Agent defined in a dict
1423
envDict: {}
1424
# <ENV_VAR_NAME>: <ENV_VAR_VALUE>
1425
1426
admissionController:
1427
# clusterAgent.admissionController.enabled -- Enable the admissionController to be able to inject APM/Dogstatsd config and standard tags (env, service, version) automatically into your pods
1428
enabled: true
1429
# clusterAgent.admissionController.validation -- Validation Webhook configuration options
1430
validation:
1431
# clusterAgent.admissionController.validation.enabled -- Enabled enables the Admission Controller validation webhook. Default: true. (Requires Agent 7.59.0+).
1432
enabled: true
1433
# clusterAgent.admissionController.mutation -- Mutation Webhook configuration options
1434
mutation:
1435
# clusterAgent.admissionController.mutation.enabled -- Enabled enables the Admission Controller mutation webhook. Default: true. (Requires Agent 7.59.0+).
1436
enabled: true
1437
# clusterAgent.admissionController.webhookName -- Name of the validatingwebhookconfiguration and mutatingwebhookconfiguration created by the cluster-agent
1438
webhookName: datadog-webhook
1439
# clusterAgent.admissionController.mutateUnlabelled -- Enable injecting config without having the pod label 'admission.datadoghq.com/enabled="true"'
1440
mutateUnlabelled: false
1441
# clusterAgent.admissionController.configMode -- The kind of configuration to be injected, it can be "hostip", "service", "socket" or "csi".
1442
1443
## If clusterAgent.admissionController.configMode is not set:
1444
## * and datadog.apm.socketEnabled is true, the Admission Controller uses socket.
1445
## * and datadog.apm.portEnabled is true, the Admission Controller uses hostip.
1446
## * and datadog.apm.useLocalService is true and the aformentioned two are false, the Admission Controller uses service.
1447
## * Otherwise, the Admission Controller defaults to hostip.
1448
## Note: "service" mode relies on the internal traffic service to target the agent running on the local node (requires Kubernetes v1.22+).
1449
## Note: "csi" mode requires enabling csi with `datadog.csi.enabled`. If not set, the admission controller will fallback to "socket" mode.
1450
## Note: "csi" mode requires version 7.65 or later of the cluster agent.
1451
## ref: https://docs.datadoghq.com/agent/cluster_agent/admission_controller/#configure-apm-and-dogstatsd-communication-mode
1452
configMode: # "hostip", "socket", "csi" or "service"
1453
# clusterAgent.admissionController.failurePolicy -- Set the failure policy for dynamic admission control.'
1454
1455
## The default of Ignore means that pods will still be admitted even if the webhook is unavailable to inject them.
1456
## Setting to Fail will require the admission controller to be present and pods to be injected before they are allowed to run.
1457
failurePolicy: Ignore
1458
# clusterAgent.admissionController.containerRegistry -- Override the default registry for the admission controller.
1459
1460
## The clusterAgent uses this configuration for apm.instrumentation, agentSidecar, and cwsInstrumentation, if
1461
## not otherwise specified.
1462
containerRegistry:
1463
remoteInstrumentation:
1464
# clusterAgent.admissionController.remoteInstrumentation.enabled -- Enable polling and applying library injection using Remote Config.
1465
## This feature is in beta, and enables Remote Config in the Cluster Agent. It also requires Cluster Agent version 7.43+.
1466
## Enabling this feature grants the Cluster Agent the permissions to patch Deployment objects in the cluster.
1467
enabled: false
1468
# clusterAgent.admissionController.port -- Set port of cluster-agent admission controller service
1469
port: 8000
1470
cwsInstrumentation:
1471
# clusterAgent.admissionController.cwsInstrumentation.enabled -- Enable the CWS Instrumentation admission controller endpoint.
1472
enabled: false
1473
# clusterAgent.admissionController.cwsInstrumentation.mode -- Mode defines how the CWS Instrumentation should behave.
1474
# Options are "remote_copy" or "init_container"
1475
mode: remote_copy
1476
kubernetesAdmissionEvents:
1477
# clusterAgent.admissionController.kubernetesAdmissionEvents.enabled -- Enable the Kubernetes Admission Events feature.
1478
enabled: false
1479
probe:
1480
# clusterAgent.admissionController.probe.enabled -- Enable the admission controller connectivity probe.
1481
## The probe periodically sends dry-run ConfigMap creation requests to verify the webhook is reachable from the API server.
1482
## (Requires Cluster Agent 7.78.0+).
1483
enabled: false
1484
# clusterAgent.admissionController.probe.interval -- Seconds between probe executions.
1485
interval: 60
1486
# clusterAgent.admissionController.probe.gracePeriod -- Seconds to wait at startup before the first probe.
1487
gracePeriod: 60
1488
agentSidecarInjection:
1489
# clusterAgent.admissionController.agentSidecarInjection.enabled -- Enables Datadog Agent sidecar injection.
1490
1491
## When enabled, the admission controller mutating webhook will inject an Agent sidecar with minimal configuration in every pod meeting the configured criteria.
1492
enabled: false
1493
# clusterAgent.admissionController.agentSidecarInjection.provider -- Used by the admission controller to add infrastructure provider-specific configurations to the Agent sidecar.
1494
1495
## Currently only "fargate" is supported. To use the feature in other environments (including local testing) omit the config.
1496
## ref: https://docs.datadoghq.com/integrations/eks_fargate
1497
provider:
1498
# clusterAgent.admissionController.agentSidecarInjection.clusterAgentCommunicationEnabled -- Enable communication between Agent sidecars and the Cluster Agent.
1499
clusterAgentCommunicationEnabled: true
1500
# clusterAgent.admissionController.agentSidecarInjection.clusterAgentTlsVerification -- TLS verification configuration for sidecar-to-cluster-agent communication.
1501
clusterAgentTlsVerification:
1502
# clusterAgent.admissionController.agentSidecarInjection.clusterAgentTlsVerification.enabled -- Enable TLS verification for Agent sidecars communicating with the Cluster Agent.
1503
enabled: false
1504
# clusterAgent.admissionController.agentSidecarInjection.clusterAgentTlsVerification.copyCaConfigMap -- Enable automatic creation of a ConfigMap containing the Cluster Agent's CA certificate in namespaces where sidecar injection occurs.
1505
copyCaConfigMap: false
1506
# clusterAgent.admissionController.agentSidecarInjection.containerRegistry -- Override the default registry for the sidecar Agent.
1507
containerRegistry:
1508
# clusterAgent.admissionController.imageName -- Override the default agents.image.name for the Agent sidecar.
1509
imageName:
1510
# clusterAgent.admissionController.imageTag -- Override the default agents.image.tag for the Agent sidecar.
1511
imageTag:
1512
# clusterAgent.admissionController.agentSidecarInjection.selectors -- Defines the pod selector for sidecar injection, currently only one rule is supported.
1513
selectors: []
1514
# - objectSelector:
1515
# matchLabels:
1516
# "podlabelKey1": podlabelValue1
1517
# "podlabelKey2": podlabelValue2
1518
# namespaceSelector:
1519
# matchLabels:
1520
# "nsLabelKey1": nsLabelValue1
1521
# "nsLabelKey2": nsLabelValue2
1522
1523
# clusterAgent.admissionController.agentSidecarInjection.profiles -- Defines the sidecar configuration override, currently only one profile is supported.
1524
1525
## This setting allows overriding the sidecar Agent configuration by adding environment variables and providing resource settings.
1526
profiles: []
1527
# - env:
1528
# - name: DD_ORCHESTRATOR_EXPLORER_ENABLED
1529
# value: "true"
1530
# resources:
1531
# requests:
1532
# cpu: "1"
1533
# memory: "512Mi"
1534
# limits:
1535
# cpu: "2"
1536
# memory: "1024Mi"
1537
# clusterAgent.confd -- Provide additional cluster check configurations. Each key will become a file in /conf.d.
1538
1539
## ref: https://docs.datadoghq.com/agent/autodiscovery/
1540
confd: {}
1541
# mysql.yaml: |-
1542
# cluster_check: true
1543
# instances:
1544
# - host: <EXTERNAL_IP>
1545
# port: 3306
1546
# username: datadog
1547
# password: <YOUR_CHOSEN_PASSWORD>
1548
1549
# clusterAgent.advancedConfd -- Provide additional cluster check configurations. Each key is an integration containing several config files.
1550
1551
## ref: https://docs.datadoghq.com/agent/autodiscovery/
1552
advancedConfd: {}
1553
# mysql.d:
1554
# 1.yaml: |-
1555
# cluster_check: true
1556
# instances:
1557
# - host: <EXTERNAL_IP>
1558
# port: 3306
1559
# username: datadog
1560
# password: <YOUR_CHOSEN_PASSWORD>
1561
# 2.yaml: |-
1562
# cluster_check: true
1563
# instances:
1564
# - host: <EXTERNAL_IP>
1565
# port: 3306
1566
# username: datadog
1567
# password: <YOUR_CHOSEN_PASSWORD>
1568
1569
## clusterAgent.kubernetesApiserverCheck -- correspond to options for configuring the kube_apiserver integration.
1570
kubernetesApiserverCheck:
1571
# clusterAgent.kubernetesApiserverCheck.disableUseComponentStatus -- Set this to true to disable use_component_status for the kube_apiserver integration.
1572
disableUseComponentStatus: false
1573
# clusterAgent.resources -- Datadog cluster-agent resource requests and limits.
1574
resources: {}
1575
# requests:
1576
# cpu: 200m
1577
# memory: 256Mi
1578
# limits:
1579
# cpu: 200m
1580
# memory: 256Mi
1581
1582
# clusterAgent.priorityClassName -- Name of the priorityClass to apply to the Cluster Agent
1583
priorityClassName: # system-cluster-critical
1584
# clusterAgent.nodeSelector -- Allow the Cluster Agent Deployment to be scheduled on selected nodes
1585
1586
## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#nodeselector
1587
## Ref: https://kubernetes.io/docs/user-guide/node-selection/
1588
nodeSelector: {}
1589
# clusterAgent.tolerations -- Allow the Cluster Agent Deployment to schedule on tainted nodes ((requires Kubernetes >= 1.6))
1590
1591
## Ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/
1592
tolerations: []
1593
# clusterAgent.affinity -- Allow the Cluster Agent Deployment to schedule using affinity rules
1594
1595
## By default, Cluster Agent Deployment Pods are forced to run on different Nodes.
1596
## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity
1597
affinity: {}
1598
# clusterAgent.topologySpreadConstraints -- Allow the Cluster Agent Deployment to schedule using pod topology spreading
1599
1600
## By default, no constraints are set, allowing cluster defaults to be used for scheduling
1601
## Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
1602
topologySpreadConstraints: []
1603
# clusterAgent.healthPort -- Port number to use in the Cluster Agent for the healthz endpoint
1604
healthPort: 5556
1605
privateActionRunner:
1606
# clusterAgent.privateActionRunner.enabled -- Enable the Private Action Runner to execute workflow actions
1607
enabled: false
1608
# clusterAgent.privateActionRunner.selfEnroll -- Enable self-enrollment for the Private Action Runner
1609
## When enabled, the runner will automatically register itself with Datadog using the provided API/APP keys
1610
## and store its identity in a Kubernetes secret. Requires leader election to be enabled.
1611
selfEnroll: true
1612
# clusterAgent.privateActionRunner.identitySecretName -- Name of the Kubernetes secret used to store PAR identity when self-enrollment is enabled
1613
## The Cluster Agent will create and manage this secret for storing the enrolled runner's URN and private key
1614
## RBAC permissions are granted specifically for this secret name
1615
identitySecretName: "datadog-private-action-runner-identity"
1616
# clusterAgent.privateActionRunner.urn -- URN of the Private Action Runner (required if selfEnroll is false)
1617
## Format: urn:datadog:private-action-runner:organization:<org_id>:runner:<runner_id>
1618
urn: # "urn:datadog:private-action-runner:organization:123456:runner:abc-def"
1619
# clusterAgent.privateActionRunner.privateKey -- Private key for the Private Action Runner (required if selfEnroll is false)
1620
## This key is used to authenticate the runner with Datadog
1621
privateKey: # "<PRIVATE_KEY>"
1622
# clusterAgent.privateActionRunner.identityFromExistingSecret -- Use existing Secret which stores the Private Action Runner URN and private key
1623
## The secret should contain 'urn' and 'private_key' keys
1624
## If set, this parameter takes precedence over "urn" and "privateKey"
1625
identityFromExistingSecret: # "<PAR_SECRET_NAME>"
1626
# clusterAgent.privateActionRunner.actionsAllowlist -- List of actions executable by the Private Action Runner
1627
actionsAllowlist: []
1628
# - "com.datadoghq.http.request"
1629
# - "com.datadoghq.kubernetes.core.*"
1630
1631
# clusterAgent.privateActionRunner.apiKeyOnlyEnrollment -- Enroll using only the API key, without requiring an app key
1632
apiKeyOnlyEnrollment: false
1633
# clusterAgent.privateActionRunner.k8sRemediationEnabled -- Enable k8s remediation RBAC for the Private Action Runner
1634
## When enabled, a ClusterRole and ClusterRoleBinding are created granting the Cluster Agent
1635
## permissions to read/patch workloads (Deployments, DaemonSets, StatefulSets, ReplicaSets, Pods)
1636
## and manage ConfigMaps and Events cluster-wide.
1637
k8sRemediationEnabled: false
1638
# clusterAgent.livenessProbe -- Override default Cluster Agent liveness probe settings
1639
# @default -- Every 15s / 6 KO / 1 OK
1640
livenessProbe:
1641
initialDelaySeconds: 15
1642
periodSeconds: 15
1643
timeoutSeconds: 5
1644
successThreshold: 1
1645
failureThreshold: 6
1646
# clusterAgent.readinessProbe -- Override default Cluster Agent readiness probe settings
1647
# @default -- Every 15s / 6 KO / 1 OK
1648
readinessProbe:
1649
initialDelaySeconds: 15
1650
periodSeconds: 15
1651
timeoutSeconds: 5
1652
successThreshold: 1
1653
failureThreshold: 6
1654
# clusterAgent.startupProbe -- Override default Cluster Agent startup probe settings
1655
# @default -- Every 15s / 6 KO / 1 OK
1656
startupProbe:
1657
initialDelaySeconds: 15
1658
periodSeconds: 15
1659
timeoutSeconds: 5
1660
successThreshold: 1
1661
failureThreshold: 6
1662
# clusterAgent.strategy -- Allow the Cluster Agent deployment to perform a rolling update on helm update
1663
1664
## ref: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#strategy
1665
strategy:
1666
type: RollingUpdate
1667
rollingUpdate:
1668
maxSurge: 1
1669
maxUnavailable: 0
1670
# clusterAgent.deploymentAnnotations -- Annotations to add to the cluster-agents's deployment
1671
deploymentAnnotations: {}
1672
# key: "value"
1673
1674
# clusterAgent.podAnnotations -- Annotations to add to the cluster-agents's pod(s)
1675
podAnnotations: {}
1676
# key: "value"
1677
1678
# clusterAgent.useHostNetwork -- Bind ports on the hostNetwork
1679
1680
## Useful for CNI networking where hostPort might
1681
## not be supported. The ports need to be available on all hosts. It can be
1682
## used for custom metrics instead of a service endpoint.
1683
##
1684
## WARNING: Make sure that hosts using this are properly firewalled otherwise
1685
## metrics and traces are accepted from any host able to connect to this host.
1686
#
1687
useHostNetwork: false
1688
# clusterAgent.dnsConfig -- Specify dns configuration options for datadog cluster agent containers e.g ndots
1689
1690
## ref: https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config
1691
dnsConfig: {}
1692
# options:
1693
# - name: ndots
1694
# value: "1"
1695
1696
# clusterAgent.volumes -- Specify additional volumes to mount in the cluster-agent container
1697
volumes: []
1698
# - hostPath:
1699
# path: <HOST_PATH>
1700
# name: <VOLUME_NAME>
1701
1702
# clusterAgent.volumeMounts -- Specify additional volumes to mount in the cluster-agent container
1703
volumeMounts: []
1704
# - name: <VOLUME_NAME>
1705
# mountPath: <CONTAINER_PATH>
1706
# readOnly: true
1707
1708
# clusterAgent.datadog_cluster_yaml -- Specify custom contents for the datadog cluster agent config (datadog-cluster.yaml)
1709
datadog_cluster_yaml: {}
1710
# clusterAgent.createPodDisruptionBudget -- Create pod disruption budget for Cluster Agent deployments
1711
# DEPRECATED. Use clusterAgent.pdb.create instead
1712
createPodDisruptionBudget: false
1713
pdb:
1714
# clusterAgent.pdb.create -- Enable pod disruption budget for Cluster Agent deployments.
1715
1716
## Only one of `minAvailable` or `maxUnavailable` can be set. More information: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
1717
## By default, minAvailable is set to 1 for cluster agent.
1718
create: false
1719
# clusterAgent.pdb.minAvailable -- Minimum number of pods that must remain available during a disruption -- default to 1
1720
minAvailable:
1721
# clusterAgent.pdb.maxUnavailable -- Maximum number of pods that can be unavailable during a disruption
1722
maxUnavailable:
1723
networkPolicy:
1724
# clusterAgent.networkPolicy.create -- If true, create a NetworkPolicy for the cluster agent.
1725
# DEPRECATED. Use datadog.networkPolicy.create instead
1726
create: false
1727
# clusterAgent.additionalLabels -- Adds labels to the Cluster Agent deployment and pods
1728
additionalLabels: {}
1729
# key: "value"
1730
1731
# clusterAgent.instanceLabelOverride -- Override the `app.kubernetes.io/instance` label on the Cluster Agent deployment and pods. Useful to restore the pre-3.140.0 value when callers (e.g. NetworkPolicies) match on that label.
1732
instanceLabelOverride: # "datadog"
1733
# clusterAgent.containerExclude -- Exclude containers from the Cluster Agent
1734
# Autodiscovery, as a space-separated list. (Requires Agent/Cluster Agent 7.50.0+)
1735
1736
## ref: https://docs.datadoghq.com/agent/guide/autodiscovery-management/?tab=containerizedagent#exclude-containers
1737
containerExclude: # "image:datadog/agent"
1738
# clusterAgent.containerInclude -- Include containers in the Cluster Agent Autodiscovery,
1739
# as a space-separated list. If a container matches an include rule, it’s
1740
# always included in the Autodiscovery. (Requires Agent/Cluster Agent 7.50.0+)
1741
1742
## ref: https://docs.datadoghq.com/agent/guide/autodiscovery-management/?tab=containerizedagent#include-containers
1743
containerInclude:
1744
# clusterAgent.celWorkloadExclude -- Exclude workloads using a CEL-based definition in the Cluster Agent. (Requires Agent 7.73.0+)
1745
# ref: https://docs.datadoghq.com/containers/guide/container-discovery-management/
1746
celWorkloadExclude:
1747
## This section lets you configure the agents deployed by this chart to connect to a Cluster Agent
1748
## deployed independently
1749
existingClusterAgent:
1750
# existingClusterAgent.join -- set this to true if you want the agents deployed by this chart to
1751
# connect to a Cluster Agent deployed independently
1752
join: false
1753
# existingClusterAgent.tokenSecretName -- Existing secret name to use for external Cluster Agent token
1754
tokenSecretName: # <EXISTING_DCA_SECRET_NAME>
1755
# existingClusterAgent.serviceName -- Existing service name to use for reaching the external Cluster Agent
1756
serviceName: # <EXISTING_DCA_SERVICE_NAME>
1757
# existingClusterAgent.clusterchecksEnabled -- set this to false if you don’t want the agents to run the cluster checks of the joined external cluster agent
1758
clusterchecksEnabled: true
1759
# useFIPSAgent -- Setting useFIPSAgent to true makes the helm chart use Agent images that are FIPS-compliant for use in GOVCLOUD environments.
1760
# Setting this to true disables the fips-proxy sidecar and is the recommended method for enabling FIPS compliance.
1761
# Enable FIPS with this flag; do not embed `-fips` in `agents.image.tag`.
1762
useFIPSAgent: false
1763
## fips is used to enable and configure the fips-proxy sidecar.
1764
fips:
1765
# fips.enabled -- Enable fips proxy sidecar.
1766
# The fips-proxy method is getting phased out in favor of FIPS-compliant images (refer to the `useFIPSAgent` setting).
1767
enabled: false
1768
# TODO: Option to override config of the FIPS side car: /etc/datadog-fips-proxy/datadog-fips-proxy.cfg
1769
# customConfig: false
1770
1771
# fips.port -- Specifies which port is used by the containers to communicate to the FIPS sidecar.
1772
# This setting is only used for the fips-proxy sidecar.
1773
port: 9803
1774
# fips.portRange -- Specifies the number of ports used, defaults to 13 https://github.com/DataDog/datadog-agent/blob/7.44.x/pkg/config/config.go#L1564-L1577.
1775
# This setting is only used for the fips-proxy sidecar.
1776
portRange: 15
1777
# fips.use_https -- Option to enable https.
1778
# This setting is only used for the fips-proxy sidecar.
1779
use_https: false
1780
# fips.resources -- Resource requests and limits for the FIPS sidecar container.
1781
# This setting is only used for the fips-proxy sidecar.
1782
resources: {}
1783
# limits:
1784
# cpu: 100m
1785
# memory: 256Mi
1786
# requests:
1787
# cpu: 20m
1788
# memory: 64Mi
1789
1790
# fips.local_address -- Set local IP address.
1791
# This setting is only used for the fips-proxy sidecar.
1792
local_address: "127.0.0.1"
1793
## Define the Datadog image to work with
1794
image:
1795
## fips.image.name -- Define the FIPS sidecar container image name.
1796
name: fips-proxy
1797
# fips.image.tag -- Define the FIPS sidecar container version to use.
1798
tag: 1.1.29
1799
# fips.image.pullPolicy -- Datadog the FIPS sidecar image pull policy
1800
pullPolicy: IfNotPresent
1801
# fips.image.digest -- Define the FIPS sidecar image digest to use, takes precedence over `fips.image.tag` if specified.
1802
digest: ""
1803
# fips.image.repository -- Override default registry + image.name for the FIPS sidecar container.
1804
repository:
1805
# fips.customFipsConfig -- Configure a custom configMap to provide the FIPS configuration. Specify custom contents for the FIPS proxy sidecar container config (/etc/datadog-fips-proxy/datadog-fips-proxy.cfg). If empty, the default FIPS proxy sidecar container config is used.
1806
1807
## Note: Use `|` to declare multi-line configuration.
1808
## ref: https://docs.datadoghq.com/agent/guide/agent-fips-proxy
1809
customFipsConfig: {} # |
1810
# foobar
1811
# foo bar baz
1812
agents:
1813
# agents.enabled -- You should keep Datadog DaemonSet enabled!
1814
1815
## The exceptional case could be a situation when you need to run
1816
## single Datadog pod per every namespace, but you do not need to
1817
## re-create a DaemonSet for every non-default namespace install.
1818
## Note: StatsD and DogStatsD work over UDP, so you may not
1819
## get guaranteed delivery of the metrics in Datadog-per-namespace setup!
1820
enabled: true
1821
# agents.shareProcessNamespace -- Set the process namespace sharing on the Datadog Daemonset
1822
shareProcessNamespace: false
1823
# agents.revisionHistoryLimit -- The number of ControllerRevision to keep in this DaemonSet.
1824
revisionHistoryLimit: 10
1825
## Define the Datadog image to work with
1826
image:
1827
# agents.image.name -- Datadog Agent image name to use (relative to `registry`)
1828
1829
## use "dogstatsd" for Standalone Datadog Agent DogStatsD 7
1830
name: scratch-images/test-tmp/datadog-agent
1831
# agents.image.tag -- Define the Agent version to use
1832
# Set a pinned version here. Do not append build variants: put `full` or `jmx` in `agents.image.tagSuffix`, and enable FIPS with `useFIPSAgent`. To stay on the latest stable Agent, leave this unset and upgrade the chart periodically.
1833
tag: 7.82.3-r0@sha256:862f01af23fd70bc5676b071fc811b68f28315977d6e155a7c9f3b89b6d15ca2
1834
# agents.image.digest -- Define Agent image digest to use, takes precedence over tag if specified
1835
digest: ""
1836
# agents.image.tagSuffix -- Suffix to append to Agent tag
1837
# This is the supported place for build variants like `full` or `jmx`; set them here rather than appending them to `agents.image.tag`.
1838
1839
## Ex:
1840
## jmx to enable jmx fetch collection
1841
## servercore to get Windows images based on servercore
1842
## full to get as many features as possible, currently ddot-collector and jmx
1843
tagSuffix: ""
1844
# agents.image.repository -- Override default registry + image.name for Agent
1845
repository:
1846
# agents.image.doNotCheckTag -- Skip the version and chart compatibility check
1847
1848
## By default, the version passed in agents.image.tag is checked
1849
## for compatibility with the version of the chart.
1850
## This boolean permits to completely skip this check.
1851
## This is useful, for example, for custom tags that are not
1852
## respecting semantic versioning
1853
doNotCheckTag: # false
1854
# agents.image.pullPolicy -- Datadog Agent image pull policy
1855
pullPolicy: IfNotPresent
1856
# agents.image.pullSecrets -- Datadog Agent repository pullSecret (ex: specify docker registry credentials)
1857
1858
## See https://kubernetes.io/docs/concepts/containers/images/#specifying-imagepullsecrets-on-a-pod
1859
pullSecrets: []
1860
# - name: "<REG_SECRET>"
1861
## Provide Daemonset RBAC configuration
1862
rbac:
1863
# agents.rbac.create -- If true, create & use RBAC resources
1864
create: true
1865
# agents.rbac.serviceAccountName -- Specify a preexisting ServiceAccount to use if agents.rbac.create is false
1866
serviceAccountName: default
1867
# agents.rbac.serviceAccountAnnotations -- Annotations to add to the ServiceAccount if agents.rbac.create is true
1868
serviceAccountAnnotations: {}
1869
# agents.rbac.serviceAccountAdditionalLabels -- Labels to add to the ServiceAccount if agents.rbac.create is true
1870
serviceAccountAdditionalLabels: {}
1871
# agents.rbac.automountServiceAccountToken -- If true, automatically mount the ServiceAccount's API credentials if agents.rbac.create is true
1872
automountServiceAccountToken: true
1873
## Provide Daemonset PodSecurityPolicy configuration
1874
podSecurity:
1875
podSecurityPolicy:
1876
# agents.podSecurity.podSecurityPolicy.create -- If true, create a PodSecurityPolicy resource for Agent pods
1877
create: false
1878
securityContextConstraints:
1879
# agents.podSecurity.securityContextConstraints.create -- If true, create a SecurityContextConstraints resource for Agent pods
1880
create: false
1881
# agents.podSecurity.seLinuxContext -- Provide seLinuxContext configuration for PSP/SCC
1882
# @default -- Must run as spc_t
1883
seLinuxContext:
1884
rule: MustRunAs
1885
seLinuxOptions:
1886
user: system_u
1887
role: system_r
1888
type: spc_t
1889
level: s0
1890
# agents.podSecurity.privileged -- If true, Allow to run privileged containers
1891
privileged: false
1892
# agents.podSecurity.capabilities -- Allowed capabilities
1893
1894
## note: capabilities must contain all agents.containers.*.securityContext.capabilities.
1895
capabilities:
1896
- SYS_ADMIN
1897
- SYS_RESOURCE
1898
- SYS_PTRACE
1899
- NET_ADMIN
1900
- NET_BROADCAST
1901
- NET_RAW
1902
- IPC_LOCK
1903
- CHOWN
1904
- AUDIT_CONTROL
1905
- AUDIT_READ
1906
- DAC_READ_SEARCH
1907
- MKNOD
1908
- SYSLOG
1909
# agents.podSecurity.allowedUnsafeSysctls -- Allowed unsafe sysclts
1910
allowedUnsafeSysctls: []
1911
# agents.podSecurity.volumes -- Allowed volumes types
1912
volumes:
1913
- configMap
1914
- downwardAPI
1915
- emptyDir
1916
- hostPath
1917
- secret
1918
# agents.podSecurity.seccompProfiles -- Allowed seccomp profiles
1919
seccompProfiles:
1920
- "runtime/default"
1921
- "localhost/system-probe"
1922
apparmor:
1923
# agents.podSecurity.apparmor.enabled -- If true, enable apparmor enforcement
1924
1925
## see: https://kubernetes.io/docs/tutorials/clusters/apparmor/
1926
enabled: true
1927
# agents.podSecurity.apparmorProfiles -- Allowed apparmor profiles
1928
apparmorProfiles:
1929
- "runtime/default"
1930
- "unconfined"
1931
# agents.podSecurity.defaultApparmor -- Default AppArmor profile for all containers but system-probe
1932
defaultApparmor: runtime/default
1933
containers:
1934
agent:
1935
# agents.containers.agent.env -- Additional environment variables for the agent container
1936
env: []
1937
# agents.containers.agent.envFrom -- Set environment variables specific to agent container from configMaps and/or secrets
1938
envFrom: []
1939
# - configMapRef:
1940
# name: <CONFIGMAP_NAME>
1941
# - secretRef:
1942
# name: <SECRET_NAME>
1943
1944
# agents.containers.agent.envDict -- Set environment variables specific to agent container defined in a dict
1945
envDict: {}
1946
# <ENV_VAR_NAME>: <ENV_VAR_VALUE>
1947
1948
# agents.containers.agent.logLevel -- Set logging verbosity, valid log levels are: trace, debug, info, warn, error, critical, and off.
1949
# If not set, fall back to the value of datadog.logLevel.
1950
logLevel: # INFO
1951
# agents.containers.agent.resources -- Resource requests and limits for the agent container.
1952
resources: {}
1953
# requests:
1954
# cpu: 200m
1955
# memory: 256Mi
1956
# limits:
1957
# cpu: 200m
1958
# memory: 256Mi
1959
1960
# agents.containers.agent.healthPort -- Port number to use in the node agent for the healthz endpoint
1961
healthPort: 5555
1962
# agents.containers.agent.livenessProbe -- Override default agent liveness probe settings
1963
# @default -- Every 15s / 6 KO / 1 OK
1964
livenessProbe:
1965
initialDelaySeconds: 15
1966
periodSeconds: 15
1967
timeoutSeconds: 5
1968
successThreshold: 1
1969
failureThreshold: 6
1970
# agents.containers.agent.readinessProbe -- Override default agent readiness probe settings
1971
# @default -- Every 15s / 6 KO / 1 OK
1972
readinessProbe:
1973
initialDelaySeconds: 15
1974
periodSeconds: 15
1975
timeoutSeconds: 5
1976
successThreshold: 1
1977
failureThreshold: 6
1978
# agents.containers.agent.startupProbe -- Override default agent startup probe settings
1979
# @default -- Every 15s / 6 KO / 1 OK
1980
startupProbe:
1981
initialDelaySeconds: 15
1982
periodSeconds: 15
1983
timeoutSeconds: 5
1984
successThreshold: 1
1985
failureThreshold: 6
1986
# agents.containers.agent.securityContext -- Allows you to overwrite the default container SecurityContext for the agent container.
1987
securityContext:
1988
readOnlyRootFilesystem: true
1989
# agents.containers.agent.ports -- Allows to specify extra ports (hostPorts for instance) for this container
1990
ports: []
1991
# agents.containers.agent.command -- Override the default `agent run` entrypoint for the agent container.
1992
# Useful for wrapping the agent in a shell entrypoint (e.g. to set environment variables based on
1993
# node-level information before `exec`-ing the agent). When unset, the container runs `agent run`.
1994
# Not supported on GKE Autopilot or GDC: the Datadog WorkloadAllowlist requires the agent container
1995
# command to be exactly `["agent", "run"]` on those providers, so setting this value with
1996
# `providers.gke.autopilot=true` or `providers.gke.gdc=true` fails at template render time.
1997
command: []
1998
privateActionRunner:
1999
# agents.containers.privateActionRunner.env -- Additional environment variables for the private-action-runner container
2000
env: []
2001
# agents.containers.privateActionRunner.envFrom -- Set environment variables specific to private-action-runner from configMaps and/or secrets
2002
envFrom: []
2003
# agents.containers.privateActionRunner.envDict -- Set environment variables specific to private-action-runner defined in a dict
2004
envDict: {}
2005
# agents.containers.privateActionRunner.logLevel -- Set logging verbosity for the private-action-runner container
2006
logLevel:
2007
# agents.containers.privateActionRunner.resources -- Resource requests and limits for the private-action-runner container.
2008
resources: {}
2009
# requests:
2010
# cpu: 100m
2011
# memory: 128Mi
2012
# limits:
2013
# cpu: 100m
2014
# memory: 128Mi
2015
2016
# agents.containers.privateActionRunner.securityContext -- Specify securityContext on the private-action-runner container.
2017
securityContext:
2018
readOnlyRootFilesystem: true
2019
capabilities:
2020
add: ["NET_RAW"]
2021
processAgent:
2022
# agents.containers.processAgent.env -- Additional environment variables for the process-agent container
2023
env: []
2024
# agents.containers.processAgent.envFrom -- Set environment variables specific to process-agent from configMaps and/or secrets
2025
envFrom: []
2026
# - configMapRef:
2027
# name: <CONFIGMAP_NAME>
2028
# - secretRef:
2029
# name: <SECRET_NAME>
2030
2031
# agents.containers.processAgent.envDict -- Set environment variables specific to process-agent defined in a dict
2032
envDict: {}
2033
# <ENV_VAR_NAME>: <ENV_VAR_VALUE>
2034
2035
# agents.containers.processAgent.logLevel -- Set logging verbosity, valid log levels are: trace, debug, info, warn, error, critical, and off.
2036
# If not set, fall back to the value of datadog.logLevel.
2037
logLevel: # INFO
2038
# agents.containers.processAgent.resources -- Resource requests and limits for the process-agent container
2039
resources: {}
2040
# requests:
2041
# cpu: 100m
2042
# memory: 200Mi
2043
# limits:
2044
# cpu: 100m
2045
# memory: 200Mi
2046
2047
# agents.containers.processAgent.securityContext -- Allows you to overwrite the default container SecurityContext for the process-agent container.
2048
securityContext:
2049
readOnlyRootFilesystem: true
2050
# agents.containers.processAgent.ports -- Allows to specify extra ports (hostPorts for instance) for this container
2051
ports: []
2052
otelAgent:
2053
# agents.containers.otelAgent.env -- Additional environment variables for the otel-agent container
2054
env: []
2055
# agents.containers.otelAgent.envFrom -- Set environment variables specific to otel-agent from configMaps and/or secrets
2056
envFrom: []
2057
# - configMapRef:
2058
# name: <CONFIGMAP_NAME>
2059
# - secretRef:
2060
# name: <SECRET_NAME>
2061
2062
# agents.containers.otelAgent.envDict -- Set environment variables specific to otel-agent defined in a dict
2063
envDict: {}
2064
# <ENV_VAR_NAME>: <ENV_VAR_VALUE>
2065
2066
# agents.containers.otelAgent.resources -- Resource requests and limits for the otel-agent container
2067
resources: {}
2068
# requests:
2069
# cpu: 100m
2070
# memory: 200Mi
2071
# limits:
2072
# cpu: 100m
2073
# memory: 200Mi
2074
2075
# agents.containers.otelAgent.securityContext -- Allows you to overwrite the default container SecurityContext for the otel-agent container.
2076
securityContext:
2077
readOnlyRootFilesystem: true
2078
# agents.containers.otelAgent.ports -- Allows to specify extra ports (hostPorts for instance) for this container
2079
ports: []
2080
# agents.containers.otelAgent.volumeMounts -- Specify additional volumes to mount in the otel-agent container
2081
volumeMounts: []
2082
# - name: <VOLUME_NAME>
2083
# mountPath: <CONTAINER_PATH>
2084
# readOnly: true
2085
hostProfiler:
2086
# agents.containers.hostProfiler.env -- Additional environment variables for the host-profiler container
2087
env: []
2088
# agents.containers.hostProfiler.envFrom -- Set environment variables specific to host-profiler from configMaps and/or secrets
2089
envFrom: []
2090
# - configMapRef:
2091
# name: <CONFIGMAP_NAME>
2092
# - secretRef:
2093
# name: <SECRET_NAME>
2094
2095
# agents.containers.hostProfiler.envDict -- Set environment variables specific to host-profiler defined in a dict
2096
envDict: {}
2097
# <ENV_VAR_NAME>: <ENV_VAR_VALUE>
2098
2099
# agents.containers.hostProfiler.resources -- Resource requests and limits for the host-profiler container
2100
resources: {}
2101
# requests:
2102
# cpu: 100m
2103
# memory: 200Mi
2104
# limits:
2105
# cpu: 100m
2106
# memory: 200Mi
2107
2108
# agents.containers.hostProfiler.securityContext -- Allows you to overwrite the default container SecurityContext for the host-profiler container.
2109
securityContext:
2110
readOnlyRootFilesystem: true
2111
allowPrivilegeEscalation: false
2112
privileged: false
2113
# spc_t so SELinux-enforcing nodes don't block host-profiler's cross-process /proc access.
2114
seLinuxOptions:
2115
type: spc_t
2116
capabilities:
2117
drop:
2118
- ALL
2119
add:
2120
- BPF
2121
- PERFMON
2122
- SYS_PTRACE
2123
- SYS_RESOURCE
2124
- DAC_READ_SEARCH
2125
- SYSLOG
2126
- CHECKPOINT_RESTORE
2127
- IPC_LOCK
2128
# agents.containers.hostProfiler.volumeMounts -- Specify additional volumes to mount in the host-profiler container
2129
volumeMounts: []
2130
# - name: <VOLUME_NAME>
2131
# mountPath: <CONTAINER_PATH>
2132
# readOnly: true
2133
traceAgent:
2134
# agents.containers.traceAgent.env -- Additional environment variables for the trace-agent container
2135
env: []
2136
# agents.containers.traceAgent.envFrom -- Set environment variables specific to trace-agent from configMaps and/or secrets
2137
envFrom: []
2138
# - configMapRef:
2139
# name: <CONFIGMAP_NAME>
2140
# - secretRef:
2141
# name: <SECRET_NAME>
2142
2143
# agents.containers.traceAgent.envDict -- Set environment variables specific to trace-agent defined in a dict
2144
envDict: {}
2145
# <ENV_VAR_NAME>: <ENV_VAR_VALUE>
2146
2147
# agents.containers.traceAgent.logLevel -- Set logging verbosity, valid log levels are: trace, debug, info, warn, error, critical, and off
2148
logLevel: # INFO
2149
# agents.containers.traceAgent.resources -- Resource requests and limits for the trace-agent container
2150
resources: {}
2151
# requests:
2152
# cpu: 100m
2153
# memory: 200Mi
2154
# limits:
2155
# cpu: 100m
2156
# memory: 200Mi
2157
2158
# agents.containers.traceAgent.livenessProbe -- Override default agent liveness probe settings
2159
# @default -- Every 15s
2160
livenessProbe:
2161
initialDelaySeconds: 15
2162
periodSeconds: 15
2163
timeoutSeconds: 5
2164
# agents.containers.traceAgent.securityContext -- Allows you to overwrite the default container SecurityContext for the trace-agent container.
2165
securityContext:
2166
readOnlyRootFilesystem: true
2167
# agents.containers.traceAgent.ports -- Allows to specify extra ports (hostPorts for instance) for this container
2168
ports: []
2169
systemProbe:
2170
# agents.containers.systemProbe.env -- Additional environment variables for the system-probe container
2171
env: []
2172
# agents.containers.systemProbe.envFrom -- Set environment variables specific to system-probe from configMaps and/or secrets
2173
envFrom: []
2174
# - configMapRef:
2175
# name: <CONFIGMAP_NAME>
2176
# - secretRef:
2177
# name: <SECRET_NAME>
2178
2179
# agents.containers.systemProbe.envDict -- Set environment variables specific to system-probe defined in a dict
2180
envDict: {}
2181
# <ENV_VAR_NAME>: <ENV_VAR_VALUE>
2182
2183
# agents.containers.systemProbe.logLevel -- Set logging verbosity, valid log levels are: trace, debug, info, warn, error, critical, and off.
2184
# If not set, fall back to the value of datadog.logLevel.
2185
logLevel: # INFO
2186
# agents.containers.systemProbe.resources -- Resource requests and limits for the system-probe container
2187
resources: {}
2188
# requests:
2189
# cpu: 150m
2190
# memory: 200Mi
2191
# limits:
2192
# cpu: 300m
2193
# memory: 400Mi
2194
2195
# agents.containers.systemProbe.securityContext -- Allows you to overwrite the default container SecurityContext for the system-probe container.
2196
2197
## agents.podSecurity.capabilities must reflect the changed made in securityContext.capabilities.
2198
securityContext:
2199
readOnlyRootFilesystem: true
2200
privileged: false
2201
capabilities:
2202
add: ["SYS_ADMIN", "SYS_RESOURCE", "SYS_PTRACE", "NET_ADMIN", "NET_BROADCAST", "NET_RAW", "IPC_LOCK", "CHOWN", "DAC_READ_SEARCH"]
2203
# agents.containers.systemProbe.ports -- Allows to specify extra ports (hostPorts for instance) for this container
2204
ports: []
2205
securityAgent:
2206
# agents.containers.securityAgent.env -- Additional environment variables for the security-agent container
2207
env: []
2208
# agents.containers.securityAgent.envFrom -- Set environment variables specific to security-agent from configMaps and/or secrets
2209
envFrom: []
2210
# - configMapRef:
2211
# name: <CONFIGMAP_NAME>
2212
# - secretRef:
2213
# name: <SECRET_NAME>
2214
2215
# agents.containers.securityAgent.envDict -- Set environment variables specific to security-agent defined in a dict
2216
envDict: {}
2217
# <ENV_VAR_NAME>: <ENV_VAR_VALUE>
2218
2219
# agents.containers.securityAgent.logLevel -- Set logging verbosity, valid log levels are: trace, debug, info, warn, error, critical, and off.
2220
# If not set, fall back to the value of datadog.logLevel.
2221
logLevel: # INFO
2222
# agents.containers.securityAgent.resources -- Resource requests and limits for the security-agent container
2223
resources: {}
2224
# requests:
2225
# cpu: 100m
2226
# memory: 300Mi
2227
# limits:
2228
# cpu: 100m
2229
# memory: 300Mi
2230
2231
# agents.containers.securityAgent.securityContext -- Allows you to overwrite the default container SecurityContext for the security-agent container.
2232
securityContext:
2233
readOnlyRootFilesystem: true
2234
# agents.containers.securityAgent.ports -- Allows to specify extra ports (hostPorts for instance) for this container
2235
ports: []
2236
agentDataPlane:
2237
# agents.containers.agentDataPlane.env -- Additional environment variables for the agent-data-plane container
2238
env: []
2239
# agents.containers.agentDataPlane.envFrom -- Set environment variables specific to agent-data-plane container from configMaps and/or secrets
2240
envFrom: []
2241
# - configMapRef:
2242
# name: <CONFIGMAP_NAME>
2243
# - secretRef:
2244
# name: <SECRET_NAME>
2245
2246
# agents.containers.agentDataPlane.envDict -- Set environment variables specific to agent-data-plane container defined in a dict
2247
envDict: {}
2248
# <ENV_VAR_NAME>: <ENV_VAR_VALUE>
2249
2250
# agents.containers.agentDataPlane.logLevel -- Set logging verbosity, valid log levels are: trace, debug, info, warn, error, critical, and off.
2251
# If not set, fall back to the value of datadog.logLevel.
2252
logLevel: # INFO
2253
# agents.containers.agentDataPlane.resources -- Resource requests and limits for the agent-data-plane container
2254
resources: {}
2255
# requests:
2256
# cpu: 100m
2257
# memory: 200Mi
2258
# limits:
2259
# cpu: 100m
2260
# memory: 200Mi
2261
2262
# agents.containers.agentDataPlane.unprivilegedApiPort -- Port for unprivileged API server, used primarily for health checks
2263
unprivilegedApiPort: 5100
2264
# agents.containers.agentDataPlane.privilegedApiPort -- Port for privileged API server, used for lower-level operations that
2265
# can alter the state of the ADP process or expose internal information
2266
privilegedApiPort: 5101
2267
# agents.containers.agentDataPlane.telemetryApiPort -- Port for telemetry API server, used for exposing internal
2268
# telemetry to be scraped by the Agent
2269
telemetryApiPort: 5102
2270
# agents.containers.agentDataPlane.livenessProbe -- Override default agent-data-plane liveness probe settings
2271
# @default -- Every 5s / 12 KO / 1 OK
2272
livenessProbe:
2273
initialDelaySeconds: 5
2274
periodSeconds: 5
2275
timeoutSeconds: 5
2276
successThreshold: 1
2277
failureThreshold: 12
2278
# agents.containers.agentDataPlane.readinessProbe -- Override default agent-data-plane readiness probe settings
2279
# @default -- Every 5s / 12 KO / 1 OK
2280
readinessProbe:
2281
initialDelaySeconds: 5
2282
periodSeconds: 5
2283
timeoutSeconds: 5
2284
successThreshold: 1
2285
failureThreshold: 12
2286
# agents.containers.agentDataPlane.securityContext -- Allows you to overwrite the default container SecurityContext for the agent-data-plane container.
2287
securityContext:
2288
readOnlyRootFilesystem: true
2289
# agents.containers.agentDataPlane.ports -- Allows to specify extra ports (hostPorts for instance) for this container
2290
ports: []
2291
initContainers:
2292
# agents.containers.initContainers.resources -- Resource requests and limits for the init containers
2293
resources: {}
2294
# requests:
2295
# cpu: 100m
2296
# memory: 200Mi
2297
# limits:
2298
# cpu: 100m
2299
# memory: 200Mi
2300
# agents.containers.initContainers.securityContext -- Allows you to overwrite the default container SecurityContext for the init containers.
2301
securityContext: {}
2302
# agents.containers.initContainers.volumeMounts -- Specify additional volumes to mount for the init containers
2303
volumeMounts: []
2304
# agents.volumes -- Specify additional volumes to mount in the dd-agent container
2305
volumes: []
2306
# - hostPath:
2307
# path: <HOST_PATH>
2308
# name: <VOLUME_NAME>
2309
2310
# agents.volumeMounts -- Specify additional volumes to mount in all containers of the agent pod
2311
volumeMounts: []
2312
# - name: <VOLUME_NAME>
2313
# mountPath: <CONTAINER_PATH>
2314
# readOnly: true
2315
2316
# agents.useHostNetwork -- Bind ports on the hostNetwork
2317
2318
## Useful for CNI networking where hostPort might
2319
## not be supported. The ports need to be available on all hosts. It Can be
2320
## used for custom metrics instead of a service endpoint.
2321
##
2322
## WARNING: Make sure that hosts using this are properly firewalled otherwise
2323
## metrics and traces are accepted from any host able to connect to this host.
2324
useHostNetwork: false
2325
# agents.dnsConfig -- specify dns configuration options for datadog cluster agent containers e.g ndots
2326
2327
## ref: https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config
2328
dnsConfig: {}
2329
# options:
2330
# - name: ndots
2331
# value: "1"
2332
2333
# agents.daemonsetAnnotations -- Annotations to add to the DaemonSet
2334
daemonsetAnnotations: {}
2335
# key: "value"
2336
2337
# agents.podAnnotations -- Annotations to add to the DaemonSet's Pods
2338
podAnnotations: {}
2339
# key: "value"
2340
2341
# agents.tolerations -- Allow the DaemonSet to schedule on tainted nodes (requires Kubernetes >= 1.6)
2342
tolerations: []
2343
# agents.nodeSelector -- Allow the DaemonSet to schedule on selected nodes
2344
2345
## Ref: https://kubernetes.io/docs/user-guide/node-selection/
2346
nodeSelector: {}
2347
# agents.affinity -- Allow the DaemonSet to schedule using affinity rules
2348
2349
## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity
2350
affinity: {}
2351
# agents.updateStrategy -- Allow the DaemonSet to perform a rolling update on helm update
2352
2353
## ref: https://kubernetes.io/docs/tasks/manage-daemon/update-daemon-set/
2354
updateStrategy:
2355
type: RollingUpdate
2356
rollingUpdate:
2357
maxUnavailable: "10%"
2358
# agents.priorityClassCreate -- Creates a priorityClass for the Datadog Agent's Daemonset pods.
2359
priorityClassCreate: false
2360
# agents.priorityClassName -- Sets PriorityClassName if defined
2361
priorityClassName:
2362
# agents.priorityPreemptionPolicyValue -- Set to "Never" to change the PriorityClass to non-preempting
2363
priorityPreemptionPolicyValue: PreemptLowerPriority
2364
# agents.priorityClassValue -- Value used to specify the priority of the scheduling of Datadog Agent's Daemonset pods.
2365
2366
## The PriorityClass uses PreemptLowerPriority.
2367
priorityClassValue: 1000000000
2368
# agents.podLabels -- Sets podLabels if defined
2369
2370
## Note: These labels are also used as label selectors so they are immutable.
2371
podLabels: {}
2372
# agents.additionalLabels -- Adds labels to the Agent daemonset and pods
2373
additionalLabels: {}
2374
# key: "value"
2375
2376
# agents.instanceLabelOverride -- Override the `app.kubernetes.io/instance` label on the Agent daemonset and pods. Useful to restore the pre-3.140.0 value when callers (e.g. NetworkPolicies) match on that label.
2377
instanceLabelOverride: # "datadog"
2378
# agents.useConfigMap -- Configures a configmap to provide the agent configuration. Use this in combination with the `agents.customAgentConfig` parameter.
2379
useConfigMap: # false
2380
# agents.customAgentConfig -- Specify custom contents for the datadog agent config (datadog.yaml)
2381
2382
## ref: https://docs.datadoghq.com/agent/guide/agent-configuration-files/?tab=agentv6
2383
## ref: https://github.com/DataDog/datadog-agent/blob/main/pkg/config/config_template.yaml
2384
## Note the `agents.useConfigMap` needs to be set to `true` for this parameter to be taken into account.
2385
customAgentConfig: {}
2386
#
2387
# # Enable java cgroup handling. Only one of those options should be enabled,
2388
# # depending on the agent version you are using along that chart.
2389
#
2390
# # agent version < 6.15
2391
# # jmx_use_cgroup_memory_limit: true
2392
#
2393
# # agent version >= 6.15
2394
# # jmx_use_container_support: true
2395
2396
networkPolicy:
2397
# agents.networkPolicy.create -- If true, create a NetworkPolicy for the agents.
2398
# DEPRECATED. Use datadog.networkPolicy.create instead
2399
create: false
2400
localService:
2401
# agents.localService.overrideName -- Name of the internal traffic service to target the agent running on the local node
2402
overrideName: ""
2403
# agents.localService.forceLocalServiceEnabled -- Force the creation of the internal traffic policy service to target the agent running on the local node.
2404
# By default, the internal traffic service is created only on Kubernetes 1.22+ where the feature became beta and enabled by default.
2405
# This option allows to force the creation of the internal traffic service on kubernetes 1.21 where the feature was alpha and required a feature gate to be explicitly enabled.
2406
forceLocalServiceEnabled: false
2407
# agents.lifecycle -- Configure the lifecycle of the Agent.
2408
# Note: The `exec` lifecycle handler is not supported in GKE Autopilot.
2409
lifecycle: {}
2410
# preStop:
2411
# sleep:
2412
# seconds: 5
2413
# exec:
2414
# command: ["/bin/sh", "-c", "sleep 70"]
2415
# postStart:
2416
# exec:
2417
# command: ["/bin/sh", "-c", "sleep 70"]
2418
# sleep:
2419
# seconds: 5
2420
2421
# agents.terminationGracePeriodSeconds -- (int) Configure the termination grace period for the Agent
2422
terminationGracePeriodSeconds: # 70
2423
clusterChecksRunner:
2424
# clusterChecksRunner.enabled -- If true, deploys agent dedicated for running the Cluster Checks instead of running in the Daemonset's agents.
2425
2426
## If both clusterChecksRunner.enabled and datadog.kubeStateMetricsCore.enabled are true, consider enabling datadog.kubeStateMetricsCore.useClusterCheckRunners as well.
2427
## If datadog.kubeStateMetricsCore.useClusterCheckRunners is enabled, it's recommended to enable this flag as well so all Cluster Checks run on Cluster Checks Runners instead of node agents.
2428
## ref: https://docs.datadoghq.com/agent/autodiscovery/clusterchecks/
2429
enabled: false
2430
remoteConfiguration:
2431
# clusterChecksRunner.remoteConfiguration.enabled -- Enable remote configuration on the Cluster Checks Runner.
2432
# Set to true to enable remote configuration on the Cluster Checks Runner.
2433
enabled: false
2434
## Define the Datadog image to work with.
2435
image:
2436
# clusterChecksRunner.image.name -- Datadog Agent image name to use (relative to `registry`)
2437
name: scratch-images/test-tmp/datadog-agent
2438
# clusterChecksRunner.image.tag -- Define the Agent version to use
2439
tag: 7.82.3-r0@sha256:862f01af23fd70bc5676b071fc811b68f28315977d6e155a7c9f3b89b6d15ca2
2440
# clusterChecksRunner.image.digest -- Define Agent image digest to use, takes precedence over tag if specified
2441
digest: ""
2442
# clusterChecksRunner.image.tagSuffix -- Suffix to append to Agent tag
2443
2444
## Ex:
2445
## jmx to enable jmx fetch collection
2446
## servercore to get Windows images based on servercore
2447
tagSuffix: ""
2448
# clusterChecksRunner.image.repository -- Override default registry + image.name for Cluster Check Runners
2449
repository:
2450
# clusterChecksRunner.image.pullPolicy -- Datadog Agent image pull policy
2451
pullPolicy: IfNotPresent
2452
# clusterChecksRunner.image.pullSecrets -- Datadog Agent repository pullSecret (ex: specify docker registry credentials)
2453
2454
## See https://kubernetes.io/docs/concepts/containers/images/#specifying-imagepullsecrets-on-a-pod
2455
pullSecrets: []
2456
# - name: "<REG_SECRET>"
2457
# clusterChecksRunner.createPodDisruptionBudget -- Create the pod disruption budget to apply to the cluster checks agents
2458
# DEPRECATED. Use clusterChecksRunner.pdb.create instead
2459
createPodDisruptionBudget: false
2460
pdb:
2461
# clusterChecksRunner.pdb.create -- Enable pod disruption budget for Cluster Checks Runner deployments.
2462
2463
## Only one of `minAvailable` or `maxUnavailable` can be set. More information: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
2464
## By default, maxUnavailable is set to 1 for cluster checks runners.
2465
create: false
2466
# clusterChecksRunner.pdb.minAvailable -- Minimum number of pods that must remain available during a disruption
2467
minAvailable:
2468
# clusterChecksRunner.pdb.maxUnavailable -- Maximum number of pods that can be unavailable during a disruption
2469
maxUnavailable:
2470
# Provide Cluster Checks Deployment pods RBAC configuration
2471
rbac:
2472
# clusterChecksRunner.rbac.create -- If true, create & use RBAC resources
2473
create: true
2474
# clusterChecksRunner.rbac.dedicated -- If true, use a dedicated RBAC resource for the cluster checks agent(s)
2475
dedicated: false
2476
# clusterChecksRunner.rbac.serviceAccountAnnotations -- Annotations to add to the ServiceAccount if clusterChecksRunner.rbac.dedicated is true
2477
serviceAccountAnnotations: {}
2478
# clusterChecksRunner.rbac.serviceAccountAdditionalLabels -- Labels to add to the ServiceAccount if clusterChecksRunner.rbac.dedicated is true
2479
serviceAccountAdditionalLabels: {}
2480
# clusterChecksRunner.rbac.automountServiceAccountToken -- If true, automatically mount the ServiceAccount's API credentials if clusterChecksRunner.rbac.create is true
2481
automountServiceAccountToken: true
2482
# clusterChecksRunner.rbac.serviceAccountName -- Specify a preexisting ServiceAccount to use if clusterChecksRunner.rbac.create is false
2483
serviceAccountName: default
2484
# clusterChecksRunner.replicas -- Number of Cluster Checks Runner instances
2485
2486
## If you want to deploy the clusterChecks agent in HA, keep at least clusterChecksRunner.replicas set to 2.
2487
## And increase the clusterChecksRunner.replicas according to the number of Cluster Checks.
2488
replicas: 2
2489
# clusterChecksRunner.revisionHistoryLimit -- The number of old ReplicaSets to keep in this Deployment.
2490
revisionHistoryLimit: 10
2491
# clusterChecksRunner.resources -- Datadog clusterchecks-agent resource requests and limits.
2492
resources: {}
2493
# requests:
2494
# cpu: 200m
2495
# memory: 500Mi
2496
# limits:
2497
# cpu: 200m
2498
# memory: 500Mi
2499
2500
# clusterChecksRunner.affinity -- Allow the ClusterChecks Deployment to schedule using affinity rules.
2501
2502
## By default, ClusterChecks Deployment Pods are preferred to run on different Nodes.
2503
## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity
2504
affinity: {}
2505
# clusterChecksRunner.topologySpreadConstraints -- Allow the ClusterChecks Deployment to schedule using pod topology spreading
2506
2507
## By default, no constraints are set, allowing cluster defaults to be used for scheduling
2508
## Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
2509
topologySpreadConstraints: []
2510
# clusterChecksRunner.strategy -- Allow the ClusterChecks deployment to perform a rolling update on helm update
2511
2512
## ref: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#strategy
2513
strategy:
2514
type: RollingUpdate
2515
rollingUpdate:
2516
maxSurge: 1
2517
maxUnavailable: 0
2518
# clusterChecksRunner.dnsConfig -- specify dns configuration options for datadog cluster agent containers e.g ndots
2519
2520
## ref: https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config
2521
dnsConfig: {}
2522
# options:
2523
# - name: ndots
2524
# value: "1"
2525
2526
# clusterChecksRunner.priorityClassName -- Name of the priorityClass to apply to the Cluster checks runners
2527
priorityClassName: # system-cluster-critical
2528
# clusterChecksRunner.nodeSelector -- Allow the ClusterChecks Deployment to schedule on selected nodes
2529
2530
## Ref: https://kubernetes.io/docs/user-guide/node-selection/
2531
nodeSelector: {}
2532
# clusterChecksRunner.tolerations -- Tolerations for pod assignment
2533
2534
## Ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/
2535
tolerations: []
2536
# clusterChecksRunner.healthPort -- Port number to use in the Cluster Checks Runner for the healthz endpoint
2537
healthPort: 5557
2538
# clusterChecksRunner.livenessProbe -- Override default agent liveness probe settings
2539
# @default -- Every 15s / 6 KO / 1 OK
2540
2541
## In case of issues with the probe, you can disable it with the
2542
## following values, to allow easier investigating:
2543
#
2544
# livenessProbe:
2545
# exec:
2546
# command: ["/bin/true"]
2547
#
2548
livenessProbe:
2549
initialDelaySeconds: 15
2550
periodSeconds: 15
2551
timeoutSeconds: 5
2552
successThreshold: 1
2553
failureThreshold: 6
2554
# clusterChecksRunner.readinessProbe -- Override default agent readiness probe settings
2555
# @default -- Every 15s / 6 KO / 1 OK
2556
2557
## In case of issues with the probe, you can disable it with the
2558
## following values, to allow easier investigating:
2559
#
2560
# readinessProbe:
2561
# exec:
2562
# command: ["/bin/true"]
2563
#
2564
readinessProbe:
2565
initialDelaySeconds: 15
2566
periodSeconds: 15
2567
timeoutSeconds: 5
2568
successThreshold: 1
2569
failureThreshold: 6
2570
# clusterChecksRunner.startupProbe -- Override default agent startup probe settings
2571
# @default -- Every 15s / 6 KO / 1 OK
2572
2573
## In case of issues with the probe, you can disable it with the
2574
## following values, to allow easier investigating:
2575
#
2576
# startupProbe:
2577
# exec:
2578
# command: ["/bin/true"]
2579
#
2580
startupProbe:
2581
initialDelaySeconds: 15
2582
periodSeconds: 15
2583
timeoutSeconds: 5
2584
successThreshold: 1
2585
failureThreshold: 6
2586
# clusterChecksRunner.deploymentAnnotations -- Annotations to add to the cluster-checks-runner's Deployment
2587
deploymentAnnotations: {}
2588
# key: "value"
2589
2590
# clusterChecksRunner.podAnnotations -- Annotations to add to the cluster-checks-runner's pod(s)
2591
podAnnotations: {}
2592
# key: "value"
2593
2594
# clusterChecksRunner.env -- Environment variables specific to Cluster Checks Runner
2595
2596
## ref: https://github.com/DataDog/datadog-agent/tree/main/Dockerfiles/agent#environment-variables
2597
env: []
2598
# - name: <ENV_VAR_NAME>
2599
# value: <ENV_VAR_VALUE>
2600
2601
# clusterChecksRunner.envFrom -- Set environment variables specific to Cluster Checks Runner from configMaps and/or secrets
2602
2603
## envFrom to pass configmaps or secrets as environment
2604
## ref: https://github.com/DataDog/datadog-agent/tree/main/Dockerfiles/agent#environment-variables
2605
envFrom: []
2606
# - configMapRef:
2607
# name: <CONFIGMAP_NAME>
2608
# - secretRef:
2609
# name: <SECRET_NAME>
2610
2611
# clusterChecksRunner.envDict -- Set environment variables specific to Cluster Checks Runner defined in a dict
2612
envDict: {}
2613
# <ENV_VAR_NAME>: <ENV_VAR_VALUE>
2614
2615
# clusterChecksRunner.volumes -- Specify additional volumes to mount in the cluster checks container
2616
volumes: []
2617
# - hostPath:
2618
# path: <HOST_PATH>
2619
# name: <VOLUME_NAME>
2620
2621
# clusterChecksRunner.volumeMounts -- Specify additional volumes to mount in the cluster checks container
2622
volumeMounts: []
2623
# - name: <VOLUME_NAME>
2624
# mountPath: <CONTAINER_PATH>
2625
# readOnly: true
2626
2627
networkPolicy:
2628
# clusterChecksRunner.networkPolicy.create -- If true, create a NetworkPolicy for the cluster checks runners.
2629
# DEPRECATED. Use datadog.networkPolicy.create instead
2630
create: false
2631
# clusterChecksRunner.additionalLabels -- Adds labels to the cluster checks runner deployment and pods
2632
additionalLabels: {}
2633
# key: "value"
2634
2635
# clusterChecksRunner.instanceLabelOverride -- Override the `app.kubernetes.io/instance` label on the cluster checks runner deployment and pods. Useful to restore the pre-3.140.0 value when callers (e.g. NetworkPolicies) match on that label.
2636
instanceLabelOverride: # "datadog"
2637
# clusterChecksRunner.securityContext -- Allows you to overwrite the default PodSecurityContext on the clusterchecks pods.
2638
securityContext: {}
2639
containers:
2640
agent:
2641
# clusterChecksRunner.containers.agent.securityContext -- Specify securityContext on the agent container
2642
securityContext:
2643
readOnlyRootFilesystem: true
2644
initContainers:
2645
# clusterChecksRunner.containers.initContainers.securityContext -- Specify securityContext on the init containers
2646
securityContext: {}
2647
# clusterChecksRunner.ports -- Allows to specify extra ports (hostPorts for instance) for this container
2648
ports: []
2649
operator:
2650
image:
2651
# operator.image.tag -- Define the Datadog Operator version to use
2652
tag: 1.29.0
2653
datadogAgent:
2654
# operator.datadogAgent.enabled -- Enables Datadog Agent controller
2655
enabled: true
2656
datadogAgentInternal:
2657
# operator.datadogAgentInternal.enabled -- Enables the Datadog Agent Internal controller
2658
enabled: true
2659
datadogDashboard:
2660
# operator.datadogDashboard.enabled -- Enables the Datadog Dashboard controller
2661
enabled: false
2662
datadogGenericResource:
2663
# operator.datadogGenericResource.enabled -- Enables the Datadog Generic Resource controller
2664
enabled: false
2665
datadogMonitor:
2666
# operator.datadogMonitor.enabled -- Enables the Datadog Monitor controller
2667
enabled: false
2668
datadogSLO:
2669
# operator.datadogSLO.enabled -- Enables the Datadog SLO controller
2670
enabled: false
2671
untaintController:
2672
# operator.untaintController.enabled -- Enables the Datadog Operator untaint controller (removes the `agent.datadoghq.com/not-ready=presence:NoSchedule` startup taint once the Agent is ready) and adds the matching toleration to the Agent DaemonSet so it can schedule on tainted nodes. Requires Operator v1.28.0+
2673
enabled: false
2674
datadogCRDs:
2675
# operator.datadogCRDs.keepCrds -- Set to true to keep the CRDs when the helm chart is uninstalled. This must be set to true if datadog.operator.migration.enabled is set to true.
2676
keepCrds: false
2677
crds:
2678
# operator.datadogCRDs.crds.datadogAgents -- Set to true to deploy the DatadogAgents CRD
2679
datadogAgents: true
2680
# operator.datadogCRDs.crds.datadogMonitors -- Set to true to deploy the DatadogMonitors CRD
2681
datadogMonitors: true
2682
# operator.datadogCRDs.crds.datadogSLOs -- Set to true to deploy the DatadogSLO CRD
2683
datadogSLOs: true
2684
# operator.datadogCRDs.crds.datadogDashboards -- Set to true to deploy the DatadogDashboard CRD
2685
datadogDashboards: true
2686
# operator.datadogCRDs.crds.datadogGenericResources -- Set to true to deploy the DatadogGenericResource CRD
2687
datadogGenericResources: true
2688
# operator.datadogCRDs.crds.datadogMetrics -- Set to true to deploy the DatadogMetrics CRD
2689
datadogMetrics: false
2690
# operator.datadogCRDs.crds.datadogPodAutoscalers -- Set to true to deploy the DatadogPodAutoscalers CRD
2691
datadogPodAutoscalers: false
2692
# operator.datadogCRDs.crds.datadogPodAutoscalerClusterProfile -- Set to false to deploy the DatadogPodAutoscalerClusterProfiles CRD
2693
datadogPodAutoscalerClusterProfiles: false
2694
# operator.datadogCRDs.crds.datadogAgentInternals -- Set to true to deploy the DatadogAgentInternals CRD
2695
datadogAgentInternals: true
2696
# operator.datadogCRDs.crds.datadogCSIDrivers -- Set to true to deploy the DatadogCSIDriver CRD
2697
datadogCSIDrivers: true
2698
# operator.datadogCRDs.crds.datadogInstrumentations -- Set to true to deploy the DatadogInstrumentations CRD
2699
datadogInstrumentations: false
2700
datadog-crds:
2701
crds:
2702
# datadog-crds.crds.datadogMetrics -- Set to true to deploy the DatadogMetrics CRD
2703
datadogMetrics: true
2704
# datadog-crds.crds.datadogPodAutoscalers -- Set to true to deploy the DatadogPodAutoscalers CRD
2705
datadogPodAutoscalers: true
2706
# crds.datadogPodAutoscalerClusterProfile -- Set to true to deploy the DatadogPodAutoscalerClusterProfiles CRD
2707
datadogPodAutoscalerClusterProfiles: true
2708
datadog-instrumentation-crd:
2709
crds:
2710
# datadog-instrumentation-crd.crds.datadogInstrumentations -- Set to true to deploy the DatadogInstrumentations CRD
2711
datadogInstrumentations: true
2712
kube-state-metrics:
2713
# kube-state-metrics.image.repository -- Default kube-state-metrics image repository.
2714
image:
2715
repository: registry.k8s.io/kube-state-metrics/kube-state-metrics
2716
rbac:
2717
# kube-state-metrics.rbac.create -- If true, create & use RBAC resources
2718
create: true
2719
serviceAccount:
2720
# kube-state-metrics.serviceAccount.create -- If true, create ServiceAccount, require rbac kube-state-metrics.rbac.create true
2721
create: true
2722
# kube-state-metrics.serviceAccount.name -- The name of the ServiceAccount to use.
2723
2724
## If not set and create is true, a name is generated using the fullname template
2725
name:
2726
# kube-state-metrics.resources -- Resource requests and limits for the kube-state-metrics container.
2727
resources: {}
2728
# requests:
2729
# cpu: 200m
2730
# memory: 256Mi
2731
# limits:
2732
# cpu: 200m
2733
# memory: 256Mi
2734
2735
# kube-state-metrics.nodeSelector -- Node selector for KSM. KSM only supports Linux.
2736
nodeSelector:
2737
kubernetes.io/os: linux
2738
providers:
2739
gke:
2740
# providers.gke.autopilot -- Enables Datadog Agent deployment on GKE Autopilot
2741
autopilot: false
2742
# providers.gke.cos -- Enables Datadog Agent deployment on GKE with Container-Optimized OS (COS)
2743
cos: false
2744
# providers.gke.gdc -- Enables Datadog Agent deployment on GKE on Google Distributed Cloud (GDC)
2745
gdc: false
2746
flatcar:
2747
# providers.flatcar.enabled -- Enable Flatcar Container Linux support. Flatcar mounts `/usr` read-only, so the host `/usr/src` volume is not mounted into system-probe.
2748
enabled: false
2749
eks:
2750
# providers.eks.controlPlaneMonitoring -- Enable control plane monitoring checks in the EKS cluster.
2751
controlPlaneMonitoring: false
2752
ec2:
2753
# providers.eks.ec2.useHostnameFromFile -- Use hostname from EC2 filesystem instead of fetching from metadata endpoint.
2754
2755
## When deploying to EC2-backed EKS infrastructure, there are situations where the
2756
## IMDS metadata endpoint is not accessible to containers. This flag mounts the host's
2757
## `/var/lib/cloud/data/instance-id` and uses that for Agent's hostname instead.
2758
useHostnameFromFile: false
2759
aks:
2760
# providers.aks.enabled -- Activate all specificities related to AKS configuration. Required as currently we cannot auto-detect AKS.
2761
enabled: false
2762
openshift:
2763
# providers.openshift.controlPlaneMonitoring -- Enable control plane monitoring checks in the OpenShift cluster.
2764
# Certificates are needed to communicate with the Etcd service, which can be found in the secret `etcd-metric-client` in the `openshift-etcd-operator` namespace.
2765
# To give the Datadog Agent access to these certificates, copy them into the same namespace the Datadog Agent is running in:
2766
# `oc get secret etcd-metric-client -n openshift-etcd-operator -o yaml | sed 's/namespace: openshift-etcd-operator/namespace: <datadog agent namespace>/' | oc create -f -`
2767
controlPlaneMonitoring: false
2768
talos:
2769
# providers.talos.enabled -- Activate all required specificities related to Talos.dev configuration,
2770
# as currently the chart cannot auto-detect Talos.dev cluster.
2771
# Note: The Agent deployment requires additional privileges that are not permitted by the default pod security policy.
2772
# The annotation `pod-security.kubernetes.io/enforce=privileged` must be applied to the Datadog installation
2773
# Kubernetes namespace. For more information on pod security policies in Talos.dev clusters, see:
2774
# https://www.talos.dev/v1.8/kubernetes-guides/configuration/pod-security/
2775
enabled: false
2776
remoteConfiguration:
2777
# remoteConfiguration.enabled -- Set to true to enable remote configuration on the Cluster Agent (if set) and the node agent.
2778
# Can be overridden if `datadog.remoteConfiguration.enabled`
2779
# Preferred way to enable Remote Configuration.
2780
enabled: true
2781
## OTel collector related configuration for otel-agent in Gateway Deployment
2782
## Note this is different from the otel-agent in Daemonset (datadog.otelCollector)
2783
otelAgentGateway:
2784
# otelAgentGateway.enabled -- Enable otel-agent Gateway
2785
enabled: false
2786
# otelAgentGateway.ports -- Ports that OTel Collector is listening on
2787
ports:
2788
# Default GRPC port of OTLP receiver
2789
- containerPort: "4317"
2790
name: otel-grpc
2791
protocol: TCP
2792
# Default HTTP port of OTLP receiver
2793
- containerPort: "4318"
2794
name: otel-http
2795
protocol: TCP
2796
# otelAgentGateway.config -- Gateway OTel Agent configuration
2797
config: null
2798
## otelAgentGateway.configMap -- Use an existing ConfigMap for Gateway OTel Agent configuration
2799
configMap:
2800
# otelAgentGateway.configMap.name -- Name of the existing ConfigMap that contains the Gateway OTel Agent configuration
2801
name: null
2802
# otelAgentGateway.configMap.checksum -- Checksum of the existing ConfigMap that contains the Gateway OTel Agent configuration
2803
checksum: null
2804
# otelAgentGateway.configMap.items -- Items within the ConfigMap that contain Gateway OTel Agent configuration
2805
items:
2806
# - key: otel-gateway-config.yaml
2807
# path: otel-gateway-config.yaml
2808
# - key: otel-gateway-config-two.yaml
2809
# path: otel-gateway-config-two.yaml
2810
# otelAgentGateway.configMap.key -- Key within the ConfigMap that contains the Gateway OTel Agent configuration
2811
key: otel-gateway-config.yaml
2812
# otelAgentGateway.featureGates -- Feature gates to pass to OTel collector, as a comma separated list
2813
featureGates: null
2814
# otelAgentGateway.replicas -- Number of otel-agent instances in the Gateway Deployment
2815
replicas: 1
2816
# otelAgentGateway.revisionHistoryLimit -- The number of old ReplicaSets to keep in this Deployment.
2817
revisionHistoryLimit: 10
2818
# otelAgentGateway.deploymentAnnotations -- Annotations to add to the otel-agent Gateway Deployment
2819
deploymentAnnotations: {}
2820
# key: "value"
2821
2822
# otelAgentGateway.podAnnotations -- Annotations to add to the Gateway Deployment's Pods
2823
podAnnotations: {}
2824
# key: "value"
2825
2826
# otelAgentGateway.tolerations -- Allow the Gateway Deployment to schedule on tainted nodes (requires Kubernetes >= 1.6)
2827
tolerations: []
2828
# otelAgentGateway.useHostNetwork -- Bind ports on the hostNetwork
2829
2830
## Useful for CNI networking where hostPort might
2831
## not be supported. The ports need to be available on all hosts. It can be
2832
## used for custom metrics instead of a service endpoint.
2833
##
2834
## WARNING: Make sure that hosts using this are properly firewalled otherwise
2835
## metrics and traces are accepted from any host able to connect to this host.
2836
#
2837
useHostNetwork: false
2838
# otelAgentGateway.dnsConfig -- Specify dns configuration options for otel agent containers e.g ndots
2839
2840
## ref: https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config
2841
dnsConfig: {}
2842
# options:
2843
# - name: ndots
2844
# value: "1"
2845
2846
# otelAgentGateway.volumes -- Specify additional volumes to mount in the otel-agent container
2847
volumes: []
2848
# - hostPath:
2849
# path: <HOST_PATH>
2850
# name: <VOLUME_NAME>
2851
2852
# otelAgentGateway.volumeMounts -- Specify additional volumes to mount in the otel-agent container
2853
volumeMounts: []
2854
# - name: <VOLUME_NAME>
2855
# mountPath: <CONTAINER_PATH>
2856
# readOnly: true
2857
2858
# otelAgentGateway.nodeSelector -- Allow the Gateway Deployment to schedule on selected nodes
2859
2860
## Ref: https://kubernetes.io/docs/user-guide/node-selection/
2861
nodeSelector: {}
2862
# otelAgentGateway.affinity -- Allow the Gateway Deployment to schedule using affinity rules
2863
2864
## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity
2865
affinity: {}
2866
# otelAgentGateway.strategy -- Allow the otel-agent Gateway Deployment to perform a rolling update on helm update
2867
2868
## ref: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#strategy
2869
strategy:
2870
type: RollingUpdate
2871
rollingUpdate:
2872
maxSurge: 1
2873
maxUnavailable: 0
2874
# otelAgentGateway.priorityClassCreate -- Creates a priorityClass for the otel-agent Gateway Deployment pods.
2875
priorityClassCreate: false
2876
# otelAgentGateway.priorityClassName -- Sets PriorityClassName if defined
2877
priorityClassName: null
2878
# otelAgentGateway.priorityPreemptionPolicyValue -- Set to "Never" to change the PriorityClass to non-preempting
2879
priorityPreemptionPolicyValue: PreemptLowerPriority
2880
# otelAgentGateway.priorityClassValue -- Value used to specify the priority of the scheduling of otel-agent Gateway Deployment pods.
2881
2882
## The PriorityClass uses PreemptLowerPriority.
2883
priorityClassValue: 1000000000
2884
# otelAgentGateway.podLabels -- Sets podLabels if defined
2885
2886
## Note: These labels are also used as label selectors so they are immutable.
2887
podLabels: {}
2888
# otelAgentGateway.additionalLabels -- Adds labels to the Agent Gateway Deployment and pods
2889
additionalLabels: {}
2890
# otelAgentGateway.shareProcessNamespace -- Set the process namespace sharing on the otel-agent
2891
shareProcessNamespace: false
2892
# otelAgentGateway.lifecycle -- Configure the lifecycle of the otel-agent
2893
lifecycle: {}
2894
# preStop:
2895
# exec:
2896
# command: ["/bin/sh", "-c", "sleep 70"]
2897
2898
# otelAgentGateway.terminationGracePeriodSeconds -- (int) Configure the termination grace period for the otel-agent
2899
terminationGracePeriodSeconds: # 70
2900
# otelAgentGateway.topologySpreadConstraints -- Allow the otel-agent Gateway Deployment to schedule using pod topology spreading
2901
2902
## By default, no constraints are set, allowing cluster defaults to be used for scheduling
2903
## Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
2904
topologySpreadConstraints: []
2905
## Configuration for the service for the OTel Agent Gateway
2906
service:
2907
# otelAgentGateway.service.type -- Set type of otel-agent-gateway service
2908
type: ClusterIP
2909
## Allow to override the Datadog otel-agent image
2910
image:
2911
# otelAgentGateway.image.name -- otel agent image name to use (relative to `registry`)
2912
name: ddot-collector
2913
# otelAgentGateway.image.tag -- Override the image tag of otel agent
2914
tag: ""
2915
# otelAgentGateway.image.tagSuffix -- Suffix to append to image tag of otel agent
2916
tagSuffix: ""
2917
# otelAgentGateway.image.digest -- Override the image digest of otel agent, takes precedence over tag if specified
2918
digest: ""
2919
# otelAgentGateway.image.repository -- Override the image repository to override default registry
2920
repository:
2921
# otelAgentGateway.image.doNotCheckTag -- Skip the version and chart compatibility check
2922
2923
## By default, the version passed in otelAgentGateway.image.tag is checked
2924
## for compatibility with the version of the chart.
2925
## This boolean permits completely skipping this check.
2926
## This is useful, for example, for custom tags that are not
2927
## respecting semantic versioning.
2928
doNotCheckTag: # false
2929
# otelAgentGateway.image.pullPolicy -- otel Agent image pullPolicy
2930
pullPolicy: IfNotPresent
2931
# otelAgentGateway.image.pullSecrets -- otel Agent repository pullSecret (ex: specify docker registry credentials)
2932
2933
## See https://kubernetes.io/docs/concepts/containers/images/#specifying-imagepullsecrets-on-a-pod
2934
pullSecrets: []
2935
# - name: "<REG_SECRET>"
2936
initContainers:
2937
# otelAgentGateway.initContainers.securityContext -- Allows you to overwrite the default container SecurityContext for init containers
2938
securityContext:
2939
# otelAgentGateway.initContainers.resources -- Resource requests and limits for init containers
2940
resources:
2941
# requests:
2942
# cpu: 100m
2943
# memory: 200Mi
2944
# limits:
2945
# cpu: 100m
2946
# memory: 200Mi
2947
containers:
2948
otelAgent:
2949
# otelAgentGateway.containers.otelAgent.env -- Additional environment variables for the otel-agent container
2950
env: []
2951
# otelAgentGateway.containers.otelAgent.envFrom -- Set environment variables specific to otel-agent from configMaps and/or secrets
2952
envFrom: []
2953
# - configMapRef:
2954
# name: <CONFIGMAP_NAME>
2955
# - secretRef:
2956
# name: <SECRET_NAME>
2957
2958
# otelAgentGateway.containers.otelAgent.envDict -- Set environment variables specific to otel-agent defined in a dict
2959
envDict: {}
2960
# <ENV_VAR_NAME>: <ENV_VAR_VALUE>
2961
2962
# otelAgentGateway.containers.otelAgent.resources -- Resource requests and limits for the otel-agent container
2963
resources: {}
2964
# requests:
2965
# cpu: 100m
2966
# memory: 200Mi
2967
# limits:
2968
# cpu: 100m
2969
# memory: 200Mi
2970
2971
# otelAgentGateway.containers.otelAgent.securityContext -- Allows you to overwrite the default container SecurityContext for the otel-agent container.
2972
securityContext: {}
2973
# otelAgentGateway.containers.otelAgent.logLevel -- Set logging verbosity, valid log levels are: trace, debug, info, warn, error, critical, and off.
2974
# If not set, fall back to the value of datadog.logLevel.
2975
logLevel: # INFO
2976
# otelAgentGateway.containers.otelAgent.healthPort -- Port number to use for the otel-agent-gateway health check endpoint (OTel health_check extension)
2977
healthPort: 13133
2978
# otelAgentGateway.containers.otelAgent.livenessProbe -- otel-agent-gateway liveness probe settings.
2979
# Set enabled to true to activate. The OTel config must expose the health_check extension
2980
# on healthPort (default 13133); the generated default config does this automatically.
2981
livenessProbe:
2982
enabled: false
2983
initialDelaySeconds: 15
2984
periodSeconds: 15
2985
timeoutSeconds: 5
2986
successThreshold: 1
2987
failureThreshold: 6
2988
# otelAgentGateway.containers.otelAgent.readinessProbe -- otel-agent-gateway readiness probe settings.
2989
# Set enabled to true to activate. The OTel config must expose the health_check extension
2990
# on healthPort (default 13133); the generated default config does this automatically.
2991
readinessProbe:
2992
enabled: false
2993
initialDelaySeconds: 15
2994
periodSeconds: 15
2995
timeoutSeconds: 5
2996
successThreshold: 1
2997
failureThreshold: 6
2998
## Provide OTel Collector RBAC configuration in Gateway
2999
rbac:
3000
# otelAgentGateway.rbac.create -- If true, check OTel Collector config for k8sattributes processor
3001
# and create required ClusterRole to access Kubernetes API
3002
create: true
3003
# otelAgentGateway.rbac.rules -- A set of additional RBAC rules to apply to OTel Collector's ClusterRole
3004
rules: []
3005
# - apiGroups: [""]
3006
# resources: ["pods", "nodes"]
3007
# verbs: ["get", "list", "watch"]
3008
## Provide OTel Collector logs configuration
3009
logs:
3010
# otelAgentGateway.logs.enabled -- Enable logs support in the OTel Collector.
3011
# If true, checks OTel Collector config for filelog receiver and mounts additional volumes to collect containers
3012
# and pods logs.
3013
enabled: false
3014
## Provide Horizontal Pod Autoscaler (HPA) configuration in OTel Agent Gateway, requires k8s 1.23.0 and above
3015
autoscaling:
3016
# otelAgentGateway.autoscaling.enabled -- enable autoscaling using Horizontal Pod Autoscaler (HPA), requires k8s 1.23.0 and above.
3017
# Will override otelAgentGateway.replicas.
3018
enabled: false
3019
# otelAgentGateway.autoscaling.annotations -- annotations for OTel Agent Gateway HPA
3020
annotations: {}
3021
# otelAgentGateway.autoscaling.minReplicas -- min number of replicas for OTel Agent Gateway HPA
3022
minReplicas: 0
3023
# otelAgentGateway.autoscaling.maxReplicas -- max number of replicas for OTel Agent Gateway HPA
3024
maxReplicas: 0
3025
# otelAgentGateway.autoscaling.metrics -- the metrics used for OTel Agent Gateway HPA
3026
metrics: []
3027
# otelAgentGateway.autoscaling.behavior -- defines the scaling behavior in OTel Agent Gateway HPA
3028
behavior:
3029
# otelAgentGateway.autoscaling.behavior.scaleUp -- defines the scaling up behavior in OTel Agent Gateway HPA
3030
scaleUp: {}
3031
# otelAgentGateway.autoscaling.behavior.scaleDown -- defines the scaling down behavior in OTel Agent Gateway HPA
3032
scaleDown: {}
3033

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.